Automation · NIS2 and Compliance Documentation

NIS2 doesn't fail in mid-market companies through lack of understanding—it fails at hour zero.

The requirements are clear: early warning within 24 hours, follow-up report within 72, final report after one month. The problem is that when an incident is happening, no one has time to note timestamps and sort evidence. We build the process that handles this in the background, so your team can work on resolving the incident instead of filling out forms.

The Problem

The incident report isn't the problem—the evidence chain afterward is.

When an incident occurs, every hour counts, yet later only documentation determines whether you fulfilled your obligations. If you start reconstructing who noticed what and who was informed only after the incident, you've already lost the evidence chain.

  • 01The moment of discovery is nowhere recorded, yet that's exactly where the 24-hour deadline begins.
  • 02Evidence lies scattered across monitoring tools, Teams chats, and private mailboxes instead of attached to one incident record.
  • 03There's no clear process for who reports, who covers for them, and what happens if the incident is discovered Friday evening.
  • 04For annual proof of compliance, the same documents must be hunted down every year, even though they accumulate throughout the year.
Use Cases
01

What we specifically build around NIS2.

We automate the workflow and documentation side, not the legal assessment. Each component works independently, you don't have to wait for a full project.

01

Incident Record from Minute One

As soon as an incident is reported or an alarm triggered, a record is created with timestamp, reporter, and initial assessment. Everything else attaches to this record instead of disappearing into chats. The moment of discovery is documented before anyone has to think about it.

Impact Timeline documented instead of reconstructed
02

Deadline Clock for All Three Reporting Levels

The workflow calculates the deadlines for early warning, follow-up report, and final report from the discovery timestamp. Reminders go to the responsible person in time, then to their cover. No deadline slips because someone was on vacation.

Impact Alert before deadline, not after
03

Prepare Report Draft Instead of Searching for Forms

The workflow compiles the information needed for the report: type of incident, affected services, current assessment, timeline. This becomes a draft that your responsible person reviews and approves. Nothing is sent automatically—the decision stays with a human.

Saving Review draft instead of starting from scratch
04

Collect Evidence Continuously, Not Once a Year

Training records, audit protocols, permission reviews, and vendor documents accumulate where they're created anyway and get assigned to the right compliance point. If a document is missing, the workflow alerts the responsible person in advance. Your file is always current, not just before an audit.

Saving No last-minute scramble before deadline
05

Define Roles, Coverage, and Escalation

Who reports, who decides, and who takes over outside business hours is stored in the workflow, not in a document no one opens during a crisis. The notification goes down the chain until someone confirms. The process can be practiced without needing a real incident.

Impact Covered even on Friday evening
Solution Paths

How we build the reporting process.

Which path fits depends on what's already running at your place and how strict your data residency requirements are. We clarify that in the initial analysis.

Workflow Automation
n8n On-Premises

n8n receives alarms from your existing monitoring tools, creates the incident record, and runs the deadline clock. Runs on a server in Germany or in your own environment, which is often a requirement for security incidents. Every step is logged and auditable afterward.

Microsoft 365
Evidence Repository in SharePoint and Teams

If you use Microsoft 365, we set up the incident record and documentation structure where your team already works. Permissions, version history, and retention follow the rules you've already set. Notifications and approvals flow through Teams.

Assessment
Governance Before Automation

Before any workflows are built, it must be clear which obligations apply to you and who is responsible. We develop this together with you in AI and process consulting, working alongside your legal counsel. Without this clarity, you automate the wrong process very efficiently.

How We Work

The 30-Day Model.

A solid first reporting process is live in 30 days, at an agreed fixed price. No open timesheets and no compliance project that runs for a year.

1

Week 1: Initial Analysis and Inventory

We review what monitoring exists today, where incidents are recorded, and what documentation already exists. You get an honest list of gaps, even if it's longer than hoped.

2

Week 2: Define Roles, Deadlines, and Reporting Paths

You define who reports, who covers, and at what point an incident counts as significant. We document these decisions so they can be translated into a workflow and coordinate them with your legal counsel.

3

Week 3: Build and Rehearse the Emergency Response

The process is built and tested with a simulated incident. This usually reveals where the chain breaks in practice, so it can be fixed before a real crisis.

4

Week 4: Handover with Documentation and Training

You receive documentation, training for responsible persons, and a dedicated contact. You can adjust deadlines, roles, and compliance checkpoints yourself afterward.

Not quite your case

Is it less about NIS2 and more about bringing order to your operations?

Many organizations discover during preparation that the problem isn't the reporting requirement but missing processes overall. In that case, an inventory of your operations is a better starting point than a compliance module.

View AI Consulting
Free Initial Analysis

Would you know today when the 24-hour deadline started?

In the free initial analysis, we spend 60 minutes walking through how an incident would actually unfold at your organization today and where your evidence chain breaks. No obligation, and you get the assessment even if we don't work together.

  • Fixed price instead of open timesheets
  • You retain control over every report
  • Runs entirely in Germany if you prefer
Frequently Asked Questions
05

What responsible parties often ask about NIS2.

Does NordFlux replace our legal counsel?

No, and that's a clear boundary. Whether you fall under the NIS2 implementation law, qualify as a critical or essential entity, and what that means legally—that's your legal counsel's domain. We build the workflows and documentation that follow from that classification and work alongside your legal team.

Does the system automatically send a report to BSI?

No. The workflow prepares a draft and monitors the deadline, but it's only sent after explicit approval by your responsible person. Automatic reporting would be wrong in principle, because the early warning itself requires an assessment that a human must take responsibility for.

We missed the registration deadline—can it still be salvaged?

BSI's grace period ended in summer 2026; systematic audits have since begun. How to handle a missed registration deadline is a question for your legal counsel and BSI, not for us. On the operational side: a solid reporting organization can still be built in reasonable time, and it's the part you'll need anyway.

We don't have our own security team—is it still worth it?

Especially then. The effort doesn't come from team size; it comes from the deadlines, and those apply regardless of how many people you have. A small team benefits most from timestamps, alerts, and evidence accumulating without extra manual work.

Do we need to buy new security tools for this?

Usually not. We build on the monitoring and storage already running at your place and connect them into a traceable chain. If something is genuinely missing, we'll say so directly instead of hiding the gap with a workaround.

Automate NIS2 Incident Reporting | NordFlux