§30 nis2scan

Why nis2scan

There are many cloud scanners. This one answers a different question.

Most tools tell you what is misconfigured in your cloud. nis2scan answers the question that matters in an audit: does your evidence hold up against §30 BSIG, the German NIS2 implementation?

Legal basis in every finding

Every finding quotes the specific obligation from §30 (2) BSIG verbatim and names the matching ISO 27001:2022 control. That is the language auditors and management understand.

Positive evidence, not just a defect list

What is in order gets documented too, with machine-readable evidence. An audit needs proof of what is fulfilled, not only a list of what is missing.

Scan limits stated in the report

Every check documents what it fundamentally cannot see. The report never claims more than was checked. Everything that cannot be scanned is covered by the attestation checklist.

Documented exceptions

False positives and accepted risks can be documented as exceptions with a rationale and an expiry date. The finding stays visible and the risk decision becomes auditable. No silent filtering.

Strictly read-only

nis2scan only reads. The permissions generator produces the minimal read rights needed for AWS, Azure, and GCP. Your data never leaves your environment because the scan runs on your side.

Open code, open legal review

Apache 2.0, source on GitHub. Every legally phrased statement goes through a documented four-eyes review whose protocol is public in the repository.

When in doubt, never "passed"

A compliance scanner can fail in two ways. It can report a defect that is not one: annoying, but fixable. Or it can attest compliance that is not proven: for an audit tool this is the worst possible failure, because one false positive proof undermines trust in all of your evidence.

nis2scan draws a hard conclusion from this: if an API returns an error, a permission is missing, or a response is ambiguous, the tool does not say "compliant" but reports the error openly. Positive evidence only ever comes from a solid, documented API response. And with every release, integration tests against real cloud environments with intentionally built-in gaps prove that defects are actually found and compliance is actually recognized.

Honest answers to fair questions

What if the project disappears tomorrow?

The code is open source (Apache 2.0) and runs entirely on your side. There is no server of ours you depend on and no lock-in. What you install today keeps working.

Is the legal mapping reliable?

Every mapping from check to legal text has gone through a documented four-eyes review; the protocol is public in the repository. Still: nis2scan is not legal advice and not a certificate, but the technical evidence layer underneath. It never preempts the judgment of an auditor or authority.

Why should we give a tool access to our cloud?

Access is strictly read-only and minimal: the permissions generator produces exactly the read rights the checks need, traceable line by line. The source code is open and auditable. There is no backchannel to us.

Our world is Microsoft 365, not AWS.

The focus is on AWS and Azure; GCP checks are included at the same scope and equally legally reviewed. Support for Microsoft 365 (Exchange Online, SharePoint, Teams) is in preparation. What the tool cannot scan is covered by the attestation checklist.

Other scanners are free too.

So is nis2scan, all checks and all providers. The difference is not the price but the legal grounding: German legal citations, positive evidence, stated scan limits, and an audit-ready report. To our knowledge no other free tool does this.