Reconectando con el servidor
Mantén esta pestaña abierta: tu trabajo no se ha perdido.
No hemos podido reconectar
Recarga la página para continuar donde lo dejaste.
La sesión ha caducado
Vuelve a cargar la página para iniciar sesión de nuevo.
Screens from DSA Compliance v6.2 in a demo environment. All data shown is fictitious.
For information only, not legal advice. Always check against the consolidated text in force.
NIS2: up to €10,000,000 or 2 % of worldwide turnover for essential entities, with personal liability for the management body. GDPR art. 32: up to €10,000,000 or 2 %. Chilean Act 21.663: up to 20,000 UTM. And in several jurisdictions the penalty reaches the director personally, not only the company.
The badges identify the obligation the program digitises. They are not certifications or conformity accreditations.
This programme implements certifiable ISO standards. If your organisation already is, here you see which part is solved and which laws it covers in each country where you operate.
No, and no software can. Certification is granted by an independent accredited body. What the programme does is prepare the system and gather the evidence so that audit can be passed, and hand it over in the format it is asked for.
From the country of the affected assets and the kind of data compromised. Every obligation in the catalogue carries its legal basis, its authority, its deadline and the moment from which it is counted —which is not the same in every rule. If the starting datum is missing, awareness is used, which always yields the shortest deadline.
Not all of them. Around a quarter are already evidenced by another programme you have —training, supplier vetting, the processing register, the asset inventory, workplaces— with real, dated proof, and they recompute themselves.
It covers much of the ground, but not all of it. What NIS2 adds and has to be solved separately are the fixed notification deadlines, registration with the national authority and the express liability of the management body. The programme shows that gap instead of hiding it.
A read-only access scoped to the modules within that audit's scope, with a mandatory expiry date and an insert-only record of everything the auditor looked at. It works the same for ISO 27001, for data protection and for health and safety, because a company is audited on several things at once.
Through three separate channels, and hardly anyone has the third. Two are inbound: the security notice — a laptop left on a train, an account still live after someone leaves — and suspected phishing, where what matters is the reporting rate. The third is outbound: nothing comes in through it; what goes out is what the organisation files with the CSIRT, the data authority or the supervisor, and every filing keeps its registration reference. Control A.6.8 asks for exactly that event-reporting channel.
The programme cross-checks what the organisation has declared against the countries where it actually holds assets and has had incidents, and flags three different gaps: what is declared but the catalogue cannot yet measure, the countries where you operate without having declared anything, and — the one nobody shows — the countries our catalogue does not reach yet. That last one is stated in those words, because it is our gap and hiding it would be worse. Declaring or not declaring switches off no obligation: the law applies either way, and the deadline clock never looks at that tick box.
A 30-minute guided demo on the real platform, or a one-hour assessment session with a consultant.