NIS2 Supplier Statement
Many of our clients are covered by the NIS2 directive (EU 2022/2555, as implemented in Danish law) and are required to manage cybersecurity in their supply chain — including assessing suppliers like Available. This page answers the standard supplier questions once, publicly, so your assessment can start here instead of with a blank questionnaire.
Available's own NIS2 position
Available ApS (CVR 42398683) is a small enterprise below the NIS2 size thresholds and is not itself a covered entity (TODO: confirm conclusion with counsel and note the assessment date). We nonetheless operate our security program as if the bar applied: an ISMS aligned with ISO/IEC 27001:2022 (certification in progress), run by management and audited on a fixed cadence.
How we address the NIS2 Article 21(2) measures
| Measure | How Available addresses it |
|---|---|
| (a) Risk analysis & security policies | Management-owned, risk-based ISMS per ISO/IEC 27001:2022; documented risk methodology reviewed quarterly; our Information Security Policy is public. |
| (b) Incident handling | Documented incident response procedure with severity triage, containment-first response, evidence preservation, and structured post-incident reviews. See Security overview. |
| (c) Business continuity | Hourly backups of production service data with 7-day retention (RPO 1 hour), stored separately from production; restore tests at least twice a year; documented continuity arrangements. See Subprocessors & Service Levels. |
| (d) Supply-chain security | Supplier register with criticality tiers, security checks and DPAs before onboarding, annual reviews of critical suppliers, and a public subprocessor list with 30-day change notice. |
| (e) Secure development & vulnerability handling | Peer review of every change, CI gates, dependency vulnerability scanning, separated environments, no production data in test; remediation SLAs (critical ≤ 7 days). Vulnerability reports: security@available.dk (TODO: confirm address). |
| (f) Effectiveness assessment | Measurable security objectives tracked quarterly, annual internal ISMS audit, annual management review — and, once certified, independent ISO 27001 audits on a three-year cycle. |
| (g) Cyber hygiene & training | Mandatory security awareness training (onboarding + annual) with per-person completion records; per-version policy acknowledgements tracked in our compliance portal; MFA and a company password manager as baseline. |
| (h) Cryptography | TLS 1.2+ in transit, industry-standard encryption at rest, keys managed in cloud KMS; no in-house cryptography. |
| (i) HR security, access control & asset management | Screening proportionate to role, contractual confidentiality surviving employment, least-privilege access with quarterly reviews, same-working-day revocation at offboarding, maintained asset register. |
| (j) MFA & secured communications | MFA/SSO mandatory everywhere supported (passkeys preferred); all service communication encrypted in transit; named incident lead coordinates crisis communication. |
Incident notification for NIS2-covered clients
NIS2 gives covered entities tight reporting deadlines (24-hour early warning, 72-hour notification). As your supplier we commit to notifying affected clients without undue delay after establishing that an incident affects their service or data, with the facts you need for your own reporting — per our contracts, our DPAs, and GDPR where personal data is involved. Single point of contact: security@available.dk (TODO: confirm address).
Verification & documents
- Public: this statement, our Information Security Policy, Security overview, and Subprocessors & Service Levels.
- Under NDA: Statement of Applicability, audit results, and other assurance documentation.
- Once certified, our ISO/IEC 27001 certificate will be published on this site.
- Need your own questionnaire template completed or a signed copy of this statement? Contact security@available.dk — we aim to respond within TODO: e.g. 5 business days.