NewEscrow Pro, Resilience, Continuity and Agentic Verification: from holding the code to proving it comes back.The new line-up is here.See what's new
Why this page looks like this. Production leads with "Achieve NIS2 compliance with bulletproof software resilience" and promises "Satisfied NIS2 supply chain security requirements" and "Protection from €10 million fines". All three overclaim: we provide evidence, and the entity and its supervisor decide. The new page tells the five-step story in NIS2 terms:
  • The exposure: what Article 21 and Article 20 actually say, quoted.
  • The shift: from a supplier list to proof that each application comes back.
  • The model: applications, in-house and supplier, each with a protection.
  • The proof: an evidence map from each article to the document that supports it.
  • The next step: book a demo, or get the sample evidence pack.
The headline borrows the launch line ("Keep your software running") and adds the evidence angle. The hero mock shows in-house and supplier applications side by side, because NIS2 covers both. All regulatory text on this page was checked on EUR-Lex on 7 Oct 2026, in the consolidated text of Directive (EU) 2022/2555 (CELEX 02022L2555-20221227), because the fetch tool cuts off the Official Journal page before the articles. Legal should confirm every quote against the Official Journal text before launch.
NIS2 · Directive (EU) 2022/2555

Keep essential services running. Keep the proof on file.

NIS2 asks essential and important entities to manage business continuity and supply chain security. Codekeeper protects the applications your services run on, in-house or from a supplier, and gives you dated evidence that each one can come back.

  • Trusted by 3,500+ teams
  • ISO/IEC 27001:2022 certified
  • Evidence mapped to Article 21(2)(c) and (d)
Social proof straight after the promise. These are the logos production already uses, loaded from codekeeper.co. Where an image can't load (for example in the preview), the name shows instead. Use the approved set only.

Trusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors

Airbus Bayer European Parliament General Motors Intuit Nestlé PepsiCo Pfizer
Step 1, the exposure, in the Directive's own words. Production cites "Article 21(2)(D)" on the Solutions page for management-body accountability, and "Art. 21(2)(c)" in the DORA evidence pack. Checked against the text: business continuity, backup and disaster recovery are 21(2)(c); supply chain security is 21(2)(d); approval and oversight by the management body is Article 20(1). Each quote below is verbatim from EUR-Lex (consolidated text). The ellipses mark where the list of measures is shortened.
  • Fines: Article 34(4) and 34(5) say Member States must provide for fines "of a maximum of at least" €10M or 2% (essential) and €7M or 1.4% (important), whichever is higher. That's a floor for the national maximum, not the maximum itself, so the copy says "up to at least". The homepage stat calls €10M or 2% "the maximum NIS2 fine"; suggest the same wording there.
  • Dates: Article 41(1) sets 18 October 2024 as the date Member States apply their measures. The Netherlands date comes from Staatsblad 2026, 189, Article 35: "De Cyberbeveiligingswet en dit besluit treden in werking met ingang van 15 augustus 2026." Production's "will take effect in early 2026" is out of date.
  • Removed: production's "criminal liability", "career-ending bans" and "authorities take control" lines. Article 20(1) says management bodies "can be held liable", which is quoted instead. Legal should review the quotes and the disclaimer.
Sources: eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02022L2555-20221227 (Art. 20(1), 21(2), 21(3), 34(4), 34(5), 41(1)); zoek.officielebekendmakingen.nl/stb-2026-189 (Art. 35).

What NIS2 asks

Continuity and suppliers are named in the Directive.

Article 21 lists the measures essential and important entities must take, at the least. Two of them are about the applications your services run on. Article 20 puts the management body in charge of them.

EUBusiness continuity
“The measures referred to in paragraph 1 … shall include at least the following: … (c) business continuity, such as backup management and disaster recovery, and crisis management;”
Directive (EU) 2022/2555, Article 21(2), point (c)
EUSupply chain security
“The measures referred to in paragraph 1 … shall include at least the following: … (d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers;”
Directive (EU) 2022/2555, Article 21(2), point (d)
EUEach direct supplier
“Member States shall ensure that, when considering which measures referred to in paragraph 2, point (d), of this Article are appropriate, entities take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures.”
Directive (EU) 2022/2555, Article 21(3)
EUManagement bodies
“Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article.”
Directive (EU) 2022/2555, Article 20(1)

Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.

€10M or 2%of worldwide annual turnover, whichever is higher: Member States must allow fines up to at least this for essential entitiesDirective (EU) 2022/2555, Art. 34(4)
€7M or 1.4%of worldwide annual turnover, whichever is higher: the same floor for important entitiesDirective (EU) 2022/2555, Art. 34(5)
18 Oct 2024the date the Directive set for Member States to apply their national NIS2 rulesDirective (EU) 2022/2555, Art. 41(1)
15 Aug 2026the Netherlands' Cyberbeveiligingswet in force. National dates vary, so check yoursStaatsblad 2026, 189, art. 35
Step 2, the shift: from a supplier file to proof. Most NIS2 programmes already have a supplier list and contract clauses. The gap is evidence that a critical application could come back if its supplier stopped or an attack took it down. The right-hand list uses only confirmed product facts: protections per application, agreed release or recovery terms, rebuilds without the vendor, SBOM and Exit workbook. No fear lines.

