Contents
The five NIS2 tools from Germany in 2026 are fuentis, DataGuard, secjur, Proliance 360 and HiScout. They support a varying number of the four BSIG obligations: risk management (§ 30), reporting (§ 32), registration (§ 33) and management body training (§ 38). According to a BSI press release, around 4,500 organisations were regulated until now; since 6 December 2025, about 29,500 entities supervised by the BSI fall under the law.
The selection is editorial, and fuentis is the vendor of one of the tools. Criteria: headquarters in Germany according to the legal notice, and NIS2 functions listed on the official vendor website. All information on the other vendors comes from their websites, as of October 2026.
What Must a NIS2 Tool Deliver?
A NIS2 tool should support four BSIG obligations: risk management measures under § 30, reporting of significant security incidents under § 32, registration under § 33 and management body training under § 38. The law requires measures, not a particular piece of software; a tool pays off when evidence, deadlines and responsibilities must be documented on an ongoing basis.
| Obligation | Provision | Deadline |
|---|---|---|
| Risk management measures | § 30 BSIG | ongoing obligation, no deadline |
| Reporting of significant security incidents | § 32 BSIG | 24 hours (initial report), 72 hours (report), final report no later than one month after submission of the report |
| Registration | § 33 BSIG | three months after an entity first qualifies as affected |
| Management body training | § 38 BSIG | regularly, no fixed deadline |
The obligations apply to essential and important entities; the NIS2 applicability checker gives an initial indication of whether yours is one of them. § 30 para. 2 lists ten areas of measures, including supply chain security. The initial report is due within 24 hours of becoming aware of the incident. A reporting chain that only takes shape during the incident will hardly meet this deadline. According to § 30 para. 1, the measures must be appropriate, proportionate and effective. Details on the NIS2 reporting obligations can be found in a dedicated article.
Which NIS2 Tools from Germany Are Compared?
According to their legal notices, the five tools come from vendors headquartered in Germany. According to the vendor websites, fuentis and HiScout offer GRC suites with ISMS and BCM modules; DataGuard, secjur and Proliance 360 position their NIS2 functions within compliance platforms. The table reflects the vendors' own statements.
| Tool | NIS2 scope (according to the vendor) | Target audience (according to the vendor) | Integration (according to the vendor) |
|---|---|---|---|
| fuentis | Risk analysis; incident management with templates for notifications to authorities and deadline reminders (24h/72h); BCMS module. Registration (§ 33), management body training (§ 38), supply chain: not listed on the product page | SMEs to public authorities and KRITIS | Modules in the same system; SaaS, private cloud or on-premise |
| DataGuard | Automated risk analyses, reporting processes, training modules, ISMS integration, with expert consulting | SMEs and large enterprises (own solution pages) | Platform; API documentation mentioned |
| secjur | ISMS implementation, management training, supply chain security; self-implementation with optional consulting | Industry solutions for startups, scaleups, mid-sized companies and KRITIS, among others (according to the navigation) | Not listed on the NIS2 page; a separate integrations page mentions 60+ integrations |
| Proliance 360 | Online training for the management body under § 38 BSIG (3 hours, one-to-one or small group); platform with ISMS functions, risk management listed as "Available soon" on the vendor page; reporting and registration mentioned only as training content | Mid-sized companies in Germany | Part of the Proliance 360 platform |
| HiScout | Risk management, IT system lifecycle, vulnerability, supply chain and business continuity management | Public authorities, KRITIS utilities, banks, insurers, healthcare | GRC suite of Grundschutz, ISM, BCM, data protection, audit management; add-ons such as ADConnect |
In the incident management module of the fuentis suite, an incident points to the affected target object groups in the ISMS; timestamps, affected systems and actions taken are recorded in the audit trail. Hosting is available as SaaS, private cloud or, in the enterprise version, on-premise. More on the NIS2 and KRITIS page, pricing on the pricing page.
DataGuard combines its software with expert consulting, according to the vendor's NIS2 page; according to the legal notice, the platform is operated by DataCo GmbH in Munich. How much of the implementation remains with the customer is not apparent from the NIS2 page.
secjur mentions the reporting process with 24h, 72h and one month only in its own comparison blog, not on the NIS2 product page. The claim that organisations can self-implement without specialist knowledge is also a vendor statement that you should verify in a trial.
Proliance offers management body training under § 38 BSIG as a dedicated online training, embedded in the platform. The page lists reporting obligations, registration and risk management as training content, not as platform functions.
According to its homepage, HiScout has been in use at federal and state authorities as well as private companies for over 15 years. The NIS-2 page maps the requirements to the functions of the suite, but does not mention a reporting function for authorities.
With NIS2, what counts is not the number of modules, but whether risk analysis, incident reporting and evidence rest on a shared data basis. A tool that only covers the 24-hour report does not answer § 30 BSIG and leaves the management body without a basis for oversight under § 38.
Srdan Manasijevic, CEO fuentis
Which NIS2 Tool Fits Which Situation?
Suites with ISMS, incident and BCM modules such as fuentis and HiScout are worth considering, according to the vendor websites, when risk, reporting and continuity planning belong together. Mid-sized companies without their own compliance department can look at DataGuard, secjur or Proliance 360. Applicability should be clarified first, then the scope of functions.
According to the vendor websites, the difference between fuentis and HiScout lies in the target audience: HiScout names federal and state authorities and utilities, fuentis names SMEs to public authorities. According to the vendor page, Proliance offers a dedicated online training for the management body under § 38; DataGuard and secjur mention training modules and management training respectively.
Check each tool against the four obligations and ask where the vendor page does not list registration, reporting or training. Organisations that use ISO 27001 or Grundschutz may find it easier to provide evidence; however, according to the BSI FAQ, the certification must be reviewed against the statutory catalogue of measures and supplemented where necessary. Next step: the NIS2 applicability checker, then the NIS2 page from fuentis. Further reading: ISMS tools compared.
Before deciding, specifically ask for a trial with a real incident: how quickly does capturing it produce the first draft report, and who in your organisation triggers it?

CEO, fuentis AG
Expert in information security, data protection and risk management with extensive experience advising enterprises and public-sector organizations. Specialized in ISO 27001, BSI standards and modern risk-analysis methods.