Get Started
Directive (EU) 2022/2555 • Commission Implementing Regulation (EU) 2024/2690

Securing network and information systems. And proving that you do.

The NIS2 Directive establishes a unified legal framework to uphold cybersecurity across 18 critical sectors in the EU. It requires you to manage the risk to your network and information systems — and, months later, to show an auditor that you did. TotulDigital collects the traces your systems already produce, checks them daily against the numbered requirements of the Directive's implementing regulation, and writes the record you hand over.

assignment See Live Compliance Record
1,119 Security Checks Tied to Law Mapped to Annex CIR 2024/2690
18 Critical Sectors in Scope Annex I (Essential) & II (Important)
100% Read-Only Telemetry Access Write permissions rejected by design
EU Core Self-Hosted or EU Datacenter Zero CLOUD Act cross-border reach
CIR (EU) 2024/2690 COMPLIANT
public 100% EU Jurisdictions
Continuous Evidentiary Architecture • CIR (EU) 2024/2690 • Six Stages

How TotulDigital turns activity into immutable evidence.

Everything digital leaves a trace. We collect the traces, place them on a unified cryptographic timeline, cross-reference them against live threat intelligence, and deliver two definitive outcomes: immediate warning if something is wrong, and verifiable proof that it is not.

Access Scope security
0% Write

Strict read-only ingestion. Connectors with write scopes are instantly rejected.

NIS2 Timer schedule
24h Clock

Article 23 compliant incident warning clock initiates upon awareness.

Audit Trail history_edu
RFC 3161

Cryptographic append-only ledger sealed daily against tampering.

Sovereign Law flag
100% EU

Zero CLOUD Act liability. All nodes held in audited EU member states.

Pipeline Architecture

The Six Stages of Evidence Conversion

From unorganized operational exhaust to deterministic, courtroom-grade compliance proof under CIR (EU) 2024/2690.

01 inbox

Collection

Your systems already write down what they do: who signed in and from where, which file was opened, what the firewall let through, what changed on a server. Those records are logs. We ingest the logs—the traces of the activity—using strict read-only connectors. Any credential returned with write permission is rejected at connection time rather than retained.

Zero Payload Ingestion
02 alt_route

Correlation

One record on its own means very little. The same account signing in from two countries twenty minutes apart means a great deal. Records from every source merge onto a single timeline, so what they mean together becomes visible—which no single system can see, because each one only holds its own half of the story.

Multi-Source Graph Sync
03 psychology

Enrichment

What is happening in your environment is then compared against what is known to be happening everywhere else: addresses being used in attacks this week, domains registered days ago, file signatures from live campaigns. An EU-hosted or on-premises language model explains findings in human operational terms with zero data egress.

Localized EU Model
04 filter_alt

Triage

Not everything unusual is wrong. A backup job reads thousands of files at night; an administrator signs in from a hotel abroad. Every signal is weighed for what it would actually cost you, the ones with an ordinary explanation are set aside, and what remains reaches a person in the order it deserves without fatigue.

False-Positive Suppression
05 notifications_active

Detection

A break-in already under way, an account taken over, malicious software running, data leaving where it should not. You are told immediately and not in tomorrow's report, because Article 23 counts from the moment you become aware and gives you twenty-four hours to issue an initial warning notification.

Article 23 Clock Active
06 fact_check

Measurement

The same material, read a second way. Every signal is attached to a numbered control of CIR (EU) 2024/2690 and becomes evidence: what you can prove, what you cannot, what was found and whether it was fixed. One report every morning, and a record that does not depend on anyone remembering to write it.

Sealed WORM Daily Record
End-To-End Topology

The Whole Loop, End to End

Where the evidence comes from, how the pipeline processes it, and who takes action. The boundary on the right is the product definition: we measure, your people change things.

