Clear Responsibility Allocation

NIS2 Advisory: Prepare Your IT Infrastructure for Compliance Audits

The NIS2 directive has entered into force, and for the more than 6,000 covered Danish companies, cybersecurity is now a board-level legal requirement. At Stratu, we do not operate like a traditional law firm. Instead, we act as your technical advisory partner. We help you navigate Article 21 by identifying which parts of your security responsibilities can advantageously be delegated to us as your provider. With our dedicated NIS2 contractual addendum, you gain full transparency into the division of responsibilities between customer and provider, ensuring you are always prepared to demonstrate due diligence to regulators and auditors.

NIS2 Contractual Addendum

Gain complete clarity on responsibilities. We have developed a dedicated addendum to our contracts that clearly defines the obligations between you and Stratu in relation to NIS2 requirements.

System Design for NIS2

We advise on processes and system design that support the legal requirements for operational continuity, including the design of independent backup and disaster recovery systems.

SOC & Response Times

Meet the requirements for rapid incident handling. Our ITSOC delivery ensures fast response times and documented root cause analysis, as required by law in the event of critical incidents.

From Legislation to Infrastructure

Can you document your technical compliance?

Previously, NIS2 was primarily a task for legal teams. Today, the challenge has moved into the IT department and the boardroom, where organizations must be able to prove that technical controls are actually working around the clock.

The critical questions many CISOs are struggling with today:

  • What is my responsibility? Without a clear division of responsibilities between the company and its IT partners, organizations risk facing unclear legal accountability in the event of an outage or incident.

  • Is my system design robust enough? NIS2 requires more than just “a backup.” It requires documented capability to restore operations (Disaster Recovery) after complex attacks.

  • Can we report within 24 hours? Authorities require rapid incident reporting and subsequent root cause analysis. Do you have the tools to identify and communicate the cause reliably and securely?

We aim to be our customers’ best decision

We are proud to work with

Partnership Built on Transparency

Your Technical Foundation for Compliance

Our advisory services are rooted in Stratu’s core business: operating and securing your IT infrastructure. We help translate the legal requirements of Article 21 into concrete technical solutions.

Our Approach to Your NIS2 Compliance:

  1. Operational Responsibility Management: We help you identify which security measures Stratu can manage on your behalf. Through our NIS2 contractual addendum, you gain the documented supplier governance that auditors require.

  2. Operational Continuity Design: We design and implement the architecture for your backup and disaster recovery systems. We ensure they are logically separated from your production environment, so they function as a true lifeline in the event of ransomware attacks.

  3. Documented Incident Management: Through our ITSOC delivery (Arctic Wolf) we provide the log data and expertise required to meet the demands for rapid response and the delivery of root cause analyses directly to the authorities.

Operational Continuity as a Legal Requirement

Technical Design of Backup and Disaster Recovery

NIS2 places strong emphasis on an organization’s ability to maintain operations during and after an attack. Here, Stratu’s advisory services are centered around two key areas:

  • Independent Backup Systems: We help you design processes where your data is protected through immutability, ensuring it cannot be deleted or altered by attackers.

  • Disaster Recovery (DRaaS): We build systems where recovery time objectives (RTO) and recovery point objectives (RPO) are documented and tested. It is no longer enough to have a plan—you need a system design that demonstrably works in practice.

  • Root Cause Analysis: Using our monitoring capabilities, we can quickly identify how a threat entered your environment, which is critical for the mandatory reporting requirements to the Danish Centre for Cyber Security (CFCS).

Where Legal Requirements Meet Reality

We Translate Article 21 into IT Solutions

The NIS2 directive (Article 21) sets out a range of minimum requirements that all covered organizations must comply with. For many, it can be difficult to determine exactly what this requires from the IT department.

We make it simple. We map the legal requirements of the directive directly to concrete technical solutions, so you know your organization is properly covered.

