Audit NIS2 Complete
iOS app by Stefan Epistatu. Business · Stefan Epistatu
- Store rating
- 0 / 5
- Store rating count
- 0
- Download price
- 89.99 USD
- In-app purchases
- Unknown
- Version
- 1.0
- Listing last refreshed
- 2026-09-14
View the original store listing
Store description excerpt
The working file of the NIS2 auditor. Not a checklist, not a PDF generator — a digital dossier carrying one client from classification through evidence, findings and corrective actions to the signed report. ONE CLIENT → ONE NIS2 FILE → ONE COMPLETE AUDIT TRAIL CLASSIFICATION THAT SHOWS ITS WORKING The applicability engine determines whether an entity falls under Directive (EU) 2022/2555 and, if so, whether it is essential or important. Every step states the article it relied on — the Article 2(1) size cap, the size-independent triggers of Article 2(2), Article 3(1) and 3(2) — and the size test follows Article 2 of the Annex to Recommendation 2003/361/EC. Where the answer belongs to the Member State rather than the Directive, the engine returns MANUAL LEGAL REVIEW instead of guessing. 30 JURISDICTIONS The 27 EU Member States plus the three EEA-EFTA states, each with competent authority, national CSIRT, single point of contact, registration and incident portals, and the national transposing act. Every entry carries its source, version and last-checked date, and is flagged UNVERIFIED until you confirm it. Nothing is hard-coded: a legislative change is a registry version, not a new build. 76 CONTROLS, FOUR FRAMEWORKS The full Article 21(2)(a)–(j) risk-management measures, Article 20 governance and the Article 23 reporting chain — 76 controls in 12 domains, each with the audit question, guidance on how to test it, the legal basis, and mappings to ISO/IEC 27001:2022 Annex A, NIST CSF 2.0 and CIS Controls v8. EVIDENCE VAULT WITH CHAIN OF CUSTODY Every item gets an EVD identifier, a SHA-256 fingerprint, an uploader, a timestamp and the controls it supports. Eight integrity checks flag duplicate content, documents dated after they were requested, stale policies and expired certificates — as alerts to weigh, never as verdicts. ARTICLE 23, COUNTED CORRECTLY Early warning within 24 hours, notification within 72 (24 for trust service providers where trust services are affected), intermediate report on request, final report one month after the notification you actually sent — or a progress report, then a final report one month after handling completes. All clocks run from becoming aware. In an EEA-EFTA state, where the Directive is not yet incorporated, the app says so instead of running a countdown that does not bind. FINDINGS, CAPA AND RISK Observations, opportunities, minor and major non-conformities and critical findings, each tied to its control and legal requirement. Corrective actions run OPEN → IN PROGRESS → EVIDENCE SUBMITTED → AUDITOR REVIEW → CLOSED. A 5×5 risk register with inherent and residual scoring. REPORTS IN PDF AND WORD A twelve-section final report composed entirely from what you recorded. PDF, Word (.docx) and printing render from the same source, so the filed and printed copies cannot diverge. Below 90% control coverage the report refuses to state a favourable conformity conclusion, and says why. SIXTEEN ROLES, FULLY OFFLINE Lea
Review coverage
AppRill has captured 0 reviews for this app. This is a collected sample, separate from the store rating count. Latest review capture: Not captured yet.
Recent captured chart positions
No chart positions have been captured for this app yet.
Chart position, rating count and review coverage do not establish downloads, revenue or profit. Understand the differences.