Skip to Content
Odoo Menu
  • Sign in
  • Try it free
  • Apps
    Finance
    • Accounting
    • Invoicing
    • Expenses
    • Spreadsheet (BI)
    • Documents
    • Sign
    Sales
    • CRM
    • Sales
    • POS Shop
    • POS Restaurant
    • Subscriptions
    • Rental
    Websites
    • Website Builder
    • eCommerce
    • Blog
    • Forum
    • Live Chat
    • eLearning
    Supply Chain
    • Inventory
    • Manufacturing
    • PLM
    • Purchase
    • Maintenance
    • Quality
    Human Resources
    • Employees
    • Recruitment
    • Time Off
    • Appraisals
    • Referrals
    • Fleet
    Marketing
    • Social Marketing
    • Email Marketing
    • SMS Marketing
    • Events
    • Marketing Automation
    • Surveys
    Services
    • Project
    • Timesheets
    • Field Service
    • Helpdesk
    • Planning
    • Appointments
    Productivity
    • Discuss
    • Approvals
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Industries
    Retail
    • Book Store
    • Clothing Store
    • Furniture Store
    • Grocery Store
    • Hardware Store
    • Toy Store
    Food & Hospitality
    • Bar and Pub
    • Restaurant
    • Fast Food
    • Guest House
    • Beverage Distributor
    • Hotel
    Real Estate
    • Real Estate Agency
    • Architecture Firm
    • Construction
    • Property Management
    • Gardening
    • Property Owner Association
    Consulting
    • Accounting Firm
    • Odoo Partner
    • Marketing Agency
    • Law firm
    • Talent Acquisition
    • Audit & Certification
    Manufacturing
    • Textile
    • Metal
    • Furnitures
    • Food
    • Brewery
    • Corporate Gifts
    Health & Fitness
    • Sports Club
    • Eyewear Store
    • Fitness Center
    • Wellness Practitioners
    • Pharmacy
    • Hair Salon
    Trades
    • Handyman
    • IT Hardware & Support
    • Solar Energy Systems
    • Shoe Maker
    • Cleaning Services
    • HVAC Services
    Others
    • Nonprofit Organization
    • Environmental Agency
    • Billboard Rental
    • Photography
    • Bike Leasing
    • Software Reseller
    Browse all Industries
  • Community
    Learn
    • Tutorials
    • Documentation
    • Certifications
    • Training
    • Blog
    • Podcast
    Empower Education
    • Education Program
    • Scale Up! Business Game
    • Visit Odoo
    Get the Software
    • Download
    • Compare Editions
    • Releases
    Collaborate
    • Github
    • Forum
    • Events
    • Translations
    • Become a Partner
    • Services for Partners
    • Register your Accounting Firm
    Get Services
    • Find a Partner
    • Find an Accountant
      • Get a Tailored Demo
    • Implementation Services
    • Customer References
    • Support
    • Upgrades
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +32 2 290 34 90
    • Get a Tailored Demo
  • Pricing
  • Help
  1. APPS
  2. Compliance
  3. NIS2 Cybersecurity Compliance for Odoo v 18.0
  4. Sales Conditions FAQ

NIS2 Cybersecurity Compliance for Odoo

by FlexigoTech https://flexigotech.com
Odoo
v 18.0 Third Party 5
Download for v 18.0 Deploy on Odoo.sh Live Preview
Apps purchases are linked to your Odoo account, please sign in or sign up first.
Availability
Odoo Online
Odoo.sh
On Premise
Odoo Apps Dependencies • Discuss (mail)
• Website (website)
Lines of code 4033
Technical Name flexigo_nis2_cybersecurity_compliance_toolkit
LicenseLGPL-3
Websitehttps://flexigotech.com
Versions 17.0 18.0 19.0
You bought this module and need support? Click here!
Availability
Odoo Online
Odoo.sh
On Premise
Odoo Apps Dependencies • Discuss (mail)
• Website (website)
Lines of code 4033
Technical Name flexigo_nis2_cybersecurity_compliance_toolkit
LicenseLGPL-3
Websitehttps://flexigotech.com
Versions 17.0 18.0 19.0
NIS2 Compliance · Odoo 19

NIS2 Cybersecurity Compliance Toolkit for Odoo 19

Turn NIS2 cybersecurity governance, risk management, incident readiness, supplier oversight and management accountability into one traceable, audit-ready workspace inside Odoo. Free and open source under LGPL‑3.

