Awarely Monitor
AwarelyMonitor

NIS2 · For essential and important entities

NIS2: from public signal to documented remediation.

For security and IT teams at entities within the scope of NIS2 (in Romania, GEO 155/2024): bring public CVE signals together, prioritise review, assign owners and document remediation in Awarely Monitor.

No credit card. Eligible new accounts receive 14 days of Pro; access returns to Free without an active subscription.

Monitor does not certify or guarantee NIS2 compliance. Notification of significant incidents to the national CSIRT (in Romania, DNSC) takes place separately.

Four steps to try with your own systems

1. Identify relevant signals

NVD, CISA KEV, EUVD and GitHub Security Advisories are collected on a scheduled two-hour cycle. CVSS, EPSS from FIRST and KEV context help prioritise review. Check the last synchronisation on the Status page too.

2. Link signals to what you run

Track critical vendors and products in a watchlist. In Pro, import your inventory from CycloneDX JSON, SPDX JSON, package.json or requirements.txt, up to 1,000 entries. Matches are version-confirmed only where the data permits; product-level results need review.

3. Assign, remediate and document

Use assignments, statuses, notes and activity history for each CVE under review. Pro adds per-severity internal remediation SLAs and Jira/Linear ticket creation after configuration.

4. Prepare evidence for review

Export the CVE list as CSV/XLSX and audit records as JSON/CSV. Starter and Pro include a date-range Evidence Pack; Pro adds the Asset Exposure report. These records can support evidence of the vulnerability-management process; check the coverage of each control in the DNSC self-assessment separately.

Check source status

An assessment to try during your trial

Add your critical vendors and products to the watchlist, pick a CVE listed in CISA KEV or with a high EPSS score and check whether you run it. Assign the review to a colleague, record the decision and the internal remediation target, then export the records. Use the result to evaluate whether Monitor fits your team’s process.

Choose a plan for the workflow you need to evaluate

Starter — €59/month: up to 5 users, statuses, notes, assignments, Critical-severity email, CSV/XLSX, audit and Evidence Pack within a 90-day window. Does not include Pro inventory or advanced integrations.

Pro — €199/month: up to 5 users, inventory/SBOM import, supported-severity alerts through email, Slack, Teams Workflows and signed outbound webhook, internal SLA, Jira/Linear, additional reports, 12-month retention and a CVE data API with 50,000 requests/month. Access depends on role and configuration.

What your own process needs to cover

  • The two-hour cycle is a collection schedule, not a freshness or delivery guarantee. Public sources may publish late or incomplete information. Monitor does not detect every vulnerability or incident and does not replace telemetry, scanning or testing.
  • Vulnerability handling is one of the Article 21 measures. Business continuity, access control, cryptography, supplier security and the other measures remain separate organisational processes.
  • An internal remediation SLA is not the statutory incident-notification deadline. Collection and audit timestamps do not automatically establish when you became aware of a significant incident.
  • Exports reflect available data and plan retention; they do not replace the DNSC self-assessment or certify NIS2 compliance. The platform also attempts a secondary S3 retention copy of audit events, without guaranteeing that every write reaches it.

NIS2 reference points in Romania

Romania transposed NIS2 through GEO 155/2024, approved by Law 124/2025. DNSC Order 1/2026, published in Official Gazette no. 712 of 27 August 2026, approves the catalogue of 218 controls and the maturity self-assessment methodology. GEO 155/2024

Article 21 covers risk-management measures, including vulnerability handling and disclosure. Article 23 covers notification of significant incidents to the national CSIRT — in Romania, DNSC. A CVE or a CVSS or EPSS score alone does not trigger a notification. Directive (EU) 2022/2555 (NIS2)

24 hours
Early warning, from becoming aware of the significant incident.
72 hours
Incident notification, with an initial assessment of severity and impact.
One month
Final report, counted from submission of the notification.

The initial self-assessment is due within 60 days of submitting the risk-level assessment (Article 18(7) of GEO 155/2024), then annually, endorsed by management (Article 12(4)). Essential entities submit a remediation plan within 30 days of the self-assessment (Article 12(5)).

Do you also make software or connected devices? CRA obligations concern the product and can apply alongside NIS2. CRA process preparation

Awarely NIS2 guides

Practical NIS2 guides

Official sources · primary texts reviewed on 5 September 2026