Coffer for Business · EU compliance

The EU changed the rules. We help you meet them — without the panic.

Two new European laws now reach almost every small digital business: the European Accessibility Act and NIS2. Neither arrives as a checklist you can hand to a developer. Coffer turns each one into a simple, automated path: scan, get a plain-English report, fix what matters, stay covered.

Automated scans & reports Plain-English fix-lists Built by a security engineer
Deadlines are already live

EAA: in force since 28 June 2025 — enforcement ramping through 2026.  ·  NIS2: transposed into national law across the EU; customer security questionnaires are landing now.

Two laws · two products

Regulatory deadlines are the one thing that makes a business buy. We make compliance boring and automatic.

European Accessibility Act · WCAG

EAA Accessibility Scanner

Point it at a website and it audits against WCAG, then hands back a branded report a non-developer can act on — the exact evidence the EAA now expects.

  • Automated WCAG 2.2 crawl — contrast, labels, keyboard, structure, media.
  • Branded PDF audit report + an accessibility statement draft.
  • Prioritised fix-list: what to fix first, and why it matters legally.
  • Continuous monitoring — re-scan on a schedule, alert on regressions.
Free scan Paid fix-list Monitoring €29–99/mo

Free first scan to prove value; report + fix-list one-off; monitoring subscription for ongoing cover.

NIS2 Directive · Supply chain

NIS2 Readiness Kit

NIS2 pushes security obligations down the supply chain. Small suppliers are suddenly drowning in customer security questionnaires. This gets them answer-ready.

  • Guided self-assessment mapped to NIS2 measures — no jargon.
  • Templated policy packs (access control, incident response, backups…).
  • A shareable readiness summary to return with customer questionnaires.
  • "Starter kit for 10-person IT suppliers" — sized for small teams.
Self-assessment Policy packs Win the contract

A purchase a contract depends on — priced as a one-off kit with optional update subscription.

Why Coffer for Business

Credible on security. Ruthless on automation. Honest on price.

Regulation-led, not fear-led

We don't sell scare stories. We turn a legal obligation into a checklist you can finish — and show exactly what "done" looks like for your business.

Automated end to end

Scanning, reporting and monitoring are software, not billable hours. That keeps the price fair for a small business and the coverage continuous, not one-and-done.

Built by a security engineer

The same studio behind Coffer's privacy-first apps. Security and data-protection are the house speciality — the content is credible because we live it.

Questions

EAA and NIS2, answered plainly

The things small businesses actually ask us before signing up. This is guidance from people who build compliance tooling, not legal advice.

What is the European Accessibility Act (EAA)?

An EU law that applies from 28 June 2025. It requires many consumer-facing digital products and services sold in the EU — online shops, banking, e-books, ticketing and transport apps among them — to be accessible, which in practice means meeting the WCAG standard. Each member state enforces it through its own national authority.

Who does NIS2 affect?

NIS2 sets EU cybersecurity duties for organisations in sectors such as energy, transport, health, digital infrastructure and IT services. It also makes those organisations responsible for the security of their suppliers, so a small vendor that is not directly in scope is increasingly asked to prove its security readiness in order to keep the contract.

Does the EAA apply to my business, or am I exempt?

If you sell covered digital products or services to consumers in the EU, start from the assumption that it applies. The directive does exempt microenterprises — fewer than 10 staff and under 2 million euro turnover — that provide services, and it allows relief where a change would impose a disproportionate burden. The exemptions are narrower than most people expect and member states have implemented them differently, so check with your national authority and treat our scan as a starting point rather than a legal opinion.

What are the penalties if we do nothing?

Both laws leave enforcement to national authorities, so the penalties differ by country: the EAA requires member states to set sanctions that are effective and dissuasive, while NIS2 adds fines and accountability at management level. We are deliberately not going to quote a scary number at you. For most small businesses the first real consequence is commercial rather than legal — a customer complaint, a procurement questionnaire you cannot answer, or a deal that stalls because you have no evidence to show.

Is an automated scan enough for EAA compliance?

No, and we will not pretend otherwise. Automated testing reliably catches a meaningful subset of WCAG issues — colour contrast, missing image alternatives, unlabelled form fields, broken heading structure, keyboard traps — but the criteria that need human judgement cannot be checked by a machine: whether alt text is actually useful, whether focus order makes sense, whether a custom widget works with a screen reader. Our scan does the mechanical part in minutes and flags clearly what a person still needs to review.

What happens after the free scan?

You get the report and you are free to stop there — no card, no obligation. If you want more, the paid step is a prioritised fix-list plus a draft accessibility statement, with optional monitoring that re-scans on a schedule and alerts you when something regresses. Both products are in early access at the moment, so joining the list is how you get the first scan when your track opens.

How long does the NIS2 self-assessment take?

It is designed to be finished in one sitting by someone who is not a security specialist: plain-language questions about access control, backups, patching and incident handling, with your answers saved so you can come back to them. Gathering the evidence usually takes longer than answering the questions, which is why the kit ships with policy templates you can adapt instead of writing them from scratch.

Something we have not covered? Email [email protected] and we will answer it here.