NIS2 Cybersecurity Compliance Toolkit for Odoo 19 banner showing the native compliance backend

The problem NIS2-covered organizations face today

Companies in scope of NIS2 often manage cybersecurity compliance across disconnected spreadsheets, policy folders, ticketing tools and external GRC software. Controls may exist, but management approval, supplier risk records, training evidence, incident reporting timelines and remediation ownership are scattered. The organization can say it has measures in place, but it cannot easily show who approved them, which risks they address, when effectiveness was assessed, what evidence supports them, and what remains open.

NIS2 raises the stakes: national transpositions can impose administrative fines of up to EUR 10,000,000 or 2% of total worldwide annual turnover on essential entities, and management bodies can be held personally accountable for overseeing cybersecurity risk-management measures. Reconstructing an audit trail after the fact is slow, expensive and stressful.

How the NIS2 Cybersecurity Compliance Toolkit solves it

The toolkit gives management, compliance, IT and auditors a structured evidence workspace aligned to the NIS2 Directive (EU) 2022/2555 and the EU implementing regulation for specified digital and ICT service entities. It connects applicability profiles, Article 21(2) controls, risks, incidents, suppliers, evidence, training and corrective actions in the same Odoo backend your departments already use. It does not replace legal counsel, a SIEM, an EDR or a vulnerability scanner, and it does not file reports with any authority — it keeps your NIS2 programme continuously documented and audit-ready.

Key features

Applicability profiles per entity

Document NIS2 scope for each legal entity: sector, size band, essential or important candidacy, implementing-regulation relevance and national review status — with a guided applicability wizard.

Article 21(2) control library

Map cybersecurity measures to the categories NIS2 lists — risk analysis, incident handling, business continuity, supply‑chain security and more — each with owner, evidence, review cadence and maturity status.

Cybersecurity risk register

Track risks across draft, under review, accepted and closed states with likelihood, impact and residual-risk acceptance, linked to the controls that address them.

Incident readiness pipeline

Move incidents through detection, triage, significant-incident assessment and a reportable decision, aligned to the Article 23 early-warning, notification and final-report milestones — without auto-filing to any authority.

Supplier and ICT dependency oversight

Document supplier cybersecurity reviews and dependency criticality across not reviewed, under review, approved, exception, rejected and expired states for Article 21(2)(d) supply‑chain security.

Management accountability and evidence vault

Record management approval and oversight per Article 20, keep an evidence vault of policies, test reports and attestations, track training, and generate board packs, audit packs and incident timelines.

Watch the walkthrough

English — product walkthrough
Español — recorrido del producto
Deutsch — Produktrundgang

See it inside Odoo

NIS2 applicability profiles for two seeded Spanish legal entities (Acme Industries S.L., Acme Logistics B.V.), both Member State Spain one essential entity candidate (ICT service management), one important entity candidate (financial market infrastructure)
1 · NIS2 applicability profiles for two seeded Spanish legal entities (Acme Industries S.L., Acme Logistics B.V.), both Member State Spain: one essential entity candidate (ICT service management), one important entity candidate (financial market infrastructure).
Cybersecurity training and awareness tracker for board, incident responders and staff across assigned/in progress/completed/overdue states
2 · Cybersecurity training and awareness tracker for board, incident responders and staff across assigned/in progress/completed/overdue states.
Article 21(2) control library with maturity status (implemented, partial, planned, not implemented)
3 · Article 21(2) control library with maturity status (implemented, partial, planned, not implemented).
Cybersecurity risk register spanning draft, under review, accepted and closed risks
4 · Cybersecurity risk register spanning draft, under review, accepted and closed risks.
Incident readiness pipeline detected, triage, under investigation, reportable decision pending, reported, closed
5 · Incident readiness pipeline: detected, triage, under investigation, reportable decision pending, reported, closed.
Management oversight reviews recording board approval of cybersecurity risk-management measures per Article 20 with review dates and states
6 · Management oversight reviews recording board approval of cybersecurity risk-management measures per Article 20 with review dates and states.
Supplier and ICT dependency review states not reviewed, under review, approved, exception, rejected, expired
7 · Supplier and ICT dependency review states: not reviewed, under review, approved, exception, rejected, expired.
Evidence vault holding policies, pentest reports, BCP minutes and supplier attestations with lifecycle states
8 · Evidence vault holding policies, pentest reports, BCP minutes and supplier attestations with lifecycle states.
Corrective and improvement action tracker with owners and open/in progress/overdue/completed states
9 · Corrective and improvement action tracker with owners and open/in progress/overdue/completed states.
Guided NIS2 applicability wizard that walks an entity through scope assessment inputs
10 · Guided NIS2 applicability wizard that walks an entity through scope assessment inputs.

