Nispo is an Italian NIS2 compliance management platform, designed for organisations subject to NIS2 in Italy. Nispo helps organisations map the NIS2 requirements and the ACN basic security measures to their own controls, collect and keep evidence, track the remediation of gaps, manage policies and suppliers, and prepare the documentation for the management body and for inspections.

Modules

The modules share the same requirements, assets, evidence and owners: data entered once counts everywhere.

01

NIS2/ACN control register

The list of controls to satisfy, structured on the ACN basic security measures with National Framework codes (e.g. GV.SC-07).

What you get: You know which requirements apply, who owns them and where you stand, control by control.

02

Gap assessment

Compares the status of each control with the requirement and ranks gaps by priority and impact.

What you get: A realistic work plan instead of an undifferentiated list of non-conformities.

03

Evidence management

A repository of compliance proof linked to controls: automated check results, uploaded documents, approved policies, service reports.

What you get: When someone says "prove it", the proof is already where it should be.

04

Remediation: tasks and deadlines

Turns every gap and every finding into an action with an owner, a due date and closure verification.

What you get: Measurable progress and proof that problems get closed, not just listed.

05

Policies and documents

Templates for the required policies and plans (e.g. information security, access control, business continuity, incident response, supplier risk management, acceptable use), with versions, approvals and review status.

What you get: Consistent documents, always in their valid version.

06

Suppliers and supply chain

An ICT supplier register with criticality, data processed, internal owner, security questionnaires and deadlines for contracts, DPAs and certifications.

What you get: Proof that supply chain assessment is being done, and with what outcome.

07

ACN portal files

Generates the files to upload to the ACN portal for the annual obligations: the categorisation of activities and services and the list of relevant NIS suppliers.

What you get: The portal obligations prepared without re-entering anything, consistent with the compliance documentation.

08

Risk register

Risks linked to assets and controls, with likelihood, impact, treatment and residual risk.

What you get: Proportionality choices that are justified and documented.

09

Inventory and people

An inventory of hardware, software and services with owners; a list of the people involved in security with roles and permissions.

What you get: You know what you own and who is responsible for it.

10

Dashboard and reporting

A compliance status dashboard by area and reports for the management body and for IT, with PDF and CSV export.

What you get: An up-to-date picture to present, without building reports by hand.

11

CSIRT Italia bulletins

Security alerts and bulletins published by CSIRT Italia (ACN), synced into the platform.

What you get: One less place to check every day.

Automation

Nispo only checks on its own what it can read from a connected system. A control’s status follows the latest automated check or the evidence uploaded by its owner; decisions stay with the organisation.

01

Automated

  • Checks of technical controls on the integrated systems (Microsoft 365 / Entra ID, Google Workspace, AWS, Google Cloud), for example admin MFA, privileged accounts and devices, with the result saved as dated evidence.
  • Import of users, devices, licences and cloud resources into the inventory.
  • Updates to control status and the dashboard, deadline reminders, CSIRT Italia bulletins.
  • ACN portal files (categorisation of activities and services, relevant NIS suppliers), generated from data already in the platform.
02

You do

  • Profile, scope and the NIS2 category notified by ACN.
  • Adapting and approving policies and plans, starting from Nispo’s templates.
  • Evidence for manual controls and non-connected systems.
  • Supplier assessment, risk decisions, carrying out remediation.
  • Reviewing and uploading the files to the ACN portal, registration and the annual update.
03

Nispo does not determine

  • Whether you fall under NIS2 and in which category: ACN notifies it.
  • Whether your measures will be deemed adequate: Nispo issues no certifications or legal opinions.
  • Risk acceptance and proportionality: these are the organisation’s decisions.
  • The status of non-connected systems: it depends on the evidence uploaded.
  • Threat detection and response: the job of tools such as Microsoft Defender, EDR and SIEM.

Product tour →Nispo and Microsoft 365 →

A 30-minute demo on your Microsoft 365 tenant: control register, evidence and your first real gaps.