The shift

A plan on paper is the start. Proof it works is the goal.

NIS2 asks for backup management, disaster recovery and attention to each direct supplier. A policy describes what should happen. Evidence shows it can.

What many supplier files hold today

  • A list of suppliers with a risk rating
  • A continuity clause in the contract
  • A recovery plan that assumes the supplier will help
  • No record of what the software depends on

What Codekeeper adds

  • A protection on each critical application, in-house or supplier
  • Release or recovery terms agreed before anything goes wrong
  • A rebuild with no help from the supplier, and a dated Recoverability Certificate
  • An SBOM and an Exit workbook for each rebuilt application
Step 3, the model, in NIS2 order. Four steps, one sentence each: applications, protections, proof, and the management body. Step 4 ties the evidence to Article 20(1), which is the board-level reason to buy. Backup is the protection for in-house systems; Escrow, Resilience and Continuity are for supplier applications. Rebuilds run on supported technology stacks, which step 3 says.

How it works

From your service map to evidence on file.

One account for every application an essential service depends on.

1

List what your services run on

Add the applications behind each essential service: the ones you build and the ones you buy.

2

Attach a protection

Escrow for supplier applications. Resilience or Continuity for supplier or in-house applications. Backup for systems you run yourself.

3

Prove it comes back

Agentic Verification rebuilds the deposit in a sealed sandbox, in hours, on supported technology stacks.

4

Report to the board

Dated certificates and run reports give your management body something concrete to approve and oversee.

Step 4, the proof: which document supports which article. This is the table compliance teams copy into their file, so it names documents, not features. Every document is a confirmed output: Software Resilience Certificate and vault report (every protection), Recoverability Certificate, run report, SBOM, build steps, Exit workbook and deployable copy (Pro and Continuity), Tested Exit Report (Exit Exercise add-on). The live environment map is a confirmed Continuity setup step.
  • Confirm before launch: production says Software Backup includes a Software Resilience Certificate. Confirm it carries over to the new line-up before the backup row names it.
  • The row labels paraphrase the articles quoted above; they aren't quotes.

Evidence map

Evidence for each article.

What you can put on file for business continuity, supply chain security and management oversight, and which protection it comes with.

NIS2Codekeeper evidence
Art. 21(2)(c)
Backup management
Daily backups of your in-house applications, restorable when you need them.
Software Resilience CertificateSoftware Backup
Art. 21(2)(c)
Disaster recovery
Proof that a critical application rebuilds from its deposit in a sealed sandbox, with no help from the supplier.
Recoverability CertificateRun reportExit workbookDeployable copyEscrow Pro · Resilience Pro · Continuity
Art. 21(2)(c)
Crisis management
A recovery you don't have to run yourself. With Continuity, we also keep the live environment paid and switched on for an agreed period while we recover.
Resilience ArrangementLive environment mapResilience · Resilience Pro · Continuity
Art. 21(2)(d)
Supply chain security
Release or recovery terms for each direct supplier's application, agreed up front, and an automated check of what's deposited.
Escrow AgreementSoftware Resilience CertificateVault reportEscrow · Resilience · Continuity
Art. 21(3)
Quality of each supplier's product
A software bill of materials and documented build steps for each rebuilt supplier application.
SBOMBuild stepsEscrow Pro · Resilience Pro · Continuity
Art. 20(1)
Approval and oversight by the management body
Dated evidence per application for the board to review. Add an Exit Exercise when you need people to test the business functions as well.
CertificatesRun reportsTested Exit ReportEvery protection · Exit Exercise as an add-on

Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.

Step 4 continued: the three proofs, in the same words as everywhere else. Production's NIS2 page sells "Verification" with "Software Resilience Certificates proving compliance readiness". Those levels are replaced, and no certificate proves compliance. The ladder is the agreed one: there, it builds, you could exit. The Recoverability Certificate line keeps the agreed wording: it documents the rebuild and doesn't grant release rights.

The proof

Proof beats promises.

Every protection comes with evidence. The higher you go, the more it proves.

Every protection

Software Resilience Certificate

The deposit is held, and an automated check confirms what's in it, with a vault report.

Proves: it's there.

Escrow Pro · Resilience Pro · Continuity

Recoverability Certificate

AI agents rebuild the deposit in a sealed sandbox, with no help from the supplier, in hours. It documents the rebuild; release rights come from the agreement.

Proves: it builds. Agentic Verification

Add-on to any plan

Tested Exit Report

Our specialists rebuild by hand in a clean room and test the business functions you nominate, without the original developers. The annex maps to your framework.

