160,000+ organizations in the EU are now in scope for NIS2, and the clock is ticking.
NIS2 is 10 controls,a 72-hour clock,and your signature.
Miss any of it, and it's up to €10M, or personal liability.
Alexus AI makes every part provable, from the operations you already run.
Two ways to prove NIS2.
- Screenshots and spreadsheets, re-gathered every audit
- Evidence that’s stale the day after you collect it
- A blank page at 2am when an incident hits
- Weeks of consultant time to prove one control
- One live graph of every asset, change and control
- Evidence that stays current as you operate
- 24h / 72h reports pre-assembled and waiting
- An answer to any control in minutes, not weeks
The operations you already run, turned into NIS2 evidence — live.
Under the hood it is one continuously-updated graph: every change, incident, access grant and asset your tools already record, linked together and scored against each NIS2 measure.
The evidence was always there. Now it's continuous.
Compliance you can prove.
The evidence NIS2 asks for (Articles 21, 23 and 20) as a by-product of the operations you already run.
Continuous readiness scoring
A live score against all 10 NIS2 measures, each with a per-control evidence trail.
- All 10 measures, continuously scored
- Gaps surfaced before the auditor
CSIRT incident reporting
24-hour and 72-hour reports, pre-formatted for each national CSIRT, not a spreadsheet.
- 24h early-warning + 72h full report
- Aligned to national CSIRT formats
Operational audit trail
Every change logged (actor, source, timestamp), hash-chained and replayable.
- Actor · source · timestamp
- Reports become a query
Executive Accountability Pack
A quarterly, audit-grade pack for boards, regulators and D&O insurers.
- Board & regulator ready
- Personal-liability defensibility
Operations in. Evidence out.
Operate
Run IT ops exactly as you already do
Capture
Every change logged: actor · source · time
Score
Live readiness across Article 21's 10 measures
Report
24h / 72h CSIRT reports, pre-formatted
Prove
Board & auditor-ready evidence pack
Where Alexus fits.
That model on the left depicts how Alexus fits in your IT estate, i.e. your service desk, cloud or identity tools (without replacing them), connecting to every tool and producing NIS2 evidence from the operations you already run.
This connection is what allows us to "query" the estate and produce a live, continuously-updated lineage of your assets, changes, access grants and owners.
Ticketing · CMDB · AI Service Desk
Runs over your service desk, or replaces it.
Observability · Alerting · Codebase
Signal from monitoring, paging and code.
GRC / Compliance Evidence
The operational-evidence layer over your GRC stack.
Reads from the tools you already run.
No rip-and-replace, the more Alexus sees, the richer the evidence.
The auditors won't wait. Neither should you.
NIS2 is transposed into national law across the EU. Essential and important entities can be assessed at any time, with evidence expected on demand, not at quarter-end.
“The reports come out in the exact shape our national CSIRT expects — the 24-hour clock stops being the thing that keeps me up at night.”
Questions, answered.
Is Alexus a replacement for our ITSM or SIEM?
No. Alexus reads from the tools you already run and turns their data into evidence. There’s nothing to migrate.
How fast can we see a readiness score?
Connect a first source and you’ll see an initial Article 21 picture the same day — it sharpens as more of your stack is linked.
Does this cover more than NIS2?
Yes. The same evidence maps to ISO 27001, SOC 2, GDPR and DORA — one graph, many frameworks.
Who is Alexus built for?
CISOs, IT and security leaders at essential and important entities in NIS2 scope across the EU.
Where is our data hosted?
AWS Frankfurt by default, with an EU-only data path. No US transfer for EU customers.
Do you replace our GRC tool?
No — we add the operational-evidence layer underneath Vanta or Drata: what your systems actually did.
Keep exploring
See how Alexus shows up in real teams, then explore the Phase 2 agent.