Frequently asked questions

About NIS2, GDPR, CRA, and how Nisenta works.

What is NIS2?+

NIS2 is the EU's revised cybersecurity directive. It requires risk management, incident reporting, and supply-chain security for organizations in sectors such as energy, transport, health, and digital infrastructure.

Who is covered by NIS2?+

Companies in NIS2's covered sectors with at least 50 employees or turnover above EUR 10 million are normally classed as essential or important entities and fall under the requirements. Smaller companies can be covered indirectly, e.g. as a supplier to a company that is itself covered.

What's the difference between NIS2 and GDPR?+

NIS2 is about cybersecurity and network security broadly. GDPR is specifically about handling personal data. Many requirements overlap (e.g. incident reporting and risk management), but they are two separate regulations with different supervisory authorities.

What happens if we don't meet the requirements?+

Under NIS2, fines can reach EUR 10 million or 2% of global turnover, and the board can be held personally liable for gross negligence. GDPR fines can reach EUR 20 million or 4% of turnover - whichever is higher.

Do we need the CRA module?+

If you manufacture or sell products with digital elements (hardware or software), you're likely covered by the Cyber Resilience Act, a separate EU regulation. The CRA module is an add-on in Nisenta on top of the base package (NIS2 and GDPR).

What does Nisenta cost?+

Pricing is based on employee count and starts from 990 SEK/month for smaller companies (1-10 employees). Get in touch for an exact price based on your size and any add-ons like the CRA module.

Can several people on our team use the same account?+

Yes. You can invite colleagues to your account, assign them tasks in the gap analysis, and let them contribute without sharing login credentials.

Where is our data stored?+

All data - database and uploaded files - is stored within the EU, in Sweden. See our security and data storage page for full details.

Do you support two-factor authentication?+

Yes, all account types (customer, reseller, and admin) can enable two-factor authentication (MFA) under Security settings.

Can we cancel whenever we want?+

Yes, get in touch with us and we'll help you cancel and get your data out.

Do you use cookies or tracking on the website?+

We use Vercel Web Analytics, a cookie-free analytics service that only counts page views and visit trends in aggregate form - no personal data, no cookies, and no cross-site tracking. That's why there's no cookie consent banner here.

Security & data storageGet started as a customer