NIS2
Network and Information Security Directive 2
Essential and important entities · 18 sectors.
In force October 2024 · BSI enforcement (DE) · €10M / 2% revenue admin fines
re-entry.ai is an AI-powered compliance platform built in the DACH region and hosted in Frankfurt. Engineering and security teams use it to continuously collect evidence, map their existing stack to NIS2, DORA, and EU AI Act controls, and export audit-ready packages in BSI-aligned format. Re-entry operates as a regulatory heat shield: when an auditor sends a request, when an incident triggers a reporting obligation, or when a new regulation phases in, the team has evidence, controls mapping, and exports ready in hours instead of weeks.
NIS2 (EU Directive 2022/2555) has been in force since October 2024 with administrative fines up to €10 million or 2% of global annual revenue. Article 20 makes management bodies personally liable for compliance failures. re-entry maps the evidence requirements across Articles 21 (cybersecurity risk management), 23 (24-hour early-warning incident reporting), and 27 (registry of essential and important entities) to artefacts already produced by GitHub, AWS, Okta, Entra, incident ticketing systems, and vendor registers.
The Digital Operational Resilience Act (EU Regulation 2022/2554) has been in force since January 2025 for financial institutions. re-entry tracks ICT third-party registers per Article 28, digital operational resilience testing per Article 25, and incident classification per Article 18 — and exports the evidence pack EBA and national competent authorities expect.
The EU AI Act (Regulation 2024/1689) phases in through August 2026, with prohibited-practice fines up to €35 million or 7% of global revenue per Article 99. re-entry discovers AI systems already deployed inside the organisation (internal LLM routers, copilots, HR screeners, automated decisioning tools), classifies them by risk tier, and tracks the obligations attached to each tier — DPIAs, transparency notices, human-oversight controls, and post-market monitoring.
Application and evidence storage are hosted in Frankfurt. No US sub-processor sits on the data path. The published sub-processor list follows BSI C5 conventions so the data protection officer can sign off without a separate Schrems II analysis. Customer support is available in German and English.
re-entry is built for CISOs, compliance officers, and heads of engineering at mid-market SaaS companies inside the European Union subject to NIS2, DORA, or the EU AI Act. Design partner engagements are €1,000 per month for six months in exchange for product feedback and a published case study. Full team licenses are announced once the design partner cohort is full.
From NIS2 to BSI C5 — every regulation modeled as structured data your auditor can read. Each control is mapped to live evidence from the systems you already run. No roadmap items.
NIS2
Network and Information Security Directive 2
Essential and important entities · 18 sectors.
In force October 2024 · BSI enforcement (DE) · €10M / 2% revenue admin fines
DORA
Digital Operational Resilience Act
Financial entities · ICT third-party risk.
In force January 2025 · BaFin enforcement (DE) · joint EBA / ESMA / EIOPA RTS
EU AI Act
EU Regulation 2024/1689
AI system providers and deployers.
Phasing through August 2026 · €35M / 7% revenue fines for prohibited practices
ISO 27001
Information security management
International audit-grade ISMS standard.
Customer-required for B2B SaaS · re-entry exports ISO mapping alongside NIS2
GDPR
General Data Protection Regulation
Personal data processing · all EU entities.
In force May 2018 · DPA enforcement per Member State · €20M / 4% revenue fines
BSI C5
Cloud Computing Compliance Criteria
German federal cloud security baseline.
Required by many DE public-sector buyers · cited in NIS2 audits
Want to see your compliance posture against NIS2, DORA and the EU AI Act?
Get started — join the waitlistThe fines stopped being theoretical 19 months ago. The next BSI audit notice is a calendar event your team has not booked yet.
or 2% of global revenue — maximum administrative penalty for non-compliance.
EU Directive 2022/2555, Art. 34
or 7% of global revenue — penalty ceiling for prohibited AI practices.
EU Regulation 2024/1689, Art. 99
Management bodies are personally liable for NIS2 compliance failures.
EU Directive 2022/2555, Art. 20
Re-entry replaces the manual collect-map-document phase. Your compliance lead spends their time on judgment calls and auditor conversations — not on hunting screenshots.
GitHub
repos · secrets · code scanning
AWS
IAM · CloudTrail · Config
Okta
users · MFA enrolment · access reviews
Sentry
incidents · severity · MTTR
Read-only OAuth into GitHub, AWS, Azure, GCP, Okta, Entra ID, Jira / Linear, Sentry. Nothing leaves the EU. No US sub-processor on the data path.
A control mapping nobody on your team owns. An evidence document that updates manually. An incident-response procedure that hasn't been drilled in 14 months. Nobody knows it's there — until the BSI sends the audit notice.
NIS2 Art. 23 · 24-hour early-warning workflow not in place
pagerduty · oncall-rotations · no BSI escalation path
In force 19 months
0 drills run
EU AI Act · 4 systems unclassified by risk tier
internal-llm-router · sales-copilot · hr-screener · refund-bot
Phase 1 active 10 months
0 DPIAs filed
DORA Art. 28 · ICT third-party register out of sync
vendor-register.xlsx · last edited 2025-09
In force 17 months
37 vendors missing
NIS2 Art. 21 · quarterly access reviews not evidenced
okta · entra · github org admins · no signed attestation
In force 19 months
0 quarters completed
DORA Art. 25 · digital operational resilience testing not performed
no chaos drills · no scenario-based testing · no TLPT
In force 17 months
0 tests recorded
Re-entry harvests every night. It walks your GitHub repos, your AWS / Azure / GCP accounts, your IdP, your incident tickets, your vendor contracts — and maps each artefact to NIS2, DORA, and EU AI Act controls. Gaps surface in plain German. Evidence packs export in BSI-aligned format. The audit becomes a checklist, not a fire drill.
See your compliance postureRead-only OAuth into the stack you already run. Every integration maps to specific articles in NIS2, DORA, ISO 27001 and BSI C5.
GitHub
Code · secrets · CI
GitLab
Code · secrets · CI
Bitbucket
Code · secrets · CI
AWS
Cloud infrastructure
Azure / Entra
Cloud + identity
Okta
Identity + access
Jira
Remediation tasks
Linear
Remediation tasks
Sentry
Incident timeline
Slack
Incident comms
PagerDuty
On-call response
Calendar
Cadence evidence
Re-entry is hosted in the EU, audited against the same controls it helps you evidence, and built by a team that lives one office park away from your auditor.
Hetzner EU
Frankfurt · DE
AES-256
At rest
TLS 1.3
In flight
Audit log
Immutable
Read-only
By default
Zero retention
No training
We pull artefacts your stack already exposes — repos, IAM, audit logs, ticket histories. Write access is opt-in per system.
Hosted in Frankfurt. Processed in the EU. No US sub-processor on the evidence path. No Schrems II exposure.
Every evidence collection, every gap flagged, every report exported — logged with full chain of custody.

SOC 2
Type II in progress

GDPR
Compliant
BDSG
German data protection
TLS 1.3 + AES-256
In transit & at rest
Backed by & hosted on
FAQ