- The exposure: what Article 21 and Article 20 actually say, quoted.
- The shift: from a supplier list to proof that each application comes back.
- The model: applications, in-house and supplier, each with a protection.
- The proof: an evidence map from each article to the document that supports it.
- The next step: book a demo, or get the sample evidence pack.
Keep essential services running. Keep the proof on file.
NIS2 asks essential and important entities to manage business continuity and supply chain security. Codekeeper protects the applications your services run on, in-house or from a supplier, and gives you dated evidence that each one can come back.
- Trusted by 3,500+ teams
- ISO/IEC 27001:2022 certified
- Evidence mapped to Article 21(2)(c) and (d)
Trusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors
- Fines: Article 34(4) and 34(5) say Member States must provide for fines "of a maximum of at least" €10M or 2% (essential) and €7M or 1.4% (important), whichever is higher. That's a floor for the national maximum, not the maximum itself, so the copy says "up to at least". The homepage stat calls €10M or 2% "the maximum NIS2 fine"; suggest the same wording there.
- Dates: Article 41(1) sets 18 October 2024 as the date Member States apply their measures. The Netherlands date comes from Staatsblad 2026, 189, Article 35: "De Cyberbeveiligingswet en dit besluit treden in werking met ingang van 15 augustus 2026." Production's "will take effect in early 2026" is out of date.
- Removed: production's "criminal liability", "career-ending bans" and "authorities take control" lines. Article 20(1) says management bodies "can be held liable", which is quoted instead. Legal should review the quotes and the disclaimer.
What NIS2 asks
Continuity and suppliers are named in the Directive.
Article 21 lists the measures essential and important entities must take, at the least. Two of them are about the applications your services run on. Article 20 puts the management body in charge of them.
“The measures referred to in paragraph 1 … shall include at least the following: … (c) business continuity, such as backup management and disaster recovery, and crisis management;”
“The measures referred to in paragraph 1 … shall include at least the following: … (d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers;”
“Member States shall ensure that, when considering which measures referred to in paragraph 2, point (d), of this Article are appropriate, entities take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures.”
“Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article.”
Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.
The shift
A plan on paper is the start. Proof it works is the goal.
NIS2 asks for backup management, disaster recovery and attention to each direct supplier. A policy describes what should happen. Evidence shows it can.
What many supplier files hold today
- A list of suppliers with a risk rating
- A continuity clause in the contract
- A recovery plan that assumes the supplier will help
- No record of what the software depends on
What Codekeeper adds
- A protection on each critical application, in-house or supplier
- Release or recovery terms agreed before anything goes wrong
- A rebuild with no help from the supplier, and a dated Recoverability Certificate
- An SBOM and an Exit workbook for each rebuilt application
How it works
From your service map to evidence on file.
One account for every application an essential service depends on.
List what your services run on
Add the applications behind each essential service: the ones you build and the ones you buy.
Attach a protection
Escrow for supplier applications. Resilience or Continuity for supplier or in-house applications. Backup for systems you run yourself.
Prove it comes back
Agentic Verification rebuilds the deposit in a sealed sandbox, in hours, on supported technology stacks.
Report to the board
Dated certificates and run reports give your management body something concrete to approve and oversee.
- Confirm before launch: production says Software Backup includes a Software Resilience Certificate. Confirm it carries over to the new line-up before the backup row names it.
- The row labels paraphrase the articles quoted above; they aren't quotes.
Evidence map
Evidence for each article.
What you can put on file for business continuity, supply chain security and management oversight, and which protection it comes with.
| NIS2 | Codekeeper evidence |
|---|---|
| Art. 21(2)(c) Backup management | Daily backups of your in-house applications, restorable when you need them. Software Resilience CertificateSoftware Backup |
| Art. 21(2)(c) Disaster recovery | Proof that a critical application rebuilds from its deposit in a sealed sandbox, with no help from the supplier. Recoverability CertificateRun reportExit workbookDeployable copyEscrow Pro · Resilience Pro · Continuity |
| Art. 21(2)(c) Crisis management | A recovery you don't have to run yourself. With Continuity, we also keep the live environment paid and switched on for an agreed period while we recover. Resilience ArrangementLive environment mapResilience · Resilience Pro · Continuity |
| Art. 21(2)(d) Supply chain security | Release or recovery terms for each direct supplier's application, agreed up front, and an automated check of what's deposited. Escrow AgreementSoftware Resilience CertificateVault reportEscrow · Resilience · Continuity |
| Art. 21(3) Quality of each supplier's product | A software bill of materials and documented build steps for each rebuilt supplier application. SBOMBuild stepsEscrow Pro · Resilience Pro · Continuity |
| Art. 20(1) Approval and oversight by the management body | Dated evidence per application for the board to review. Add an Exit Exercise when you need people to test the business functions as well. CertificatesRun reportsTested Exit ReportEvery protection · Exit Exercise as an add-on |
Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.
