NIS2 compliance, made operational.

NIS2 isn’t a document to file away: it’s ongoing work to keep running over time. Epic Assess turns it into policies, controls, tasks and deadlines, all in one place, with an owner for every task and a record of what was done.

See if you’re in scopeBook a demo

NIS2 can’t be run on a spreadsheet.

Legislative Decree 138/2024.

Fines up to €10M / 2%.

18 sectors.

Scattered requirements

Obligations, measures and evidence end up in different folders, emails and sheets. Nobody knows what’s actually covered.

How Epic Assess works:

The directive asks for security measures, proof they’re applied, incident response times and control over your suppliers. Managed by hand, it all gives way at the first deadline — and it shows at the first inspection.

You declare your company data once. Epic Assess works out your scope and prepares the elements you need, already linked to each other.

The solution

From the regulation to the elements that make it work.

The decisions that matter by law — whether you must comply, which measures, by when — are made by precise, tested rules, not by an AI.

Where it saves time, a ready-made draft cites the measure: you read it, correct it, sign it.

Obligations, measures and evidence in one place, already linked together.

  • A starting draft for each measure, citing its legal source, for you to complete and approve.

  • The ACN measures that apply to your profile, with coverage status at a glance.

  • Every measure has an owner and an action: everyone knows who does what, and by when.

  • Risks documented with mitigations linked to the measures, not a list on the side.

  • A portal where critical suppliers fill in the questionnaire, with their VAT number checked on VIES.

  • Coverage, documents, evidence and incident history in a single dossier, ready to show.

Six working elements, from the policy to the inspection dossier.

See if you’re in scope

The automations

Recurring work puts itself back on the calendar.

Compliance isn’t a project that ends: it’s a cycle. Epic Assess keeps track of the deadlines for you.

Compliance isn’t a project that ends: it’s a cycle. Epic Assess keeps track of the deadlines for you.

Review cycles

Policies and measures have a review date: they come back on the table when needed, not at random.

Review cycles

Due for review this month

  • Information security policy
  • Incident management procedure
  • Business continuity plan

Upcoming reviews

  • Access control
  • Critical supplier management
  • Staff training plan

Reminders and deadlines

Week 41

Upcoming deadlines

October 5, 2026

Due soon

4

Overdue

0

Alert

7 d

  • Access policy reviewin 7 d
  • Annual trainingin 12 d
  • Incident drillin 21 d

Tracked approvals

Approval requested: Information security policy, version 3.

Awaiting signature
  1. Security lead

    Draft checked

    09/12 · 10:42
  2. Legal

    References confirmed

    09/15 · 16:08
  3. Management body

    In review

    today

Recurring tasks

They come back on their own

  • Staff trainingevery 12 months11/03
  • Backup restore testevery 6 months10/18
  • Asset inventoryevery quarter01/01
  • Critical supplier checkevery 12 months02/14

Review cycles

Due for review this month

  • Information security policy
  • Incident management procedure
  • Business continuity plan

Upcoming reviews

  • Access control
  • Critical supplier management
  • Staff training plan

Review cycles

Policies and measures have a review date: they come back on the table when needed, not at random.

Reminders and deadlines

Week 41

Upcoming deadlines

October 5, 2026

Due soon

4

Overdue

0

Alert

7 d

  • Access policy reviewin 7 d
  • Annual trainingin 12 d
  • Incident drillin 21 d

Reminders and deadlines

Every obligation with a date is tracked, and you get an alert before it’s due.

Tracked approvals

Approval requested: Information security policy, version 3.

Awaiting signature
  1. Security lead

    Draft checked

    09/12 · 10:42
  2. Legal

    References confirmed

    09/15 · 16:08
  3. Management body

    In review

    today

Tracked approvals

Who approves what and when stays on record: the role the law gives management is documented.

Recurring tasks

They come back on their own

  • Staff trainingevery 12 months11/03
  • Backup restore testevery 6 months10/18
  • Asset inventoryevery quarter01/01
  • Critical supplier checkevery 12 months02/14

Recurring tasks

Training, checks and periodic censuses come back on their own, without chasing anyone.

The notification windows

24h

Early warning to CSIRT Italia.

72h

Notification with an initial assessment of severity and impact.

30d

Final report with causes, impact and remedies.

The notification windows

24h

Early warning to CSIRT Italia.

72h

Notification with an initial assessment of severity and impact.

30d

Final report with causes, impact and remedies.

One system

The work you do for NIS2 doesn’t stay locked inside NIS2.

Every measure is linked to the main security standards. When you take on another framework, you start from what you’ve already done, not from scratch.

  • ISO/IEC 27001
  • NIST SP 800-53
  • GDPR
  • NIS2
  • CIS Controls v8

The AI Act too

AI Act

AI system inventory and deployer obligations, on the same engine as NIS2.