Duvo has completed the work required to operate in line with NIS2, the EU's cybersecurity directive for essential and important organizations. It joins SOC 2 Type II, ISO 27001, ISO 42001, and GDPR support on the trust center.
Key Takeaways
- NIS2 raises the cybersecurity bar across Europe for organizations in sectors such as telecommunications, energy, transport, financial services, and digital infrastructure, and it reaches their suppliers through explicit supply-chain security obligations.
- Duvo now operates in line with NIS2's requirements on security governance, risk management, incident response, business continuity, access controls, and supply-chain security.
- ISO 42001 and NIS2 together cover both sides of the question a reviewer actually asks: how the AI is governed, and how the systems around it are secured.
What NIS2 asks
NIS2 significantly raises the cybersecurity requirements for organizations that run Europe's critical services. It covers security governance, risk management, incident response, business continuity, access controls, and supply-chain security, and its reach does not stop at the regulated organization. Suppliers that work inside business-critical processes are part of the compliance surface, and organizations in scope are required to assess them.
That changes what a security review looks like. Every vendor with access to a critical process is a question the reviewer has to answer. A vendor that cannot show its own controls becomes a finding.
Why this matters for a Duvo deployment
Duvo works inside business-critical processes and systems: reading data in one system, acting in another, writing results back. That is exactly the kind of access NIS2 tells regulated organizations to scrutinize. Deploying Duvo must not introduce a new weak point into a customer's security or compliance posture, and now the review can confirm that against the directive's own requirements rather than a questionnaire.
For banks, telecoms, retailers of scale, and critical-infrastructure operators, this is quickly becoming a condition of doing business, not a differentiator. Duvo did the work early so its customers do not have to wait for it.
One trust foundation, reviewed in one place
NIS2 adds a layer to an assurance base that is already independently audited:
- SOC 2 Type II: independently attested security, availability, and confidentiality controls, operating over time.
- ISO 27001: a certified information security management system.
- ISO 42001: a certified AI management system governing how AI is developed, deployed, and monitored.
- GDPR: data handling and customer rights governed to align with EU privacy requirements.
- NIS2: security governance, risk management, incident response, business continuity, access controls, and supply-chain security operating in line with the EU cybersecurity directive.
All of it is gathered on the trust center, with review documents available on request through MyCroft, so a security review does not require a second sales call.