NIS2 asks for proof. Have yours ready.
Your customers, insurer and auditor ask for it too. AI Monks checks what your company exposes online, around the clock, and keeps the evidence ready.
Not sure NIS2 applies to you? Take the 30-second checkJoin the waiting list and get
- First access, before we open to everyone later this year
- An exclusive launch discount, only for the waiting list
- Your first scan explained by a Monk, in plain English
Join the waiting list
Takes 30 seconds. No obligation, no sales sequence.
NVIDIA Inception
Member of NVIDIA's start-up programme
ISO 27001 lead auditors
on the team that builds it
A decade on watch
for banks, governments and hospitals
Portal data stored in the EU
Data processing agreement on request
Does NIS2 apply to your company?
Three questions for a plain first answer. Your result carries over to the waiting-list form, so you only tell us once.
How many people work at your company?
Does your company work in one of these sectors?
Do customers ask you to prove your security?
Answer all three questions to see where you stand.
A first indication, not legal advice. Your national law decides: the Cyberbeveiligingswet (NL), the NIS2 law of 26 April 2024 (BE) or the NIS2UmsuCG (DE).
Three ways NIS2 reaches your company.
NIS2 is the EU's cybersecurity law. It has applied in Belgium since October 2024, in Germany since December 2025 and in the Netherlands since 15 August 2026.
You are in scope.
You have 50 or more people, or over €10 million in both turnover and balance sheet, and work in one of the 18 sectors NIS2 names, such as manufacturing, food, transport, health, energy or managed IT. You take proportionate measures and report significant incidents within 24 hours.
Your customers are in scope.
Companies under NIS2 must manage the security of their direct suppliers. That is you. Expect questionnaires, contract clauses and requests for evidence.
Insurers and auditors ask anyway.
Insurers, auditors and large customers ask the same questions, NIS2 or not. What do you expose online? Is your email set up safely? How do you know, today?
A plain-language summary, not legal advice. Your national law decides: the Cyberbeveiligingswet (NL), the NIS2 law of 26 April 2024 (BE) or the NIS2UmsuCG (DE). Companies in a group count together, and DNS, domain registry, trust and telecom services are covered at any size.
What the outside world sees. Checked around the clock.
Nothing to install, no passwords, no access to your systems. Every issue comes with a plain-English fix, sorted by severity.
Your open doors
Every domain, subdomain, server and open port linked to your name, including the ones you forgot.
Your email
Whether someone could send email in your name. SPF, DKIM and DMARC, checked and explained.
Your certificates
Expiry, trust chain and encryption strength, so no visitor ever sees a security warning.
Your uptime
Your site checked continuously from several countries. We tell you when it goes down, and when it comes back.
Breaches and leaks
Breaches tied to your company name, yours and your suppliers'.
Your suppliers
How exposed the vendors you depend on are, and where many of your services lean on the same one.

One honest number, and everything behind it.
Your cyber risk score, graded and ranked, with the issues that drive it and a fix for each. This is the AI Monks Portal as it stands today.
Uptime, breach and supplier checks come with Professional.
Where we help with NIS2. And where we don't.
Article 21 lists ten groups of measures, in proportion to your size and risk. From the outside, we help with nine of them, three directly. The tenth happens inside your company, out of our sight.
| Art. 21 | Measure | AI Monks | What that means for you |
|---|---|---|---|
| (a) | Risk analysis and security policies | Partial | An independent outside view to feed your risk analysis. The policies themselves are yours. |
| (b) | Incident handling | Partial | We tell you the moment your site goes down or your DNS changes. Reporting to the authority stays with you. |
| (c) | Business continuity | Partial | Uptime watched from several countries. Backups and recovery plans stay with you. |
| (d) | Supply chain security | Direct | See how exposed your suppliers are, and show your own posture to the customers who ask. |
| (e) | Vulnerability handling | Direct | Every weakness visible from outside, ranked by severity, with a plain-English fix. |
| (f) | Checking that measures work | Direct | A time-stamped score and its history, so you can show the trend, not just today. |
| (g) | Cyber hygiene and training | Partial | We check the hygiene visible from outside, like email records and exposed services. Training your people is yours. |
| (h) | Cryptography and encryption | Partial | Certificates and encryption on your public services, checked continuously. Encryption inside is yours. |
| (i) | Access control and asset management | Partial | Every domain, server and port you expose, mapped. People and access rights are yours. |
| (j) | MFA and secured communication | Not covered | This happens inside your company, where we do not look. |
- (d)Supply chain security
- (e)Vulnerability handling
- (f)Checking that measures work
- (a)Risk analysis and policies
- (b)Incident handling
- (c)Business continuity
- (g)Cyber hygiene and training
- (h)Cryptography and encryption
- (i)Access control and assets
- (j)MFA and secured communication
Directors answer for it.
Your board approves and oversees these measures and can be held liable under national law. One honest number, in plain English, makes that oversight practical.
24 hours to raise the alarm.
A significant incident needs an early warning within 24 hours. You can only report what you notice.
Straight answers.
Will AI Monks make us NIS2 compliant?
No tool can, and there is no NIS2 certificate. The law is mostly about governance and process. We cover the outside-in part: what you expose, how it changes, and the evidence that you are on top of it.
We have fewer than 50 people. Does NIS2 apply?
Usually not directly, unless your turnover and balance sheet both exceed €10 million, counted with your group, or you provide DNS, domain registry, trust or telecom services. Your customers in scope will still check you as a supplier.
What will it cost?
Packages start at €95 a month per organisation. Uptime, breach and supplier checks start with Professional at €180. People on the waiting list get an exclusive launch discount.
What happens after I sign up?
We keep quiet until launch, later this year. Then you get your invitation and your offer by email. No newsletter, no sales sequence.
Be ready before anyone asks.
Join the waiting list for first access and a launch discount no one else gets.
Join the waiting list →