Skip to content

Solutions

Compliance & audit: evidence that stays current

Compliance means being able to prove security. blacklens.io generates the technical evidence for NIS2, ISO 27001, TISAX and DORA continuously: inventory, vulnerabilities, remediation and reports.

Evidence for auditors and insurersas PDF
Asset inventoryISO/IEC 27001 A.5.9continuous
Vulnerability reportISO/IEC 27001 A.8.8, TISAXmonthly
Threat Center matchingISO/IEC 27001 A.5.7real time
Vulnerability handlingNIS2 Art. 21 (2) econtinuous
Supplier watchlistNIS2 Art. 21 (2) dcontinuous

Where implementation fails in practice

Stale inventory

The asset inventory is maintained for the audit and goes stale afterwards. New cloud resources are missing.

Measures that are hard to prove

"We patch regularly" is not evidence. Auditors want to see what was closed and when.

No current threat data

Whether a new critical CVE affects your own systems is researched manually, if at all.

High manual effort

Asset lists and reports are kept in spreadsheets and reworked before every audit.

How blacklens.io generates compliance evidence

Evidence is produced during everyday operations, not in the week before the audit.

Newly discovered assets+4 since yesterday
beispiel-gmbh.atRoot domain
vpn.beispiel-gmbh.atFortiGate SSL-VPN 7.0.12Critical
dev-old.beispiel-gmbh.atGitLab 15.2Shadow ITHigh
mail.beispiel-gmbh.atExchange Server 2019Medium
203.0.113.24OpenSSH 8.9NewInfo

Visuals show sample data.

Example from practice

Critical infrastructure operator prepares for a NIS2 audit

A critical infrastructure company had to implement NIS2 technically and prove it in an audit. With blacklens.io, attack surface and vulnerabilities were monitored continuously, prioritised and documented with clear ownership.

  • Result

    Technical protection of the external systems rated "exemplary and consistently documented" in the audit.

Progresslast 90 days
Critical findings143
Exposed services3821

Visuals show sample data.

Frequently asked questions

blacklens.io provides technical evidence for NIS2 (Directive (EU) 2022/2555) for essential and important entities, DORA (Regulation (EU) 2022/2554) for financial entities and their ICT providers, ISO/IEC 27001:2022 with Annex A controls such as A.5.7, A.8.8 and A.8.16, TISAX based on the VDA ISA, and the critical infrastructure (KRITIS) duty to demonstrate the state of the art. Cyber insurers' questionnaires on MFA, patch management, exposed services and the external attack surface can also be answered with current data instead of estimates.

Evidence that is ready before the next audit

Start with your domains and see how inventory, findings and reports come together.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings