Audit NIS2 Complete
EU NIS2 audit operating system
$89.99 · Designed for iPad. Not verified for macOS.
One client, one NIS2 file, one complete audit trail. 76 controls mapped to ISO 27001, NIST CSF and CIS. Article 23 deadlines counted from the moment you became aware.
The working file of the NIS2 auditor. Not a checklist, not a PDF generator — a digital dossier carrying one client from classification through evidence, findings and corrective actions to the signed report.
ONE CLIENT → ONE NIS2 FILE → ONE COMPLETE AUDIT TRAIL
CLASSIFICATION THAT SHOWS ITS WORKING
The applicability engine determines whether an entity falls under Directive (EU) 2022/2555 and, if so, whether it is essential or important. Every step states the article it relied on — the Article 2(1) size cap, the size-independent triggers of Article 2(2), Article 3(1) and 3(2) — and the size test follows Article 2 of the Annex to Recommendation 2003/361/EC. Where the answer belongs to the Member State rather than the Directive, the engine returns MANUAL LEGAL REVIEW instead of guessing.
30 JURISDICTIONS
The 27 EU Member States plus the three EEA-EFTA states, each with competent authority, national CSIRT, single point of contact, registration and incident portals, and the national transposing act. Every entry carries its source, version and last-checked date, and is flagged UNVERIFIED until you confirm it. Nothing is hard-coded: a legislative change is a registry version, not a new build.
76 CONTROLS, FOUR FRAMEWORKS
The full Article 21(2)(a)–(j) risk-management measures, Article 20 governance and the Article 23 reporting chain — 76 controls in 12 domains, each with the audit question, guidance on how to test it, the legal basis, and mappings to ISO/IEC 27001:2022 Annex A, NIST CSF 2.0 and CIS Controls v8.
EVIDENCE VAULT WITH CHAIN OF CUSTODY
Every item gets an EVD identifier, a SHA-256 fingerprint, an uploader, a timestamp and the controls it supports. Eight integrity checks flag duplicate content, documents dated after they were requested, stale policies and expired certificates — as alerts to weigh, never as verdicts.
ARTICLE 23, COUNTED CORRECTLY
Early warning within 24 hours, notification within 72 (24 for trust service providers where trust services are affected), intermediate report on request, final report one month after the notification you actually sent — or a progress report, then a final report one month after handling completes. All clocks run from becoming aware. In an EEA-EFTA state, where the Directive is not yet incorporated, the app says so instead of running a countdown that does not bind.
FINDINGS, CAPA AND RISK
Observations, opportunities, minor and major non-conformities and critical findings, each tied to its control and legal requirement. Corrective actions run OPEN → IN PROGRESS → EVIDENCE SUBMITTED → AUDITOR REVIEW → CLOSED. A 5×5 risk register with inherent and residual scoring.
REPORTS IN PDF AND WORD
A twelve-section final report composed entirely from what you recorded. PDF, Word (.docx) and printing render from the same source, so the filed and printed copies cannot diverge. Below 90% control coverage the report refuses to state a favourable conformity conclusion, and says why.
SIXTEEN ROLES, FULLY OFFLINE
Lead auditor, NIS2 officer, CISO, CSIRT lead, DPO, legal, observer and more, across 23 permissions. Everything runs on device: no account, no server, no tracking, no third-party SDK.
TAMPER-EVIDENT AUDIT TRAIL
Every operation records who, what, when and from which device, in a hash chain where each entry commits to the one before it. Deleting or editing a record breaks the chain, and the app can prove it.
PRICING
A single purchase. No subscription, no in-app purchases, no recurring charge. New Country Pack and control-catalogue versions arrive through free app updates as national law changes.
IMPORTANT
Results are technical assessments based on Directive (EU) 2022/2555 and the data you enter. They are not legal advice and do not replace verification of national transposing law. For financial entities, Regulation (EU) 2022/2554 (DORA) applies as lex specialis under Article 4 NIS2.
Terms of Use (EULA): https://www.apple.com/legal/internet-services/itunes/dev/stdeula/
Ratings & Reviews
- This app hasn’t received enough ratings or reviews to display an overview.
The developer, Stefan Epistatu, indicated that the app’s privacy practices may include handling of data as described below. For more information, see the developer’s privacy policy .
Data Not Collected
The developer does not collect any data from this app.
Accessibility
The developer has not yet indicated which accessibility features this app supports. Learn More
Information
- Seller
- Stefan Epistatu
- Size
- 20.4 MB
- Category
- Business
- Compatibility
Requires iOS 17.0 or later.
- iPhone
Requires iOS 17.0 or later. - iPad
Requires iPadOS 17.0 or later. - Mac
Requires macOS 14.0 or later and a Mac with Apple M1 chip or later. - Apple Vision
Requires visionOS 1.0 or later.
- iPhone
- Languages
- English and Romanian
- Age Rating
4+
- 4+
- Copyright
- © 2026 Ștefan Epistatu

