Control compliance with NIS 2 / ISO 27001
- Learn NIS 2 requirements and start controlling at once
- Engage teams and track compliance progress
- Conduct internal assessments and invite external assessors
- Control your teams, divisions, contractors and suppliers
- Achieve certification readiness and monitor audit readiness
- Manage the scope of control: NIS 2, ISO 27001, your own standards
Who is this solution for?
Is your organization covered
by NIS 2 requirements?
NIS 2 applies to key entities related to national critical infrastructure and important entities, as well as IT and SaaS service providers and subcontractors in the supply chain.
ISO 27001 is a voluntary standard; each organization decides whether to apply it.
Compliance monitoring
in one place?
NIS 2 and ISO 27001 requirements cover a variety of activities and involve diverse teams, from IT to administration and legal.
PREMIS creates a single central location for all organizational compliance information, while maintaining an auditable track record.
Is audit readiness important?
Both NIS 2 and ISO 27001 require maintaining up-to-date technical documentation, incident logs, risk registers, and other documentation.
An organization should be prepared to demonstrate compliance during audits, inspections, and incident handling.
How does it work?
Planning
Using the compliance template, you plan your approach to achieving compliance with NIS 2 and/or ISO 27001.
The template provides a general framework that forms the basis for customization based on the specifics of your organization, technology, and risk analysis results.
Compliance Monitoring
Responsible individuals implement process activities and provide appropriate procedures, documentation, and records. Appropriate records are maintained.
The completeness, consistency, and validity of all documentation are monitored. Results are reported on an ongoing basis.
Monitoring and Improvement
You conduct internal and external assessments at PREMIS and supervise repairs until they are confirmed effective.
You ensure documentation is up to date and ensure control activities are carried out. You respond to incidents and risks.
Customization and Extensions
Do you need customization for specific technologies, processes, or other standards or regulations?
No problem. PREMIS supports:
extending and modifying compliance templates
including their versioning,
merging templates for different compliance
documentation standards,
template validation and library development.
We support our users in customization and integration with other systems that serve as a source of compliance data.
Collaboration among all involved individuals
PREMIS is a platform for collaboration between the team, internal auditors, and, if necessary, external auditors or subcontractors.
The three main roles are:
compliance planning and defining
detailed requirements,
task execution and delivery
compliance documentation
wverification through reviews and audits.
Participants can communicate directly via chat in PREMIS.
Frequently asked questions
There is no requirement for prior knowledge of NIS 2 or ISO 27001. PREMIS contains the NIS 2 requirements organized and cross-referenced to the relevant sections of this regulation. Therefore, you can easily learn the requirements in PREMIS and refer to the NIS 2 text as needed.
Buy ISO 27001 standard to learn its requirements. PREMIS will then help you implement it.
No problem. Requirements are tagged with standard or regulation symbols. You can mark them as excluded or simply remove them from the template.
You can just as easily expand the compliance template to include other requirements, or develop your own compliance templates specific for your organisation. You will be the only owner of your compliance templates.
To learn more about PREMIS, you can create a free account. You’ll find a button on the menu bar of our website to create a free account. Using a free account will familiarize you with PREMIS and allow you to create any compliance templates yourself, but you won’t have access to the NIS 2 compliance template.
The suggested approach for starting NIS 2 audits is as follows:
- Order the PREMIS for NIS 2 service for one or two people to perform a quick self-assessment of compliance.
- One day is sufficient for a quick self-assessment, but allow a week or two to develop a clear picture of full compliance.
- If necessary, take advantage of our consulting services. While this isn’t usually necessary, we’re always happy to consult on compliance planning, help tailor the process to your organization’s specific needs, and provide user training.
- Check whether the compliance assessment template needs to be adapted to your organization’s specific needs. You can modify and expand it at any time.
- Select a compliance area (the first two areas are key, but you can choose another) and implement it. This will allow you to begin collecting compliance evidence and conducting audits.
Using PREMIS significantly reduces the costs of reviews, verifications, inspections, and audits. Our clients report an increase in inspection efficiency of approximately 30%, which is often associated with improved audit effectiveness.
This is achieved primarily through a focus on compliance objectives and a clear link between objectives and the evidence being reviewed. This goal-based approach facilitates the maintenance of compliance documentation. In particular, change control and document validity functions help manage documentation updates and maintain audit readiness.
You pay for PREMIS services according to the price list on a monthly or annual basis. You can adjust the number of users at any time to meet your current needs. Discounts apply when the user group reaches 50.
The second cost area is consulting services, which can be useful during the PREMIS implementation period. Contact us to plan your implementation and budget.
Data is hosted in a secure data center in Gdańsk, certified for ISO 9001 quality, PCI DSS, and ISO 27001 security, and with a certified ISO 22301 business continuity management system. Data and backups are maintained in Poland. PREMIS can also be hosted in a cloud environment, such as Azure, if required.
We employ an advanced firewall and SIEM system, secure administrative access procedures, and the system is monitored 24/7. We use hardened container images with very limited attack vectors. PREMIS software is developed using a DevSecOps process with automated security tests performed daily. Some of our clients also conduct independent security tests, with consistently excellent results.
If a very high level of security is required, such as for military applications, PREMIS can be hosted in a 2F Game Warden environment, for which PREMIS was approved in 2024 for use at the DoD IL5 data security level. Please contact us directly if you require such a high level of security.
PREMIS can also be hosted in the client’s environment after purchasing a license. In this case, the client manages the security of the services entirely independently. PREMIS does not connect to Argevide servers and can be used within the client’s internal network, completely isolated from external networks.