File transfer that supports your NIS2 obligations

One supplier that cannot leak what it never sees

NIS2 pushed cybersecurity out of the IT department and into the boardroom - and out of your own network and into your supply chain. GCN.ONE encrypts every file in the browser before upload, so the documents you exchange with clients, authorities and partners reach us as ciphertext we cannot read, and every delivery leaves a signed, verifiable record.

Send a file now See pricing
What NIS2 is, in brief

NIS2 is the EU directive on network and information security. It replaced the original NIS directive and has been transposed into national law across the Union from October 2024, so what actually applies to you is your country’s implementing act rather than the directive itself.

It is broader and sharper than what came before: more sectors are covered, the security measures are spelled out rather than implied, incidents have to be reported on a tight clock, and senior management is personally accountable for getting it done.

Who it covers
Essential and important entities across energy, transport, banking, health, water, digital infrastructure, public administration, post, waste, chemicals, food and manufacturing - generally from 50 staff or EUR 10 million turnover, with some sectors in scope at any size.
Risk-management measures
Article 21 names them explicitly: risk analysis and security policies, incident handling, business continuity and backups, access control, the use of cryptography and encryption, security in acquisition and maintenance, and testing how well all of it actually works.
Supply-chain security
You answer for the security of your direct suppliers and service providers, and for how you exchange data with them. Every tool that carries your documents is part of the assessment - which is why vendor questionnaires got a lot longer.
Reporting and accountability
A significant incident means an early warning within 24 hours, a notification within 72 hours and a final report within a month. Management bodies must approve the measures and can be held liable, and supervisory authorities can fine and sanction.
How GCN.ONE helps

GCN.ONE is a file-transfer supplier, so it sits squarely in the supply-chain part of your assessment. The whole point of the design is to be a small piece of your attack surface rather than a large one. Here is what that gives you, item by item.

Encryption you do not have to trust us with
Files, filenames and messages are encrypted in the browser before upload, with keys we never receive. Article 21 asks for the use of cryptography; here it is structural, so a breach of our infrastructure exposes ciphertext and nothing else.
Evidence that a document actually arrived
Every link open and download start is recorded with a timestamp, and any delivered file can be issued a cryptographically signed delivery certificate that anyone can verify - useful when an incident timeline or a notification deadline has to be reconstructed.
EU infrastructure and jurisdiction
The systems that hold your data run in the European Union, under EU data-protection law, with sub-processors listed publicly and covered by Article 28 agreements. One less cross-border question in your supplier file.
Deletion that happens on its own
Transfers expire on download or on a date you set, and the encrypted data is then permanently deleted. Old documents stop accumulating in a mailbox or a share someone forgot about, which shrinks the blast radius of anything that goes wrong later.
A supplier file you can actually fill in
A data processing agreement you can sign yourself, a public sub-processor list, and technical documentation of the encryption model - the material a supply-chain assessment asks for, without a sales call to get hold of it.
A tamper-evident record behind it
Delivery events are written into an append-only, hash-chained audit log that is rolled up and publicly anchored, so the history behind a certificate cannot be quietly rewritten after the fact - by us or by anyone else.
What this page does not claim

No supplier can make you NIS2 compliant, and we do not claim to. Compliance is assessed for your organisation, by your organisation, against your national implementing law. What a supplier can do is be a controlled, documented component of it: we support your assessment with a data processing agreement and full technical documentation of the encryption model, and because the keys never reach us, the residual risk you are assessing here is transfer metadata rather than the documents themselves.

Request our Data Processing Agreement (DPA)

Put one supplier beyond reach
Send an encrypted file now, or see what it costs at scale.