# Security Monitoring & NIS2 — from assessment to a working SOC and certification readinessAn organization under NIS2 stands up real security monitoring — a self-hosted SIEM/XDR, hardened perimeter, and an ISO 27001 / BSI ISMS — from an OSSTMM assessment to a working SOC and a trained in-house team.

NIS2 makes security oversight a management responsibility — but the organization has no real detection: no SIEM, no audit trails, no incident path. It needs **provable security monitoring** and a working SOC, and it wants its own team to run it.

## Building blocks

| Layer | What we deploy / do |
|---|---|
| Detection & response | [Security & Observability Platform](/portfolio/sovereign-security-observability-platform/) (SIEM/XDR) |
| Perimeter | [Sovereign Edge Firewall](/portfolio/sovereign-edge-firewall/) · [Abusive HTTP Watch](/portfolio/abusive-http-watch/) · [Certificate Authority](/portfolio/sovereign-certificate-authority/) |
| People | [Security Officer](/portfolio/rent-a-security-officer/) · [DPO](/portfolio/rent-a-data-protection-officer/) |
| Disciplines | [Security](/security/) · [Digital Sovereignty](/digital-sovereignty/) |

The result: a working SOC the organization owns — provable control, NIS2-defensible, ISO 27001 / BSI-ready, run by a trained in-house team. → [Talk to us](/contact/)