NIS2 Legal Requirements (Article 21)Our Solution
Operational Continuity & Crisis ManagementWe ensure that you have a tested Disaster Recovery Planthat enables the business to continue operating after an outage. We document RTO (recovery time) and RPO (data loss tolerance).
Incident ManagementThe directive requires rapid response. With our SOC-service ITSOC service, you have 24/7 monitoring that detects threats in real time, helping you meet incident reporting deadlines.
Supply Chain SecurityAs your IT partner, we are part of your supply chain. We provide our own ISO 27001 certifications, security policies, and NIS2 contractual addendums to support your compliance documentation. ISO 27001 Certifications and audit reports available for your compliance documentation.
Cyber Hygiene & Access ControlWe implement technical safeguards such as MFA (Multi-Factor Authentication) and user access management to ensure that only the right people have access to your data.
Measuring EffectivenessCompliance is not a one-time exercise. We support ongoing reporting and documentation of your security posture, so you can continuously demonstrate compliance and improvement over time. auditsthat prove your security measures work in practice every day.

Why Choose Stratu as Your NIS2 Partner?

We Share the Responsibility with You

We are an important part of your supply chain ourselves, which is why we have invested heavily in strengthening our own security and compliance posture—so we can help elevate yours as well.

  • ISO 27001 certified: Our own processes are audited, enabling you to “inherit” our controls and document supplier governance without extensive manual audits.

  • Practical Experience: We do not operate in theory. Our advisory services are based on the system designs we manage every day for some of Denmark’s most critical businesses.

  • Danish Foundation: As a 100% Danish partner, we understand the local legislation and the specific requirements Danish authorities place on businesses in our sector.

Want to learn more about

Why Choose Stratu as Your NIS2 Partner?

Complete the contact form below and one of our specialists will contact you.

Frequently asked questions:

NIS2(FAQ)

No. The legislation is clear: the board and executive management hold the ultimate personal responsibility for the organization’s compliance. However, you can delegate the operational responsibility for the technical measures outlined in Article 21 to us. Through our NIS2 contractual addendum, we clearly define which controls Stratu is responsible for (e.g. backup security, network segmentation, and SOC monitoring), giving you a solid documentation foundation for regulatory authorities.

In the event of an audit, you must be able to document your ability to detect and respond to incidents rapidly. Stratu delivers an ITSOC solution designed to meet NIS2 requirements for response times and root cause analysis. We do not just provide alerts; we provide the data and reporting support you need to notify authorities (such as CFCS) within the legally required timeframes.

As a general rule, the legislation applies to organizations operating in critical sectors with more than 50 employees or annual revenue exceeding EUR 10 million. However, authorities may also designate smaller organizations if they are considered to provide critical societal functions.

Authorities can issue orders and fines. For essential entities, the fines can be substantial, and in extreme cases, management may be temporarily prohibited from performing executive functions.

No. NIS2 requires continuous maintenance. You must regularly update your risk assessments, test your preparedness, and train employees. Compliance is a process, not a one-time project.

Column in ITWatch

Column: IT Providers’ Ability to Meet Compliance Requirements Will Become a Future Gamechanger

In a column, our CEO, Jeppe Klestrup, shares his thoughts on the role of IT providers in achieving compliance.

In the article, he writes:

"With directives such as NIS2 and increasing focus on GDPR and ESG requirements, organizations face a complex challenge: how do you ensure that both operations and processes meet the necessary standards without compromising productivity?

In many cases, the answer lies with IT providers. Companies that can deliver solutions where compliance is built in from the beginning—from backup and data security to governance and documentation—will stand out. The ability to streamline compliance through strong processes and economies of scale will become a competitive advantage."

– Jeppe Klestrup, CEO, Stratu

Read the full column here.

World-class international technology partners

We partner with

Just as we, as a professional organisation, must help, serve and understand each individual member, we need suppliers who understand our organisation and needs.

Our customers say it best.

We wanted a flexible platform that could keep pace with developments and support the organisation without unnecessary administration.
Frederik Krebs Jensen
Head of Technology at e-Boks
Stratu has a strong team with a clear customer focus. They have helped us build a digital foundation that supports both operations and development.
Dennis H. Krogstrup
CIO Group Online