TotulDigital evidence pipeline: your estate, six processing stages, and your administrators
hub 01. Your Estate

Read-only ingestion from SaaS (M365, Google Workspace), Cloud platforms (AWS, Azure), on-premises infrastructure, firewalls, and host endpoints. Zero internal data egress.

precision_manufacturing 02. TotulDigital Engine

Automated correlation across disparate timelines, localized AI enrichment, impact triage, CIR (EU) 2024/2690 control mapping, and append-only ledger sealing.

admin_panel_settings 03. Your Administrators

Remediation is carried out exclusively by your team or designated managed provider. TotulDigital holds zero write access; the subsequent collection cycle independently verifies the fix.

fingerprint Architectural Principle

We collect the traces, never the content.

This distinction is the cornerstone of our architecture. A log records that a document was opened, by whom, from where, and at what timestamp. It never contains the document itself. We never read your email, inspect your files, or store customer records. What we preserve is the auditable trace of activity—which is precisely what a National Competent Authority auditor requests.

check_circle Assessor Evidence Compliant (EU data protection / NIS2 Art 21)
block Strict Boundary

What TotulDigital does not do.

We do not remediate, and deliberately cannot. No connector holds write access. No firewall rules are modified, no accounts are disabled, and no files are moved by our platform. All operational remediations are executed by your administrators or managed IT partners. The subsequent collection sweep verifies whether the remediation resolved the finding.

check_circle Zero Remote Execution Surface • Zero Write Credentials
Optional Turnkey Delivery

If you would rather it were done for you.

TotulDigital tells you what is wrong and proves it was fixed. When organizations lack internal capacity, our certified sovereign IT operations partners execute end-to-end remediation under strict approval control.

Inquire About Managed Remediation arrow_forward
01 / DISCIPLINE

What it takes on

Whole operations rather than isolated tasks: tickets, incidents, patch deployment, and change management on the IT side; triage and escalation on the security side. A finding TotulDigital raises becomes an accountable case with an owner, a clear plan, and a verifiable closure date.

02 / AUTHORITY

Who signs

Nothing with consequence runs unsigned. Anything touching a production system escalates to an authorized person on your side. No credential or access policy changes without explicit authorization, leaving an unalterable log for your auditor.

03 / LOCALIZATION

Where it runs

Single-tenant by default. On TotulDigital sovereign bare-metal infrastructure, within your private sovereign cloud, or on your isolated air-gapped hardware with zero internet egress. Compute, models, and ledgers remain entirely under your territorial jurisdiction.

Connector Matrix

What It Reads

Sources are added one at a time, and each connector explicitly states which numbered CIR (EU) 2024/2690 controls it advances. A source that advances none is not offered.

FILTER: 12 CONNECTORS VERIFIED
Source & Scope CIR (EU) 2024/2690 Control Status
cloud
Microsoft 365 & Entra ID Sign-ins, MFA states, administrative privilege changes, external file sharing
Pt 11.2, Pt 11.7 Available
domain
Google Workspace Sign-ins, account activity, Drive DLP events, and organizational sharing
Pt 11.2, Pt 11.3 Available
dns
Linux, Windows & macOS Hosts File integrity monitoring (FIM), system configuration audit, CVE vulnerability scans
Pt 6.9, Pt 6.10, Pt 12.4 Available
laptop_mac
Workstations & Laptops Disk encryption status, local administrator escalation, patch compliance
Pt 11.3, Pt 11.7 Available
router
Firewalls & Network Infrastructure Fortinet, Palo Alto, Cisco, Sophos, SonicWall, pfSense, MikroTik, OPNsense
Pt 6.7, Pt 6.8 Available
cloud_queue
Public Cloud Platforms Amazon Web Services (CloudTrail), Microsoft Azure Monitor, Google Cloud Audit
Pt 3.2, Pt 3.4 Available
badge
Identity & Access Providers Authentik, Keycloak, Okta, Ping Identity, FreeIPA
Pt 11.3, Pt 11.6, Pt 11.7 Available
backup
Virtualization & Backup Systems Proxmox PBS, VMware vCenter, Veeam with air-gap verification checks
Pt 10.1 Available
developer_board
Container Platforms & Orchestration Kubernetes audit logs, Docker socket events, Podman systemd services
Pt 12.4 Available
sync_alt
Aggregated SIEM & Plain Syslog Splunk, Elastic, Graylog, or generic RFC 3164/5424 collectors
Pt 3.2 Available
Self-Assessment Tool

Which of these you actually need depends on what you run.

