NIS2/DORA compliant in weeks, not months

Reliable in operations, secure in audits

We set up the IT services of regulated companies to be DORA, KRITIS and NIS2 compliant, before an outage costs you revenue and reputation and non-compliance costs you a penalty. You stay able to act, even on the worst day of the year.

No transition period

NIS2 and DORA put your board on the hook.

Required: detect and stop attacks before damage occurs, rehearse recovery, and prove at any time that the measures work.

NIS2

The BSI grace period for registration ended on 31 July 2026, the duties themselves have applied since December 2025 with no transition period. Around 29,500 companies across 18 sectors, many from 50 employees upwards. Early warning to the BSI within 24 hours.

DORA

In force since 17 January 2025 for insurers, banks and financial entities. BaFin withdrew the VAIT for it. Initial report four hours after classification.

If you cannot produce evidence

Fines up to ten million euros or 2 percent of global turnover, whichever is higher (§ 65 BSIG).

The board is personally liable. Approving and supervising cannot be delegated (§ 38 BSIG, DORA Article 5).

If the contractual duties under Article 30 and the information register are missing, BaFin will challenge your outsourcing.

After an incident the regulator, your insurer and your customers ask for the same evidence. Whoever builds it then does not have it.

01

Quick check

Which law applies to you?

01

Quick check

Which law applies to you?

I am

02

Entry point

Three steps to success

We know where you want to go. Show us where you are and we take you there.

02

Entry point

Three steps to success

We know where you want to go. Show us where you are and we take you there.

1

Feasibility assessment

The result is an action plan. We deliver it, or your team does it internally.

You run a platform

Audit

You show us where you stand, we deliver the findings list for your board.

You are planning a platform

Workshop

You tell us your project, we deliver the target picture, the architecture draft and the delivery plan.

2

Delivery of the pillars

We are glad to take on the delivery and provide the estimated effort for each milestone in advance.

Your plan

Experience values

You are NIS2 and DORA compliant, with evidence

Your recovery is measured, not estimated, and your users do not notice individual failures.

Every duty from the comparison is covered and backed by a report.

Your team carries the procedures on without us, documented and repeatable.

Now the evidence appears in normal operation, without special steps before the audit.

03

The Aetherize concept

The three pillars of our concept

03

The Aetherize concept

The three pillars of our concept

What changes for you

High availability: the platform absorbs individual failures on its own

Audits: a report answers the auditor’s question

Access control: when someone leaves, every access ends at once

Tenant separation: other tenants’ data stays out of reach

Standard duration
2 to 8 weeks
One change, two attemptsExample

Nobody writes past the system. A rollback runs back down the same path.

Attempt 1

  1. Submission
  2. Signature
  3. Policy
  4. Production

rejected

The gate held. Unsigned artifact, rollout aborted.

Attempt 2

  1. Submission
  2. Signature
  3. Policy
  4. Production

rolled out

Signed, approved by a second person, live at 14:12.

Example values from a rollout record. The result is the change record, versioned out of the live system.

All four modules one by one, with what you provide for them. Platform in detail

What changes for you

The attack ends on the machine where it starts

Audit preparation shrinks to pulling a report

Your executives evidence their oversight duty with reports

The reporting deadlines are prepared before an incident

Standard duration
2 to 10 weeks
Two seconds, then four hoursExample
  1. 03:14:02process started from a temporary directorybehaviour rule triggers
  2. 03:14:02process terminatedblocked, not merely logged
  3. 03:14:03outbound connectiondropped, destination not approved
  4. 03:14:09event handed to your situation picturecase opened, on-call alerted
  5. 03:41classification by the on-call engineerreportable under DORA Article 19
  6. 06:58initial notification to the regulator3 h 17 after classification

Deadline

3 h 17 of 4 h

Without a prepared template and a named owner, the search starts here. The four hours run regardless.

Example values from an incident record. The result is the incident report with the full deadline chain.

All three modules one by one, with the line drawn to the management system. Security in detail

What changes for you

Not even an administrator can delete your backups

Recovery time and data loss are set per application

The drill record is your evidence towards the regulator

If your site goes down, the second one takes over

Standard duration
4 to 10 weeks
Two drills, the same finish lineExample

Backups immutable, access circles separated. Not even the backup administrator can shorten retention. That way the recovery point sits before the initial infection, not just before the encryption.

