NIS2 is in force and regulators are already running inspections. At IOAS we built Audrix — a single system that ties NIS2, GDPR, ISO 27001 and the Slovak Act 69/2018 into one workflow, so that compliance stops being a project and becomes a process. The first 20 organisations get free access through our ticket system.
Why we built it
After watching for a year how Slovak companies and institutions cope with the new legislation — NIS2, GDPR, Act 69/2018, Decree 362/2018, the new Act 366/2024 and its Decree 227/2025 (Slovak national laws on cybersecurity) — we kept seeing the same pattern everywhere: Excel spreadsheets, an expensive external consultant and panic three weeks before the audit. Global GRC platforms do not cover Slovak legislation, they lack direct reporting to NBÚ (the Slovak National Security Authority), ÚOOÚ (the Slovak Data Protection Office) and SK-CERT (the national CSIRT), and they do not recognise Slovak personal-data formats (national ID numbers, IBAN SK, company ID, tax ID).
So at IOAS we decided to build Audrix — not yet another tool, but a single system that simplifies the entire process. Instead of five applications, three consultants and fifteen spreadsheets, you get one workflow.
Audit-ready. Every day.
Audrix doesn’t treat compliance as a one-off project before an audit. It treats it as a continuous state — controls run, evidence is collected automatically, and your compliance score is available 24/7. When NBÚ, ÚOOÚ or an accredited auditor shows up, the audit package is one click away.
A typical journey looks like this:
| Day | Milestone | What happens |
|---|---|---|
| 1 | Onboarding | Scope, integrations, team |
| 7 | Gap analysis | Where you stand today |
| 21 | Remediation | Policies, controls, evidence |
| 35 | Internal audit | A dry run before the real one |
| 45 | Audit-ready | Ready for NBÚ / ÚOOÚ |
For organisations that already hold ISO 27001 or SOC 2, cross-framework mapping typically cuts this down to 15–25 days.
Four regulations. One system.
Controls are mapped automatically across frameworks — do the work once, satisfy several obligations:
- NIS2 (EU 2022/2555) — 84 controls, SK-CERT reporting
- GDPR (EU 2016/679) + Slovak Act 18/2018 — 47 controls, ÚOOÚ reporting
- ISO 27001 : 2022 — 93 Annex A controls
- Act 69/2018 Coll. on cybersecurity + Decree 362/2018 (Slovak national laws) — 68 controls, NBÚ reporting
Plus coverage of the new Act 366/2024 and Decree 227/2025, ISO 22301 (crisis management and BCM), and the Slovak law on soft-target protection — areas that global GRC platforms either ignore or have left half-finished.
Eleven modules, one workflow
We designed the modules so they cover the full agenda of a DPO, a CISO, a crisis manager and an external auditor — without ever having to open a second tool:
- Evidence collection — automatic evidence from Microsoft 365, Google Workspace, AWS, Azure and GitHub
- Cross-framework mapping — a control for ISO 27001 also counts towards NIS2, SOC 2 and GDPR
- Risk register based on ISO 27005
- Slovak PII detector — our own BERT model fine-tuned on a Slovak corpus, F1 0.94 (national IDs, IBAN, company ID, tax ID, addresses)
- Vendor risk management — DPA templates, due-diligence workflow, NIS2 Art. 21(5)
- Policy builder — 42 Slovak templates reviewed by accredited auditors
- Incident response — workflow from detection through to the 24h/72h reports to SK-CERT and ÚOOÚ
- RoPA, DPIA, DSAR — records of processing activities, impact assessments, data-subject requests
- Audit reporting — one-click audit package for NBÚ, ÚOOÚ and any accredited body
- Crisis management and BCM — ISO 22301 + NIS2 Art. 21(c), BIA, BCP, DR plans, tabletop exercises
- Soft-target security — facility categorisation, threat assessment, security plan, training
What we set out to remove
Audrix does not replace the role of a DPO or CISO — you still need them. It removes 80 % of the administrative work that DPOs do today (filling in tables, gathering evidence, writing policies). The DPO can focus on the decisions that genuinely require human judgement.
The Slovak PII detector runs locally inside the customer’s infrastructure — sensitive data never leaves your environment. Primary data centres are in Germany and Frankfurt; for the public sector we offer on-premise deployment. Encryption at rest and in transit (AES-256, TLS 1.3). Audrix itself is NIS2-compliant and undergoes annual penetration testing.
Access for the first 20 organisations — by ticket
We built Audrix as the IOAS team and we want the first twenty organisations to get access with no upfront cost — in exchange for the feedback that will help us tune the tool to Slovak practice.
How it works:
- Fill in the registration form — every field is optional, share only what you know and want to tell us about your organisation.
- Your request enters the approval queue as a ticket.
- The IOAS team reviews every ticket — we focus on genuine need and on whether the organisation is ready to put the deployment to use.
- An approved ticket unlocks full access to Audrix, including onboarding.
Once the 20 spots are filled, Audrix moves to its standard pricing model (Start packages from €290 / month, Professional from €690, Enterprise from €1,900 / month).
Closing
Compliance is no longer something you can defer. NIS2 brings personal liability for leadership — this isn’t just about the company. Fines reach up to €10M or 2 % of global turnover (essential entities), and up to €20M or 4 % of turnover under GDPR.
Audrix exists to turn that pressure into a manageable process. Not magical, not miraculous — just a well-assembled workflow that the IOAS team has put together so a Slovak organisation can be audit-ready without five tools and three consultants.