NIS2 compliance, made operational.
NIS2 isn’t a document to file away: it’s ongoing work to keep running over time. Epic Assess turns it into policies, controls, tasks and deadlines, all in one place, with an owner for every task and a record of what was done.
NIS2 can’t be run on a spreadsheet.
Legislative Decree 138/2024.
Fines up to €10M / 2%.
18 sectors.
Obligations, measures and evidence end up in different folders, emails and sheets. Nobody knows what’s actually covered.
How Epic Assess works:
The directive asks for security measures, proof they’re applied, incident response times and control over your suppliers. Managed by hand, it all gives way at the first deadline — and it shows at the first inspection.
You declare your company data once. Epic Assess works out your scope and prepares the elements you need, already linked to each other.
The solution
From the regulation to the elements that make it work.
The decisions that matter by law — whether you must comply, which measures, by when — are made by precise, tested rules, not by an AI.
Where it saves time, a ready-made draft cites the measure: you read it, correct it, sign it.
Obligations, measures and evidence in one place, already linked together.
A starting draft for each measure, citing its legal source, for you to complete and approve.
The ACN measures that apply to your profile, with coverage status at a glance.
Every measure has an owner and an action: everyone knows who does what, and by when.
Risks documented with mitigations linked to the measures, not a list on the side.
A portal where critical suppliers fill in the questionnaire, with their VAT number checked on VIES.
Coverage, documents, evidence and incident history in a single dossier, ready to show.
Six working elements, from the policy to the inspection dossier.
See if you’re in scopeThe automations
Recurring work puts itself back on the calendar.
Compliance isn’t a project that ends: it’s a cycle. Epic Assess keeps track of the deadlines for you.
Compliance isn’t a project that ends: it’s a cycle. Epic Assess keeps track of the deadlines for you.
Review cycles
Policies and measures have a review date: they come back on the table when needed, not at random.
Review cycles
Due for review this month
- Information security policy
- Incident management procedure
- Business continuity plan
Upcoming reviews
- Access control
- Critical supplier management
- Staff training plan
Reminders and deadlines
Week 41
Upcoming deadlines
October 5, 2026
Due soon
4
Overdue
0
Alert
7 d
- Access policy reviewin 7 d
- Annual trainingin 12 d
- Incident drillin 21 d
Tracked approvals
Approval requested: Information security policy, version 3.
- 09/12 · 10:42
Security lead
Draft checked
- 09/15 · 16:08
Legal
References confirmed
- today
Management body
In review
Recurring tasks
They come back on their own
- Staff trainingevery 12 months11/03
- Backup restore testevery 6 months10/18
- Asset inventoryevery quarter01/01
- Critical supplier checkevery 12 months02/14
Review cycles
Due for review this month
- Information security policy
- Incident management procedure
- Business continuity plan
Upcoming reviews
- Access control
- Critical supplier management
- Staff training plan
Review cycles
Policies and measures have a review date: they come back on the table when needed, not at random.
Reminders and deadlines
Week 41
Upcoming deadlines
October 5, 2026
Due soon
4
Overdue
0
Alert
7 d
- Access policy reviewin 7 d
- Annual trainingin 12 d
- Incident drillin 21 d
Reminders and deadlines
Every obligation with a date is tracked, and you get an alert before it’s due.
Tracked approvals
Approval requested: Information security policy, version 3.
- 09/12 · 10:42
Security lead
Draft checked
- 09/15 · 16:08
Legal
References confirmed
- today
Management body
In review
Tracked approvals
Who approves what and when stays on record: the role the law gives management is documented.
Recurring tasks
They come back on their own
- Staff trainingevery 12 months11/03
- Backup restore testevery 6 months10/18
- Asset inventoryevery quarter01/01
- Critical supplier checkevery 12 months02/14
Recurring tasks
Training, checks and periodic censuses come back on their own, without chasing anyone.

The notification windows
Early warning to CSIRT Italia.
Notification with an initial assessment of severity and impact.
Final report with causes, impact and remedies.
The notification windows
Early warning to CSIRT Italia.
Notification with an initial assessment of severity and impact.
Final report with causes, impact and remedies.
One system
The work you do for NIS2 doesn’t stay locked inside NIS2.
Every measure is linked to the main security standards. When you take on another framework, you start from what you’ve already done, not from scratch.
- ISO/IEC 27001
- NIST SP 800-53
- GDPR
- NIS2
- CIS Controls v8
The AI Act too
AI Act
AI system inventory and deployer obligations, on the same engine as NIS2.

