NIS2: what the law asks of you, and what OPEREX adds
NIS2 applies to ORGANISATIONS, not to software — there is no such thing as “NIS2-compliant software”. What a supplier can do is provide transparent, measurable controls and notify you fast enough that you can meet your own deadlines. That is what this page describes.
- 10/10Article 21(2) measures mapped
- ≤24 hincident notification to you
- EUprimary data residency, on an encrypted volume
- 117/117tenant tables isolated at database level
What we do not claim
We do not claim that using OPEREX makes you compliant. We hold no ISO 27001 certificate, and no external penetration test has been carried out yet. What we do provide: written policies, measurable technical controls, and a notification commitment that serves your 24-hour deadline. We state our gaps on this same page — a supplier who states none has not thereby avoided having them.
Why this concerns you
An organisation in scope of NIS2 must manage its supply chain under Article 21(2)(d) — which makes it accountable for supplier security too. In practice that means three things:
- 1Procurement asks suppliers for their security controls — usually through a questionnaire or a statement.
- 2The incident reporting deadlines (24-hour early warning, 72-hour report) bind you even when the event happened at a supplier — so how fast the supplier tells you matters.
- 3Contracts gain security annexes: notification duties, audit rights, a sub-processor list.
Article 21(2) measures and OPEREX
The ten points below state WHAT the system does in each measure group. We deliberately make no compliance claim — that judgement is yours and the authority’s. Every line rests on a measurable technical property or a written procedure.
a)Risk analysis, information security policies
A gap register with tracked identifiers, plus operational policies (incident response, access management, offboarding); a formal risk register and a regular review cycle are being established.
b)Incident handling
A written incident response plan with severity classes, an evidence-preservation step and a customer notification template. Detection: deep health checks, a log watcher and a push alert channel, plus external availability monitoring. Logs are copied off the server daily (90-day retention), so evidence survives a wiped local trail.
c)Business continuity, backup
Self-verifying off-site backups every 6 hours (SHA-256 read-back) with roughly a 6-hour recovery point, into an EU-jurisdiction store with a 90-day long-term tier. Restores are proven by drill, not assumed.
d)Supply chain security
A published sub-processor list in the legal documents, with 30 days' notice before engaging a new one. The software supply chain is built on locked dependencies, automated vulnerability tracking and a secret-leak gate. On exit, a complete data handover (every data table in machine-readable and spreadsheet form, with a file inventory and checksums), followed on request by a certified deletion.
e)Acquisition, development, vulnerability handling
Every change passes automated checks (tenant-isolation tests, a security scan, a secret gate), and a release cannot start until those are green. Vulnerability reports are received through an RFC 9116 channel.
f)Assessing effectiveness
Controls are guarded by machine gates that we deliberately break to measure — so it is proven that the gate actually catches. Independent code audits run regularly; an external penetration test is scheduled.
g)Cyber hygiene, training
Documented operating procedures and an access register; for the organisation using the product, the Help centre and Knowledge base provide usage guidance.
h)Cryptography, encryption
TLS on all traffic with HSTS; on the production server the database, the file store and local backups sit on an encrypted volume; passwords are hashed and two-factor secrets separately encrypted.
i)Access control, asset management
Invitation-only account creation, role-based access control, tenant isolation enforced at the database level and an append-only audit trail whose modification and deletion the database refuses for EVERY role. A maintained asset and access register, reviewed quarterly.
j)Multi-factor authentication
TOTP-based two-factor authentication is mandatory for platform administrator access and can be enforced per organisation for tenant administrators. On the operator side it is active on every external provider console.
What we commit to in an incident
Our notification deadline is set by your reporting duty, not the other way round.
- Within 24 hours of detection — by email, asking for acknowledgement.
- We notify even with partial information; we do not wait for the investigation to conclude.
- We state what we know, what we do not know yet, and when the next update is due.
- Reporting to the authority is yours; we supply the facts and help with the investigation.
Documents
What you can download or request — separately for procurement and for IT.
- NIS2 supplier data sheet (PDF)The Article 21(2) a)–j) mapping, our notification commitment, and stated limits. This is what procurement asks for.
- Security overview (PDF)Data isolation, audit trail, data residency, platform hardening. This is what IT asks for.
- Security pageThe technical depth: what protects your data today — measured — and where we are.
- Data processing agreementThe Article 28 GDPR agreement: sub-processors, Article 32 measures, notification deadline.
Frequently asked questions
Is OPEREX NIS2-compliant?
No such certification exists for software — NIS2 applies to organisations. What we provide: measurable controls, written procedures and a 24-hour notification commitment so you can meet your own obligation.
Do you hold ISO 27001?
No. Instead there is a data processing agreement listing the Article 32 measures, a written incident response plan, an access register, and technical controls guarded by machine gates.
Where is the data stored?
The primary storage location is the EU (Germany), with a self-hosted database and object store. On the production server the data sits on an encrypted volume, and off-site backups go to an EU-jurisdiction store. Transactional email is delivered by a US provider under the EU–U.S. Data Privacy Framework — the privacy notice lists each provider.
Will you complete our security questionnaire?
Yes. We keep prepared answers with evidence references for the common questions, and we will fill in your own format.
What happens if you have an incident?
We have a written plan with severity classes and an evidence-preservation step. We notify you within 24 hours of detection — even with partial information — and supply data for the investigation.
Can it run on our infrastructure (on-premise)?
Yes — the system was built for it: standard Postgres and object storage, vendor-neutral code. A first such deployment is a joint project, not a download.
If we terminate, do we get our data back? And is it deleted?
Both. The return is complete: every data table in machine-readable (NDJSON) and spreadsheet-openable (CSV) form, with a file inventory and a SHA-256 checksum per file — and the manifest names anything deliberately left out, with the reason. Then, on request, a certified deletion: the certificate records what was deleted, the result of the post-deletion verification, and the checksum of the export we handed over first. Data leaves the backups with the rotation, within 90 days at the latest — we say that plainly, because backups are taken of the whole database and cannot be cleaned selectively.
Let's start a pilot
We'll show you OPEREX on your own operational processes — no strings attached.
Request a demo