Compliance

NIS2: what the law asks of you, and what OPEREX adds

NIS2 applies to ORGANISATIONS, not to software — there is no such thing as “NIS2-compliant software”. What a supplier can do is provide transparent, measurable controls and notify you fast enough that you can meet your own deadlines. That is what this page describes.

What we do not claim

We do not claim that using OPEREX makes you compliant. We hold no ISO 27001 certificate, and no external penetration test has been carried out yet. What we do provide: written policies, measurable technical controls, and a notification commitment that serves your 24-hour deadline. We state our gaps on this same page — a supplier who states none has not thereby avoided having them.

Why this concerns you

An organisation in scope of NIS2 must manage its supply chain under Article 21(2)(d) — which makes it accountable for supplier security too. In practice that means three things:

  1. 1Procurement asks suppliers for their security controls — usually through a questionnaire or a statement.
  2. 2The incident reporting deadlines (24-hour early warning, 72-hour report) bind you even when the event happened at a supplier — so how fast the supplier tells you matters.
  3. 3Contracts gain security annexes: notification duties, audit rights, a sub-processor list.

Article 21(2) measures and OPEREX

The ten points below state WHAT the system does in each measure group. We deliberately make no compliance claim — that judgement is yours and the authority’s. Every line rests on a measurable technical property or a written procedure.

What we commit to in an incident

Our notification deadline is set by your reporting duty, not the other way round.

  • Within 24 hours of detection — by email, asking for acknowledgement.
  • We notify even with partial information; we do not wait for the investigation to conclude.
  • We state what we know, what we do not know yet, and when the next update is due.
  • Reporting to the authority is yours; we supply the facts and help with the investigation.

Documents

What you can download or request — separately for procurement and for IT.

Frequently asked questions

Is OPEREX NIS2-compliant?

No such certification exists for software — NIS2 applies to organisations. What we provide: measurable controls, written procedures and a 24-hour notification commitment so you can meet your own obligation.

Do you hold ISO 27001?

No. Instead there is a data processing agreement listing the Article 32 measures, a written incident response plan, an access register, and technical controls guarded by machine gates.

Where is the data stored?

The primary storage location is the EU (Germany), with a self-hosted database and object store. On the production server the data sits on an encrypted volume, and off-site backups go to an EU-jurisdiction store. Transactional email is delivered by a US provider under the EU–U.S. Data Privacy Framework — the privacy notice lists each provider.

Will you complete our security questionnaire?

Yes. We keep prepared answers with evidence references for the common questions, and we will fill in your own format.

What happens if you have an incident?

We have a written plan with severity classes and an evidence-preservation step. We notify you within 24 hours of detection — even with partial information — and supply data for the investigation.

Can it run on our infrastructure (on-premise)?

Yes — the system was built for it: standard Postgres and object storage, vendor-neutral code. A first such deployment is a joint project, not a download.

If we terminate, do we get our data back? And is it deleted?

Both. The return is complete: every data table in machine-readable (NDJSON) and spreadsheet-openable (CSV) form, with a file inventory and a SHA-256 checksum per file — and the manifest names anything deliberately left out, with the reason. Then, on request, a certified deletion: the certificate records what was deleted, the result of the post-deletion verification, and the checksum of the export we handed over first. Data leaves the backups with the rotation, within 90 days at the latest — we say that plainly, because backups are taken of the whole database and cannot be cleaned selectively.

Let's start a pilot

We'll show you OPEREX on your own operational processes — no strings attached.

Request a demo
Newsletter

Follow how OPEREX evolves

New modules, industrial shift-log tips and ISO 45001 practices — once a month at most, no spam.

You can unsubscribe anytime — the link is at the bottom of every email.