Proves: you could exit and keep working. Exit Exercise

Step 3 again, now as a choice, with prices. NIS2's "crisis management" maps naturally to the question "who runs the recovery?", so the three jobs sit here with the existing Continuity film (54 s), which shows the live environment kept switched on. "From" prices are the 6 Oct list; the lead is the agreed price logic sentence. Backup is named as the in-house protection without a price, because its production price still has a $99 vs $89 conflict to resolve.

Choose the protection

Who runs the recovery when a supplier stops?

Escrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on.

Released to you

Escrow

Deposit→Released to you→You recover

When the agreed conditions are met, the deposit is released to you. Escrow Pro adds proof it builds. Explore Escrow

From $199

Recovered by us

Resilience

Deposit→Comes to us→We recover

If the application fails, Codekeeper runs the recovery for you. Resilience Pro starts from a deposit we know builds. Explore Resilience

From $399

Kept switched on

Continuity

Live service kept on+We recover

Everything in Resilience Pro, plus the live environment kept paid and switched on for an agreed period while we recover. Explore Continuity

From $1,449

Prices per application per month. For your own in-house systems, Software Backup attaches the same way. See all prices

Three audiences, by their position in NIS2. The first two cards follow the Directive's own split of sectors: Annex I, "Sectors of high criticality", and Annex II, "Other critical sectors" (checked on EUR-Lex: energy, transport, banking, health and digital infrastructure in Annex I; postal and courier services, chemicals, food and manufacturing in Annex II). They're not labelled essential and important, because Article 3 decides that by type and size, not by sector alone. The third card speaks to suppliers of NIS2 entities, who get asked for evidence under Article 21(3), and routes them to Escrow Pro.

Who it's for

Wherever you sit in the supply chain.

Sectors of high criticality

Energy, transport, banking, health, digital infrastructure and the rest of Annex I. Show the services you run can recover. Continuity

Other critical sectors

Manufacturing, chemicals, food, postal and courier services and the rest of Annex II. Put evidence behind the supplier measures in your plan. Resilience

Suppliers to NIS2 entities

Your customers have to consider each direct supplier. Give them a certificate and proof your application builds. Escrow Pro

The secondary conversion, on every page. Visitors who aren't ready to talk can still leave their email. The sample evidence pack is the same offer on every page, so the site has one lead magnet instead of a different e-book per page. It also carries the launch story: proof, not promises. The button goes to the sample evidence pack page.

Sample evidence pack

See what your auditor would receive.

An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.

  • Recoverability Certificate
  • Run report
  • SBOM and Exit workbook excerpts
Get the sample evidence pack
The questions NIS2 buyers ask, in the order sales hears them. Compliance first, then which articles, then fines, then the Netherlands (production had this question; the answer is now dated and sourced to the Staatsblad). Production's NCSC "basic measures" answer is cut: it isn't about our product and we haven't checked the source. The DORA answer avoids any claim about how the two laws interact; legal can add that if they want it.

Questions

Before your next NIS2 review.

Will Codekeeper make us NIS2 compliant?

No product can do that on its own. Codekeeper gives you evidence for your file: certificates, run reports, SBOMs and, if you add an Exit Exercise, a Tested Exit Report. Whether it meets a specific requirement is for you and your assessor to decide.

Which parts of NIS2 does the evidence relate to?

Mainly Article 21(2)(c), business continuity, including backup management, disaster recovery and crisis management, and Article 21(2)(d), supply chain security, with Article 21(3) on assessing each direct supplier. The evidence also gives your management body something concrete to approve and oversee under Article 20(1). See the evidence map.

What are the fines under NIS2?

Fines are set in national law. Article 34 requires Member States to allow fines of up to at least €10 million or 2% of total worldwide annual turnover for essential entities, and €7 million or 1.4% for important entities, whichever is higher in each case.

When does NIS2 apply in the Netherlands?

The Netherlands implemented NIS2 through the Cyberbeveiligingswet, which entered into force on 15 August 2026 (Staatsblad 2026, 189, article 35). Other Member States have their own laws and dates.

We supply software to NIS2 entities. Does this help us?

Yes. Your customers have to take each direct supplier into account. With Escrow Pro you can give them release terms, a Software Resilience Certificate and a Recoverability Certificate showing your application rebuilds without your team.

Do we need Backup or Escrow?

It depends on the job. Backup keeps daily copies of systems you run yourself, so you can restore them. Escrow releases a supplier's code to you. Resilience and Continuity put the recovery with us, for supplier or in-house applications. Many organisations use more than one, in one account.

We're a financial entity. Is this the right page?

DORA has its own rules on ICT third-party risk and exit plans. See our DORA page for the evidence that applies there.

Is our code safe with you?

Codekeeper is ISO/IEC 27001:2022 certified. Deposits are encrypted at rest, and Agentic Verification runs on our own models, so code stays in our environment. See the Trust Center.

The same close on every page. The NIS2 page closes on its own headline, so the promise the visitor arrived with is the last thing they read. Every page ends on the same two actions in the same order: Book a demo, then the sample evidence pack.

Keep essential services running. Keep the proof on file.

We'll map the applications behind your essential services to the protection and the evidence each one needs.