SentriKat is live, launch pricing and hands-on onboarding for founding customers. Get started
NIS2 Compliance

NIS2 vulnerability management
built for European organizations

Meet Article 21 vulnerability handling requirements with on-premises deployment, the European vulnerability database read natively, and cross-checked intelligence from 6+ authoritative databases, backed by cryptographically signed, auditor-ready evidence. Made in Europe. EU data sovereign. €4,999/yr.

To be clear: SentriKat produces the vulnerability-management and supply-chain evidence Article 21 asks for. That's one part of NIS2, not the whole directive, and no single tool can be.

What NIS2 Article 21 requires, and how SentriKat delivers

NIS2 Requirement

Article 21(2)(e) mandates "vulnerability handling and disclosure", a structured, repeatable process for identifying, assessing, and remediating vulnerabilities across your IT environment.

SentriKat Delivers

Automated inventory discovery, multi-source vulnerability matching (two feeds, one of them European), CVSS enrichment from 3 databases, remediation deadline tracking, and NIS2-specific compliance reports for auditors.

Why EU organizations choose SentriKat

EU Data Sovereignty

100% on-premises. Your vulnerability data never leaves your infrastructure. No US cloud dependency. Deploy on your own EU-based servers and maintain full control over sensitive security data.

European Vulnerability Database

Native integration with the European Vulnerability Database mandated by NIS2 Article 12. Track EU-flagged exploited vulnerabilities alongside the other catalogues we track, so no single source decides what you get to see.

NIS2 Compliance Reports

Generate audit-ready NIS2 Article 21 compliance reports with executive summaries, risk scores, remediation timelines, and KPIs. PDF exports ready for board presentations and regulatory audits.

What auditors actually want

Cryptographically signed, tamper-evident evidence

Every compliance report SentriKat generates is hashed with SHA-256 and signed with HMAC. An auditor can verify, independently, offline , that the evidence in front of them hasn't been altered since SentriKat produced it. Most scanners export unsigned PDFs that anyone can edit without a trace.

SHA-256 content hash

Each report carries a fingerprint of its exact contents. Change a single character and the hash no longer matches, instant, mathematical tamper-evidence.

HMAC signature

The hash is signed with a keyed HMAC, tying each report to your SentriKat instance. Verifiable offline, no SaaS call-home, no third party in the loop.

Independently verifiable

Hand the PDF or JSON to your auditor with the verification steps. They confirm the integrity themselves, evidence that stands on its own, no trust in us required.

Signed reports, mapped to the controls your auditor checks

NIS2, Article 21(2)(e)
Exploited-vulnerability deadlines
PCI-DSS v4.0, Req. 6 & 11
ISO 27001:2022, A.8.8
SOC 2, CC7.1
Executive Summary

Multi-source vulnerability intelligence

No single point of failure. SentriKat enriches every CVE from 6+ authoritative databases with automatic fallback.

Source Purpose EU Relevance
Exploited-vulnerability catalogue Vulnerabilities confirmed as used in attacks US-maintained, globally adopted
European vulnerability database EU exploited vulnerabilities + CVSS Established by NIS2 Article 12
Primary severity database Primary CVSS scoring Industry standard baseline
Enriched CVE records Secondary CVSS, publisher-provided scores Independent fallback
Exploit probability How likely a vulnerability is to be used Prioritization model
Package advisories Open-source package vulnerability data Vendor advisory aggregation

SentriKat vs. enterprise scanners for NIS2

Purpose-built for European compliance, not retrofitted from US-centric products.

