What must I demonstrate, and is it documented?
Your CISO maps the NIS-2 minimum measures from § 30 of the German BSI Act or, in the financial sector, the DORA requirements, together with ISO 27001 Annex A, to your organisation and keeps the status per control with documented evidence. The platform provides it as a PDF whenever you need it.




