From scope check to a living evidence file, in four steps
From "does this apply to us?" to a file you can show a client or regulator as-is. Step 1 is free; from step 2 on you work inside the subscription.
Scope check
Four short steps about your sector, size and clients. An immediate provisional outcome: in scope, supply-chain relation or out of scope — with the reasoning included.
AI baseline assessment
Upload your existing policies and procedures into your own workspace. The AI reads along per measure and returns a draft explanation plus a list of what is still missing.
Getting it in order
You record an owner, deadline and evidence item per measure yourself. The AI action plan states what is still missing per measure; you tick it off and attach the evidence.
Maintaining & reporting
A continuous dashboard with deadlines and an incident register. During an incident the tool guards the 24- and 72-hour deadlines and has an AI draft notification ready.
Not a folder of Word documents, but one workspace
Everything lives in the Munitor Compliance tool: maturity, owner, explanation and evidence per measure. You see at a glance what percentage is demonstrable — per organisation, project or service.
The file is shareable with a client or auditor, with version history. That replaces "we're working on it" with a link.
What this is and is not
Munitor Compliance is not a certificate and does not replace an audit. It makes your duty of care demonstrable: what you have arranged, who is responsible, and where the evidence sits. You report to the CSIRT yourself via mijn.ncsc.nl — the tool makes sure you are on time and that the draft notification is ready.
Frequently asked questions
Does the Dutch Cybersecurity Act (NIS2) apply to us?
That depends on your sector, your size, and whether you supply organisations that fall under the act themselves. The free scope check gives a provisional outcome in ten minutes, with the reasoning included.
We are out of scope, but our client is not. Now what?
Then the questions will most likely reach you through your client: they have to demonstrate their supply chain is in order. With a file in Munitor Compliance you answer that request with a link instead of an afternoon of searching.
What exactly does the AI do with our documents?
The AI reads your uploaded policies and writes a draft explanation per measure. Every draft is reviewed by a human before it enters the file. Everything runs on EU servers, with no retention.
Is this a certificate?
No. It is a demonstrable file for your duty of care. If you want to certify later (ISO 27001, for example), the file is the preparation for it — the measures and the evidence are already in place.
What happens during an incident?
You record the incident in the tool. It guards the statutory deadlines — early warning within 24 hours, notification within 72 hours — and prepares an AI draft notification. You file it yourself via mijn.ncsc.nl; the register proves you were on time.
Start with the free scope check
Ten minutes, an immediate provisional outcome. A reply within one working day, from a human.