§30 nis2scan

Open Source · Apache 2.0 · Made in Germany

Your cloud. §30 BSIG.
One scan.

The German NIS2 implementation act obliges around 30,000 companies to meet ten concrete security measures, with no transition period. nis2scan checks AWS & Azure against them and delivers the audit-ready report in German, with a statutory citation in every finding.

# install (Python 3.12+)
$ pip install nis2scan

# scan (read-only)
$ nis2scan scan --provider aws

Degree of fulfilment under §30(2) BSIG:
 No. 8 Cryptography    fulfilled
 No. 9 Access control partial
 No. 3 BCM             not fulfilled
154 legally reviewed checks Strictly read-only Four-eyes legal review, open in the repo German-language audit reports
§30

ten legally mandatory risk management measures, in force since December 2025.

~30,000

affected entities in Germany (entities of particular importance & important entities under §28 BSIG).

§38

the management board's duty to approve and oversee risk management, including a training obligation.

What sets nis2scan apart

A scanner that speaks the language of the audit.

Legal basis for every finding

Every finding quotes §30(2) BSIG (the German NIS2 implementation in the BSI Act) verbatim, alongside the matching ISO 27001:2022 control. That is the language your auditor speaks.

Strictly read-only

The engine has no write permissions whatsoever. nis2scan reads your cloud configuration; it never changes a single resource.

Positive evidence

What is already in order gets documented too, with machine-readable evidence. For an audit, the proof matters as much as the gap.

Fail-safe

Anything that could not be checked is reported as an error, never as "passed". The tool never claims more than it has actually verified.

Attestation checklist

Whatever a scanner cannot see by nature (processes, training, responsibilities) is handed to you as a structured checklist.

Permissions generator

nis2scan generates the exact least-privilege read permissions itself: as an IAM policy, an Azure RBAC role, or ready-made Terraform.

In three steps

From access to an audit-ready report.

Generate read access

nis2scan permissions generates the minimal least-privilege role for your cloud, as an IAM policy, an Azure RBAC role, or ready-made Terraform. The scanner never gets more access than that.

Scan

nis2scan scan checks all ten §30 areas read-only, locally from your machine or from your CI. Your data never leaves your environment.

Hand over the report

A German-language report with the degree of fulfilment per measure, a statutory citation per finding, positive evidence, and an attestation checklist. Ready for your auditor and management board.

Boundaries

What nis2scan covers, and what it does not.

NIS2 is more than technology. nis2scan covers the part that can be checked in the cloud technically, and names the rest instead of glossing over it.

§30(2): the cloud-technical part of all ten measures 154 automated checks for AWS, Azure, and GCP

Organizational §30 obligations as an attestation checklist Policies, processes, responsibilities: handed over in structured form for self-attestation

§32/§33: reporting significant security incidents to the BSI a manual reporting process with deadlines that no scanner can carry out for you

§38: approval, oversight, and training of the management board a personal duty of the governing body; the report provides the basis for that decision

§31: additional obligations for operators of critical facilities (KRITIS) among others, attack detection systems, a separate set of duties beyond the scan

The difference

Not just a "misconfiguration", but the exact statute behind it.

Every legal mapping has gone through a documented four-eyes review against the statutory text; the review log is open in the repository. The §30 BSIG ↔ ISO 27001 mapping is part of the free version.

View mapping & review log
HIGH AWS-NR8-001 · S3 Default Encryption
Legal basis
§30(2) no. 8 BSIG: "concepts and procedures for the use of cryptography and encryption."
ISO 27001:2022
A.8.24 Use of cryptography
Remediation
Enable default encryption (SSE-KMS) for the bucket.

Full coverage

All ten measures of §30(2) BSIG.

No. 1 Risk analysis & IT security concepts
No. 2 Incident handling
No. 3 Business continuity (BCM)
No. 4 Supply chain security
No. 5 Security in acquisition, development & maintenance
No. 6 Effectiveness assessment
No. 7 Basic training & awareness
No. 8 Cryptography
No. 9 Personnel security, access control & ICT
No. 10 MFA & secure communication

Frequently asked questions

Briefly answered.

Is nis2scan legal advice or a certification?

No, and deliberately so. nis2scan produces technical evidence and findings with a documented legal basis. Assessing your overall compliance remains with you, your auditor, and where applicable your legal counsel.

What access does the scanner need?

Read access only. nis2scan permissions generates the exact minimal permission set for you. The engine contains no write operations whatsoever; that is verifiable in the source code.

What does nis2scan cost?

The core is free and open source (Apache 2.0): all checks, all providers, German-language reports, the attestation checklist. Paid tiers add convenience and scale (among other things, PDF export, continuous scanning), but never correctness.

Where does my scan data go?

Nowhere. The CLI scan runs entirely inside your own environment. Reports are generated locally; an export profile can pseudonymize all resource identifiers on request before you share them.

Where does the legal basis of the checks come from?

Every mapping to §30 BSIG and ISO 27001:2022 has gone through a documented four-eyes review against the statutory text. The mapping and the review log are open in the repository.

Know where you stand in five minutes.

Free and open source. Read-only access is enough; the audit-ready report comes in German.