Who it is for

  • Compliance officers, DPOs and legal counsel assessing NIS2 applicability and obligations.
  • CISOs and IT security managers maintaining controls, risks, incidents, evidence and remediation.
  • General managers and board members who must approve and oversee cybersecurity measures.
  • Procurement and vendor managers documenting supplier cybersecurity evidence.
  • Odoo partners delivering NIS2 readiness projects for mid-market customers.

Compatibility

Odoo 19 Community and Enterprise. Built on standard Odoo (base, mail, website, web) — no external SaaS, no mandatory API integration. Uses Odoo employees, attachments and activities where available. EU baseline plus country overlays for national transposition references.

Pricing

Free

Open source under LGPL‑3

No licence fee and no per-database price. Install it, own it, and extend it inside your Odoo. Optional paid services are available for applicability assessment, control mapping, incident-readiness and audit-pack preparation.

Frequently asked questions

How do I install the NIS2 Cybersecurity Compliance Toolkit on Odoo 19?

Add the module to your addons path or install it from the Apps list, then open the NIS2 Compliance menu. It depends only on standard Odoo (base, mail, website, web), so there is no external service to configure first.

Does it work on Odoo Community?

Yes. The toolkit runs on Odoo 19 Community and Enterprise. It does not require any Enterprise-only dependency.

Does this module make my company NIS2 compliant or file reports for me?

No. It is an evidence and governance workspace. It does not guarantee legal compliance, does not provide legal advice, and does not submit incident reports to CSIRTs or competent authorities. Final applicability, entity classification, incident reportability and notification destination depend on national transposition and competent authority guidance.

How does it handle NIS2 incident reporting timelines?

The incident workflow tracks the Article 23 milestones — an early warning, an incident notification and a final report — and helps you record the significant-incident decision and supporting evidence. You still send the actual notifications through your national channel.

What about DORA and CER overlap?

You can flag DORA or CER overlap on an entity profile. The toolkit warns that sector-specific Union law may partially displace or run in parallel with NIS2 and keeps the NIS2-specific language separate so obligations are not merged without legal review.

What languages are supported?

The interface follows your Odoo language. Marketing and walkthrough materials are provided in English, Spanish and German, and the EU baseline supports country overlays for national references.

Can I customise it for my company?

Yes. It is LGPL‑3 open source, so you can adapt controls, country overlays, review cadences and reports. FlexigoTech also offers paid services to tailor it to your programme.

Build your NIS2 evidence trail in Odoo

Install the free toolkit, document applicability, controls, risks, incidents and suppliers in one place, and stay audit-ready.

Contact FlexigoTech — comercial@flexigobe.com

Please log in to comment on this module

  • The author can leave a single reply to each comment.
  • This section is meant to ask simple questions or leave a rating. Every report of a problem experienced while using the module should be addressed to the author directly (refer to the following point).
  • If you want to start a discussion with the author, please use the developer contact information. They can usually be found in the description.
Community
  • Tutorials
  • Documentation
  • Forum
Open Source
  • Download
  • Github
  • Runbot
  • Translations
Services
  • Odoo.sh Hosting
  • Support
  • Upgrade
  • Custom Developments
  • Education
  • Find an Accountant
  • Find a Partner
  • Become a Partner
About us
  • Our company
  • Brand Assets
  • Contact us
  • Jobs
  • Events
  • Podcast
  • Blog
  • Customers
  • Legal • Privacy
  • Security

Odoo is a suite of open source business apps that cover all your company needs: CRM, eCommerce, accounting, inventory, point of sale, project management, etc.

Odoo's unique value proposition is to be at the same time very easy to use and fully integrated.

Website made with