The proof
Proof beats promises.
Every protection comes with evidence. The higher you go, the more it proves.
Software Resilience Certificate
The deposit is held, and an automated check confirms what's in it, with a vault report.
Proves: it's there.
Recoverability Certificate
AI agents rebuild the deposit in a sealed sandbox, with no help from the supplier, in hours. It documents the rebuild; release rights come from the agreement.
Proves: it builds. Agentic Verification
Tested Exit Report
Our specialists rebuild by hand in a clean room and test the business functions you nominate, without the original developers. The annex maps to your framework.
Proves: you could exit and keep working. Exit Exercise
Choose the protection
Who runs the recovery when a supplier stops?
Escrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on.
Escrow
Deposit→Released to you→You recover
When the agreed conditions are met, the deposit is released to you. Escrow Pro adds proof it builds. Explore Escrow
From $199
Resilience
Deposit→Comes to us→We recover
If the application fails, Codekeeper runs the recovery for you. Resilience Pro starts from a deposit we know builds. Explore Resilience
From $399
Continuity
Live service kept on+We recover
Everything in Resilience Pro, plus the live environment kept paid and switched on for an agreed period while we recover. Explore Continuity
From $1,449
Prices per application per month. For your own in-house systems, Software Backup attaches the same way. See all prices
Who it's for
Wherever you sit in the supply chain.
Sectors of high criticality
Energy, transport, banking, health, digital infrastructure and the rest of Annex I. Show the services you run can recover. Continuity
Other critical sectors
Manufacturing, chemicals, food, postal and courier services and the rest of Annex II. Put evidence behind the supplier measures in your plan. Resilience
Suppliers to NIS2 entities
Your customers have to consider each direct supplier. Give them a certificate and proof your application builds. Escrow Pro
Sample evidence pack
See what your auditor would receive.
An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.
- Recoverability Certificate
- Run report
- SBOM and Exit workbook excerpts
Questions
Before your next NIS2 review.
Will Codekeeper make us NIS2 compliant?
No product can do that on its own. Codekeeper gives you evidence for your file: certificates, run reports, SBOMs and, if you add an Exit Exercise, a Tested Exit Report. Whether it meets a specific requirement is for you and your assessor to decide.
Which parts of NIS2 does the evidence relate to?
Mainly Article 21(2)(c), business continuity, including backup management, disaster recovery and crisis management, and Article 21(2)(d), supply chain security, with Article 21(3) on assessing each direct supplier. The evidence also gives your management body something concrete to approve and oversee under Article 20(1). See the evidence map.
What are the fines under NIS2?
Fines are set in national law. Article 34 requires Member States to allow fines of up to at least €10 million or 2% of total worldwide annual turnover for essential entities, and €7 million or 1.4% for important entities, whichever is higher in each case.
When does NIS2 apply in the Netherlands?
The Netherlands implemented NIS2 through the Cyberbeveiligingswet, which entered into force on 15 August 2026 (Staatsblad 2026, 189, article 35). Other Member States have their own laws and dates.
We supply software to NIS2 entities. Does this help us?
Yes. Your customers have to take each direct supplier into account. With Escrow Pro you can give them release terms, a Software Resilience Certificate and a Recoverability Certificate showing your application rebuilds without your team.
Do we need Backup or Escrow?
It depends on the job. Backup keeps daily copies of systems you run yourself, so you can restore them. Escrow releases a supplier's code to you. Resilience and Continuity put the recovery with us, for supplier or in-house applications. Many organisations use more than one, in one account.
We're a financial entity. Is this the right page?
DORA has its own rules on ICT third-party risk and exit plans. See our DORA page for the evidence that applies there.
Is our code safe with you?
Codekeeper is ISO/IEC 27001:2022 certified. Deposits are encrypted at rest, and Agentic Verification runs on our own models, so code stays in our environment. See the Trust Center.
Keep essential services running. Keep the proof on file.
We'll map the applications behind your essential services to the protection and the evidence each one needs.