Solutions
Compliance & audit: evidence that stays current
Compliance means being able to prove security. blacklens.io generates the technical evidence for NIS2, ISO 27001, TISAX and DORA continuously: inventory, vulnerabilities, remediation and reports.
Where implementation fails in practice
Stale inventory
The asset inventory is maintained for the audit and goes stale afterwards. New cloud resources are missing.
Measures that are hard to prove
"We patch regularly" is not evidence. Auditors want to see what was closed and when.
No current threat data
Whether a new critical CVE affects your own systems is researched manually, if at all.
High manual effort
Asset lists and reports are kept in spreadsheets and reworked before every audit.
How blacklens.io generates compliance evidence
Evidence is produced during everyday operations, not in the week before the audit.
- Assigned to IT operations
- Update installed
- Re-scan confirmed: closed automatically
- CVE published08:12
- 2 assets in your inventory affected09:00
- Confirmed by PoC scan09:26
- Alert sent to Microsoft Teams09:27
Visuals show sample data.
Frameworks at a glance
NIS2
Article 21 requires vulnerability handling, supply chain security and incident handling, among others.
DORA
ICT risk management, third-party risk and resilience testing for financial entities and ICT providers.
ISO/IEC 27001:2022
Continuous evidence for Annex A controls such as A.5.7, A.8.8 and A.8.16.
TISAX
Answer the VDA ISA questions on vulnerabilities, network and suppliers with the same evidence.
Critical infrastructure (KRITIS)
Demonstrate the state of the art with continuous monitoring of the external and internal attack surface.
Cyber insurance
Answer questions on MFA, patches and exposed services with data instead of estimates.
Example from practice
Critical infrastructure operator prepares for a NIS2 audit
A critical infrastructure company had to implement NIS2 technically and prove it in an audit. With blacklens.io, attack surface and vulnerabilities were monitored continuously, prioritised and documented with clear ownership.
Result
Technical protection of the external systems rated "exemplary and consistently documented" in the audit.
Visuals show sample data.
Frequently asked questions
- blacklens.io provides technical evidence for NIS2 (Directive (EU) 2022/2555) for essential and important entities, DORA (Regulation (EU) 2022/2554) for financial entities and their ICT providers, ISO/IEC 27001:2022 with Annex A controls such as A.5.7, A.8.8 and A.8.16, TISAX based on the VDA ISA, and the critical infrastructure (KRITIS) duty to demonstrate the state of the art. Cyber insurers' questionnaires on MFA, patch management, exposed services and the external attack surface can also be answered with current data instead of estimates.
Evidence that is ready before the next audit
Start with your domains and see how inventory, findings and reports come together.
- 14 days free, all features
- No credit card required
- We walk you through your first findings