Open Source · Apache 2.0 · Made in Germany
Your cloud. §30 BSIG.
One scan.
The German NIS2 implementation act obliges around 30,000 companies to meet ten concrete security measures, with no transition period. nis2scan checks AWS & Azure against them and delivers the audit-ready report in German, with a statutory citation in every finding.
$ pip install nis2scan
# scan (read-only)
$ nis2scan scan --provider aws
Degree of fulfilment under §30(2) BSIG:
No. 8 Cryptography fulfilled
No. 9 Access control partial
No. 3 BCM not fulfilled
ten legally mandatory risk management measures, in force since December 2025.
affected entities in Germany (entities of particular importance & important entities under §28 BSIG).
the management board's duty to approve and oversee risk management, including a training obligation.
What sets nis2scan apart
A scanner that speaks the language of the audit.
Legal basis for every finding
Every finding quotes §30(2) BSIG (the German NIS2 implementation in the BSI Act) verbatim, alongside the matching ISO 27001:2022 control. That is the language your auditor speaks.
Strictly read-only
The engine has no write permissions whatsoever. nis2scan reads your cloud configuration; it never changes a single resource.
Positive evidence
What is already in order gets documented too, with machine-readable evidence. For an audit, the proof matters as much as the gap.
Fail-safe
Anything that could not be checked is reported as an error, never as "passed". The tool never claims more than it has actually verified.
Attestation checklist
Whatever a scanner cannot see by nature (processes, training, responsibilities) is handed to you as a structured checklist.
Permissions generator
nis2scan generates the exact least-privilege read permissions itself: as an IAM policy, an Azure RBAC role, or ready-made Terraform.
In three steps
From access to an audit-ready report.
Generate read access
nis2scan permissions generates the minimal
least-privilege role for your cloud, as an IAM policy, an Azure
RBAC role, or ready-made Terraform. The scanner never gets more
access than that.
Scan
nis2scan scan checks all ten §30 areas read-only,
locally from your machine or from your CI. Your data never
leaves your environment.
Hand over the report
A German-language report with the degree of fulfilment per measure, a statutory citation per finding, positive evidence, and an attestation checklist. Ready for your auditor and management board.
Boundaries
What nis2scan covers, and what it does not.
NIS2 is more than technology. nis2scan covers the part that can be checked in the cloud technically, and names the rest instead of glossing over it.
§30(2): the cloud-technical part of all ten measures 154 automated checks for AWS, Azure, and GCP
Organizational §30 obligations as an attestation checklist Policies, processes, responsibilities: handed over in structured form for self-attestation
§32/§33: reporting significant security incidents to the BSI a manual reporting process with deadlines that no scanner can carry out for you
§38: approval, oversight, and training of the management board a personal duty of the governing body; the report provides the basis for that decision
§31: additional obligations for operators of critical facilities (KRITIS) among others, attack detection systems, a separate set of duties beyond the scan
The difference
Not just a "misconfiguration", but the exact statute behind it.
Every legal mapping has gone through a documented four-eyes review against the statutory text; the review log is open in the repository. The §30 BSIG ↔ ISO 27001 mapping is part of the free version.
View mapping & review log- Legal basis
- §30(2) no. 8 BSIG: "concepts and procedures for the use of cryptography and encryption."
- ISO 27001:2022
- A.8.24 Use of cryptography
- Remediation
- Enable default encryption (SSE-KMS) for the bucket.
Full coverage
All ten measures of §30(2) BSIG.
Frequently asked questions
Briefly answered.
Is nis2scan legal advice or a certification?
No, and deliberately so. nis2scan produces technical evidence and findings with a documented legal basis. Assessing your overall compliance remains with you, your auditor, and where applicable your legal counsel.
What access does the scanner need?
Read access only. nis2scan permissions generates
the exact minimal permission set for you. The engine contains no
write operations whatsoever; that is verifiable in the source
code.
What does nis2scan cost?
The core is free and open source (Apache 2.0): all checks, all providers, German-language reports, the attestation checklist. Paid tiers add convenience and scale (among other things, PDF export, continuous scanning), but never correctness.
Where does my scan data go?
Nowhere. The CLI scan runs entirely inside your own environment. Reports are generated locally; an export profile can pseudonymize all resource identifiers on request before you share them.
Where does the legal basis of the checks come from?
Every mapping to §30 BSIG and ISO 27001:2022 has gone through a documented four-eyes review against the statutory text. The mapping and the review log are open in the repository.
Know where you stand in five minutes.
Free and open source. Read-only access is enough; the audit-ready report comes in German.