Capability SentriKat Enterprise Scanners
Deployment 100% on-premises Cloud-first (US-hosted)
European vulnerability database Native integration Not available
CVSS sources 3 sources + auto-fallback One source only
NIS2 compliance reports Built-in, Article 21 Generic / add-on module
Data sovereignty Full EU control US Cloud Act exposure
Source code audit Available Proprietary / closed
Pricing €4,999/yr all-inclusive $10,000+/module/yr

EU and international compliance frameworks

NIS2
Article 21(2)(e)
Vulnerability handling
DORA
ICT Risk Management
Financial sector
ISO 27001
Annex A.8.8
Technical vulnerability mgmt
Exploited-first
Remediation deadlines
Deadline tracking
Machines, not just servers

Industrial equipment is in scope, and we check it for you

NIS2 covers energy, water, transport, manufacturing and health. In those sectors the asset that matters is often a controller on a production line that has run untouched for nine years, and no software can be installed on it. So we do that part by hand.

1
You send the list

Makes, models and firmware versions. A spreadsheet is fine.

2
We match it

Against the same database the product runs on, including the exploited-in-the-wild list and exploitation probability.

3
You get a report

What is exploitable today, what can wait, and what has no fix. Written for whoever has to schedule the downtime.

What this is not

We do not put software on your industrial equipment and we do not connect anything to your control network. This is a person reading your equipment list against a database that is already current, and telling you what to do about it.

Send us your equipment list

Tell us the sector and roughly how many devices. We will say what we can answer before you send anything.

Honest about what this is

SentriKat produces auditor-ready gap analysis and evidence for the vulnerability-management parts of NIS2, DORA, PCI-DSS, ISO 27001 and SOC 2, finding, prioritising and tracking the fix of vulnerabilities, then documenting it in signed reports. It hands your auditor clean, verifiable proof and makes their job faster. It is not a certification, and no tool can make you "compliant" on its own. We'd rather tell you that up front than oversell it, that's the kind of vendor we want to be.

Ready for NIS2 compliance?

Deploy SentriKat on-premises, import your inventory, and generate your first NIS2 compliance report, all in under an hour.

Frequently asked questions

Does SentriKat meet NIS2 Article 21 vulnerability handling requirements?

Yes. SentriKat provides structured, auditable vulnerability handling: automated discovery via agents, severity scoring cross-checked across three independent public databases, remediation tracking with deadlines, and NIS2-specific compliance reports with executive summaries for auditors and board presentations.

Can SentriKat run 100% on-premises in the EU?

Yes. SentriKat is fully self-hosted via Docker Compose. Your vulnerability data, scan results, and full software inventory never leave your infrastructure. Air-gapped deployments are supported with offline license activation. The external calls are a lightweight license heartbeat and, if left enabled, anonymized signals about software our engine could not identify (no version, hostname, or customer data). Both are documented at sentrikat.com/privacy.

Does SentriKat use the European vulnerability database?

Yes. SentriKat reads the European vulnerability database established by NIS2 Article 12, both for exploited-vulnerability tracking and for severity enrichment. It is cross-checked against three other public databases, so no single one, European or American, decides what you are told.

What is the difference between SentriKat and Tenable or Qualys for NIS2 compliance?

SentriKat is on-premises (EU data sovereignty), reads the European vulnerability database natively, generates NIS2-specific compliance reports, and costs €4,999/year for everything included. Enterprise scanners require cloud tenancy, start at $10,000+/module, and don't include EU-specific vulnerability databases or NIS2 report templates.

How does SentriKat make its compliance reports tamper-evident?

Every compliance report is hashed with SHA-256 and signed with HMAC. The hash is a fingerprint of the report's exact contents, and the HMAC signature ties it to your SentriKat instance. An auditor can verify offline that the evidence hasn't been altered since it was generated, no third-party service required. Most vulnerability scanners export unsigned PDFs that can be edited without trace.

Does SentriKat make my organization NIS2 or ISO 27001 certified?

No, and no tool can. SentriKat produces auditor-ready gap-analysis and evidence for the vulnerability-management parts of NIS2, DORA, PCI-DSS, ISO 27001 and SOC 2. It documents your posture and gives your auditor verifiable evidence, which accelerates an assessment or certification carried out by an accredited body. SentriKat itself does not issue certifications.