Describe your environment and you will receive a written sovereign attestation statement detailing the controls it would evidence, and the ones it would not.

verified Strict Non-Disclosure • 0% Marketing Spam
ANNEX I & ANNEX II TAXONOMY

The 18 Sectors in Scope

The obligations do not change by sector; the systems that evidence them do. Size and operational tier together determine whether an entity is Essential or Important under Directive (EU) 2022/2555.

gavel
Non-Compliance LiabilityFines reach €10,000,000 or 2% of global annual turnover. Personal civil liability and executive management suspensions apply.
ANNEX I

Sectors of High Criticality (11)

Subject to Proactive Ex-Ante Audits
bolt
01. EnergyElectricity, Gas, Oil, Hydrogen
01
directions_subway
02. TransportAir, Rail, Water, Road corridors
02
account_balance
03. BankingCredit institutions & clearing
03
trending_up
04. Financial MarketsTrading venues, CCPs
04
local_hospital
05. HealthHospitals, Pharma R&D, Labs
05
water_drop
06. Drinking WaterSupply & distribution systems
06
dns
07. Digital InfrastructureDNS, TLDs, Cloud, Datacenters
07
verified_user
08. ICT Service MgmtB2B MSPs & Managed Sec (MSSP)
08
opacity
09. Waste WaterCollection, disposal & treatment
09
assured_workload
10. Public AdministrationCentral and regional authorities
10
satellite_alt
11. SpaceGround telemetry & satellites
11
verified
Verify Entity ClassArticle 3 Rules & Turnover
ANNEX II

Other Critical Sectors (7)

Ex-Post Oversight
local_shipping
12. Postal & Courier ServicesExpress freight, parcel networks
12
recycling
13. Waste ManagementCollection, recovery & disposal
13
science
14. Manufacture of ChemicalsBase chemicals & compounds
14
agriculture
15. Food Production & DistIndustrial processing & supply
15
precision_manufacturing
16. ManufacturingMedical devices, machinery, electrical
16
cloud
17. Digital ProvidersOnline marketplaces, SaaS, search
17
biotech
18. Research OrganisationsScientific & technical institutes
18
THE FOUNDATIONAL PHILOSOPHY

Being secure and proving it are two different jobs.

Think of the fire extinguishers in your building. Having them is not enough. Someone signs a sheet every month to say they were checked, and that sheet is what an inspector asks for. Security now works the same way. The law does not only ask whether you are watching — it asks you to produce the record. Most organisations are doing far more than they can show.

Continuous Record
  • check_circle Generated every single morning
  • check_circle Tied line-by-line to CIR 2024/2690
  • check_circle Records open, closed, & recurring findings
01 / INTEGRITY lock

100% Read-Only Access

TotulDigital connectors request read scopes exclusively. A credential returned with write permission is rejected at connection time rather than retained. We inspect without the power to alter.

02 / JURISDICTION public

Self-Hosted or EU Managed

Identical software, deployed directly into your own enterprise network or operated in our sovereign European Datacenters (planned EU regions). Zero US CLOUD Act exposure.

03 / VERIFICATION sync_saved_locally

Remediation Verification

Each finding includes a structured remediation plan executed by your administrators. Subsequent automated collections record the outcome as verified closed, unresolved, or recurring.

DAILY AUDITABLE RECORD

This is what arrives each morning.

One page. The number on the left is the legal control each line answers; your team does not need to memorize it, but the NIS2 national auditor (e.g., DNSC, the German federal cyber authority, ANSSI) will verify against it.

LEDGER ARCHIVE ID: CL-2026-0919-001 • Daily Snapshot of 19 September 2026
7 Opened 4 Verified Closed 1 Recurring
Annex Point CIR 2024/2690 Requirement Cryptographic Observation Telemetry Status
Point 11.2 Management of access rights A sharing link created in March remains active on a document restricted on 28 August. Retrievable by any holder without authentication. Recurring (closed 2 Sep)
Point 6.7 Network security A firewall rule permits inbound connections from any external IP address directly to the internal finance database server. Open
Point 3.4 Event assessment and classification A workstation sent 4.2 GB of data to an unrecognized autonomous system between 01:00 and 04:00 UTC. Open
Point 11.7 Multi-factor authentication Four accounts with domain administrative privileges authenticate with single-factor password only. Open (rec 14 Sep)
Point 11.3 Privileged accounts The superuser administrator credential for the core HR ERP platform is concurrent and shared by 2 operators. Open
Point 6.8 Network segmentation General workstation VLAN has direct IP route to hypervisor management cluster without micro-segmentation. Open
Point 12.4 Asset inventory Three rogue Linux servers discovered transmitting telemetry on secondary subnet; absent from approved CMDB. Open
Point 11.5 Identification Shared finance mailbox signs in via generic service account with non-attributable authorization. Open
Point 3.2 Monitoring and logging Application server stopped syslog stream at 02:14 UTC. Resumed 14 hours later following agent restart. Verified closed
Point 6.9 Malicious software Quarantined ransomware dropper signature on accounting endpoint; hash revoked across cluster fleet. Verified closed
Point 10.3 Termination procedures HR termination date was recorded as 18 August; credentials stayed active for 31 days. Session revoked 19 Sep. Verified closed
Point 6.10 Vulnerability handling Three critical CVEs on perimeter reverse proxy patched; verification scan confirmed complete mitigation. Verified closed
Point numbers and requirement titles reproduced from the Annex to Commission Implementing Regulation (EU) 2024/2690. EUR-Lex Official Annex open_in_new
ARTICLE 21 • POINTS 11.2 & 12.1

Who outside your organisation can open your files.

Every file and folder reachable from outside, sorted by how far it reaches. The worst kind is a link that needs no sign-in at all: anyone who has the address can open the file, nobody is recorded as having done so, and it keeps working even after you think you have locked the file down.

INSIDE YOUR ORGANISATION home_storage
  • folder Finance & Auditing
  • folder HR & Personnel Records
  • folder Board Minutes & Governance
  • folder Project Engineering Archive
  • folder Shared Corporate Storage

And everywhere else your enterprise stores unstructured data.

REACHABLE FROM OUTSIDE Active Exposure Vector
People outside your organisation each one named
148 external
Audited and listed in daily ledger
Shared with "Everyone" passed down hierarchy
31 global
Inherited recursive permissions
Links needing zero sign-in (anonymous URL)
63 unauthenticated
No identity recorded, no expiry date
warning 9 of these anonymous links open documents marked as confidential or restricted.
TECHNICAL SPECIFICATION

Which controls a real environment evidenced.

One page out of the same report. Approximately one-third of the numbered controls in CIR (EU) 2024/2690 are evidenced by telemetry. The remainder are reported as open documentary items. Coverage claims that exceed what a monitoring system can observe do not survive an audit.

Engine: 4,512 Telemetry Checks Examined
Legal Ref CIR 2024/2690 Control Name Automated Detections Evidenced in Audit Record
11.6 Authentication 302 check_circle Yes
3.2 Monitoring and logging 167 check_circle Yes
6.9 Protection against malicious and unauthorised software 155 check_circle Yes
11.2 Management of access rights 140 check_circle Yes
3.4 Event assessment and classification 135 check_circle Yes
6.7 Network security 70 check_circle Yes
11.3 Privileged accounts and system administration accounts 30 info Partial
11.7 Multi-factor authentication 2 Requires an identity source
verified
Built on Proven Open Source Security Architecture Hardened collection agent integration (GPLv2) mapped with 192 proprietary TotulDigital legal rulesets.
Engine Version 0.6.1-EU
ASSESSMENT

Find out where you stand.

Tell us what your organisation runs — five lines is enough — and we will tell you which parts of the law you could prove today and which you could not. Written, transparent, and no sales call required.

Response provided under NDA within 24 hours
EUR-LEX & ENISA SOURCES

Legal Texts

Every figure, deadline, and title is quoted verbatim from official EU texts:

TotulDigital SRL • Bucharest, Romania • EU Sovereign Cloud