NIS2/DORA compliant in weeks, not months
Reliable in operations, secure in audits
We set up the IT services of regulated companies to be DORA, KRITIS and NIS2 compliant, before an outage costs you revenue and reputation and non-compliance costs you a penalty. You stay able to act, even on the worst day of the year.
No transition period
NIS2 and DORA put your board on the hook.
Required: detect and stop attacks before damage occurs, rehearse recovery, and prove at any time that the measures work.
NIS2
The BSI grace period for registration ended on 31 July 2026, the duties themselves have applied since December 2025 with no transition period. Around 29,500 companies across 18 sectors, many from 50 employees upwards. Early warning to the BSI within 24 hours.
DORA
In force since 17 January 2025 for insurers, banks and financial entities. BaFin withdrew the VAIT for it. Initial report four hours after classification.
If you cannot produce evidence
Fines up to ten million euros or 2 percent of global turnover, whichever is higher (§ 65 BSIG).
The board is personally liable. Approving and supervising cannot be delegated (§ 38 BSIG, DORA Article 5).
If the contractual duties under Article 30 and the information register are missing, BaFin will challenge your outsourcing.
After an incident the regulator, your insurer and your customers ask for the same evidence. Whoever builds it then does not have it.
1
Feasibility assessment
The result is an action plan. We deliver it, or your team does it internally.
You run a platform
Audit
You show us where you stand, we deliver the findings list for your board.
You are planning a platform
Workshop
You tell us your project, we deliver the target picture, the architecture draft and the delivery plan.
2
Delivery of the pillars
We are glad to take on the delivery and provide the estimated effort for each milestone in advance.
Your plan
Experience values
Action plan
Platform4 modules2 to 8 weeksSecurity3 modules2 to 10 weeksBusiness Continuity and Disaster Recovery3 modules4 to 10 weeksYou are NIS2 and DORA compliant, with evidence
Your recovery is measured, not estimated, and your users do not notice individual failures.
Every duty from the comparison is covered and backed by a report.
Your team carries the procedures on without us, documented and repeatable.
Now the evidence appears in normal operation, without special steps before the audit.
What changes for you
High availability: the platform absorbs individual failures on its own
Audits: a report answers the auditor’s question
Access control: when someone leaves, every access ends at once
Tenant separation: other tenants’ data stays out of reach
- Standard duration
- 2 to 8 weeks
Nobody writes past the system. A rollback runs back down the same path.
Attempt 1
- Submission
- Signature
- Policy
- Production
rejected
The gate held. Unsigned artifact, rollout aborted.
Attempt 2
- Submission
- Signature
- Policy
- Production
rolled out
Signed, approved by a second person, live at 14:12.
Example values from a rollout record. The result is the change record, versioned out of the live system.
All four modules one by one, with what you provide for them. Platform in detail
What changes for you
The attack ends on the machine where it starts
Audit preparation shrinks to pulling a report
Your executives evidence their oversight duty with reports
The reporting deadlines are prepared before an incident
- Standard duration
- 2 to 10 weeks
03:14:02process started from a temporary directorybehaviour rule triggers03:14:02process terminatedblocked, not merely logged03:14:03outbound connectiondropped, destination not approved03:14:09event handed to your situation picturecase opened, on-call alerted03:41classification by the on-call engineerreportable under DORA Article 1906:58initial notification to the regulator3 h 17 after classification
Deadline
3 h 17 of 4 h
Without a prepared template and a named owner, the search starts here. The four hours run regardless.
Example values from an incident record. The result is the incident report with the full deadline chain.
All three modules one by one, with the line drawn to the management system. Security in detail
What changes for you
Not even an administrator can delete your backups
Recovery time and data loss are set per application
The drill record is your evidence towards the regulator
If your site goes down, the second one takes over
- Standard duration
- 4 to 10 weeks
Backups immutable, access circles separated. Not even the backup administrator can shorten retention. That way the recovery point sits before the initial infection, not just before the encryption.
02 hTarget 4 h6 h8 h
Drill Q1
6 h 12
Target missed. Credentials were missing at the secondary site.
Drill Q3
3 h 20
Target held. Data loss 11 minutes against a 15 minute limit.
Example values from two drills. Your times are measured, not promised. The result is the drill record, your evidence towards auditor and regulator.
All three modules one by one, with what the second site requires. Business Continuity in detail
Your audit file
Each pillar creates the evidence you need and real value for your company.
Artificial intelligence
Agents, gateways and AI-assisted processes
AI on your own premises
Custom project
Migration, custom software, an additional site, audit support.
Custom software solutions
Changes and access on record
Auditors ask who changed what when, and who was allowed to access it.
A single path into production, every change with author, approval and timestamp.
Reliable operation, sufficient capacity
DORA Article 7 requires reliable, resilient systems, § 30 BSIG requires availability.
Redundant nodes absorb failures, the platform scales on its own and reports the bottleneck before it hits.
Detect and stop attacks
§ 30 BSIG requires risk measures, DORA Article 10 requires detection.
IDS and IPS at kernel level report and block the moment the attack starts.
Prove effectiveness
The board is liable for the measures actually working.
Every control is mapped to ISO 27001, BSI IT-Grundschutz and DORA, and the report comes versioned out of the running system.
Reporting within the deadlines
NIS2: early warning 24 hours, report 72 hours. DORA: initial report 4 hours after classification.
Report templates and the deadline chain are prepared. Alert paths and escalation are wired up.
Tested recovery plans
DORA Articles 11 and 12 and NIS2 require crisis management and backups.
Immutable backup, rehearsed recovery, the drill record as evidence.
Run AI accountably
Transparency duties of the AI Act under Article 50, in force since August 2026.
Every request recorded with user, model and version, documentation for Articles 12 and 13.
Aetherize GmbH is a consultancy from Germany with a deliberately small, experienced team. Every engineer works directly with you, with no account manager in between. We have taken platforms to production: in every major public cloud and on bare metal, for young SaaS providers as well as regulated and government-adjacent environments.
We diagnose before we prescribe, and we are not tied to any technology stack. Before we recommend anything, we look at your platform, your workloads, your spend and how your team works day to day. We recommend what that evidence points to, even when it turns out you need something different from what you came asking for. Hearing that before the project costs far less than after.
You talk to the engineer who does the work. They stay from the first call to go-live and own the project. We treat your outcome as if it were our own.
What other vendors do
The vendor runs a platform on their side. Connecting to it is faster, but it costs you your independence.
Your logs, your inventory and your configuration leave your premises. The renewal price becomes the price of your compliance.
When the contract ends, you lose every benefit and are no longer protected against fines and attacks.
Your infrastructure
Logs
Inventory
Configuration
Vendor’s platform
Your evidence sits with the vendor.
What we do
We build everything in your infrastructure - on premises or public cloud - and hand operations to your team.
You can leave any service any time, and stay independent.
You pay no subscription for your compliance.
The rules fit your system, not the average case.
Your infrastructure
Your evidence stays with you.