02 hTarget 4 h6 h8 h

Drill Q1

6 h 12

Target missed. Credentials were missing at the secondary site.

Drill Q3

3 h 20

Target held. Data loss 11 minutes against a 15 minute limit.

Example values from two drills. Your times are measured, not promised. The result is the drill record, your evidence towards auditor and regulator.

All three modules one by one, with what the second site requires. Business Continuity in detail

Your audit file

Each pillar creates the evidence you need and real value for your company.

Artificial intelligence

Agents, gateways and AI-assisted processes

AI on your own premises

Custom project

Migration, custom software, an additional site, audit support.

Custom software solutions

04

Comparison

What NIS2 and DORA require and which pillar delivers it

04

Comparison

What NIS2 and DORA require and which pillar delivers it

Changes and access on record

Auditors ask who changed what when, and who was allowed to access it.

A single path into production, every change with author, approval and timestamp.

Reliable operation, sufficient capacity

DORA Article 7 requires reliable, resilient systems, § 30 BSIG requires availability.

Redundant nodes absorb failures, the platform scales on its own and reports the bottleneck before it hits.

Detect and stop attacks

§ 30 BSIG requires risk measures, DORA Article 10 requires detection.

IDS and IPS at kernel level report and block the moment the attack starts.

Prove effectiveness

The board is liable for the measures actually working.

Every control is mapped to ISO 27001, BSI IT-Grundschutz and DORA, and the report comes versioned out of the running system.

Reporting within the deadlines

NIS2: early warning 24 hours, report 72 hours. DORA: initial report 4 hours after classification.

Report templates and the deadline chain are prepared. Alert paths and escalation are wired up.

Tested recovery plans

DORA Articles 11 and 12 and NIS2 require crisis management and backups.

Immutable backup, rehearsed recovery, the drill record as evidence.

Run AI accountably

Transparency duties of the AI Act under Article 50, in force since August 2026.

Every request recorded with user, model and version, documentation for Articles 12 and 13.

05

Aetherize GmbH

Who builds this for you

05

Aetherize GmbH

Who builds this for you

Aetherize GmbH is a consultancy from Germany with a deliberately small, experienced team. Every engineer works directly with you, with no account manager in between. We have taken platforms to production: in every major public cloud and on bare metal, for young SaaS providers as well as regulated and government-adjacent environments.

We diagnose before we prescribe, and we are not tied to any technology stack. Before we recommend anything, we look at your platform, your workloads, your spend and how your team works day to day. We recommend what that evidence points to, even when it turns out you need something different from what you came asking for. Hearing that before the project costs far less than after.

You talk to the engineer who does the work. They stay from the first call to go-live and own the project. We treat your outcome as if it were our own.

Michael and Karsten, the founders of Aetherize GmbH

Dr. Michael Dudzinski and Karsten Siemer

Founders

Michael and Karsten, the founders of Aetherize GmbH

Dr. Michael Dudzinski and Karsten Siemer

Founders

06

Why us

Everything stays with you, even after we leave.

06

Why us

Everything stays with you, even after we leave.

What other vendors do

The vendor runs a platform on their side. Connecting to it is faster, but it costs you your independence.

Your logs, your inventory and your configuration leave your premises. The renewal price becomes the price of your compliance.

When the contract ends, you lose every benefit and are no longer protected against fines and attacks.

Your infrastructure

Evidence

Logs

Inventory

Configuration

Vendor’s platform

Evidence

Your evidence sits with the vendor.

What we do

We build everything in your infrastructure - on premises or public cloud - and hand operations to your team.

You can leave any service any time, and stay independent.

You pay no subscription for your compliance.

The rules fit your system, not the average case.

Your infrastructure

Evidence

Your evidence stays with you.

Next step

30 minutes that belong before your next audit

An intro call with the founders. We listen to where you stand and recommend the best next step.

30 minutes

Free of charge

With the founders

Request an intro call

One email is enough. We reply with a proposed time.

Write an email

Next step

30 minutes that belong before your next audit

An intro call with the founders. We listen to where you stand and recommend the best next step.

30 minutes

Free of charge

With the founders

Request an intro call

One email is enough. We reply with a proposed time.

Write an email