EU · 8 controls evidenced

    Continuous evidence for NIS2 Directive

    Article 21 cybersecurity measures + Article 23 incident reporting.

    https://

    170+ checks · 10 layers · Results in <60s · No signup

    See your NIS2 Directive readiness in 60 seconds. Free, no signup.

    Sample evidence
    acme-corp.com · NIS2 Directive
    Live
    Art. 21(2)(a) Risk analysis & information system security
    Reputation & threat intelligence
    Art. 23 Incident notification (24h / 72h / 1 month)
    Credential exposure monitoring
    Art. 21(2)(b) Incident handling
    DNS hygiene & DNSSEC
    Art. 21(2)(d) Supply-chain security
    Secure HTTP response headers
    Updated continuously+ 4 more controls
    Why it matters

    NIS2 Directive in 30 seconds

    NIS2 obliges essential and important entities across the EU to implement specific technical and organisational risk-management measures, and to detect and report significant incidents within strict timeframes. Continuous external monitoring is one of the most direct ways to prove Art. 21(2) measures are effective.

    Scope

    Essential and important entities in 18 sectors (energy, transport, banking, health, digital infrastructure, postal, public administration, manufacturing, food, chemicals, ICT service management, etc.) operating in the EU.

    Exposure

    Up to €10M or 2% of global annual turnover (essential entities); €7M or 1.4% (important entities).

    Clause-by-clause mapping

    How Security Monitor evidences NIS2 Directive

    Each row links a NIS2 Directive clause to the external check we perform and the evidence it produces. Mappings are reviewed by our compliance team and updated when standards change.

    NIS2 Directive clauseWhat it requiresHow we evidence it
    REP-1
    Art. 21(2)(a) Risk analysis & information system security
    Policies on risk analysis and information system security must be in place and effective.
    Reputation & threat intelligence
    We cross-check the domain and its IPs against VirusTotal, Shodan, Spamhaus, URLhaus and Google Safe Browsing.
    BREACH-1
    Art. 23 Incident notification (24h / 72h / 1 month)
    Significant incidents must be detected and notified to the national CSIRT within 24h (early warning) and 72h (assessment).
    Credential exposure monitoring
    We query Have I Been Pwned for breaches involving the monitored domain and surface affected accounts.
    DNS-1
    Art. 21(2)(b) Incident handling
    Incident handling capabilities require continuous monitoring of network and DNS-level signals.
    DNS hygiene & DNSSEC
    We resolve A, AAAA, MX, NS, CAA and DNSSEC records and flag anomalies, dangling records and missing controls.
    WEB-1
    Art. 21(2)(d) Supply-chain security
    Security of network and information systems used in the supply chain, including web-facing services, must be addressed.
    Secure HTTP response headers
    We test for HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy and X-Content-Type-Options on the live site.
    EXP-1
    Art. 21(2)(e) Security in acquisition, development and maintenance
    Vulnerability handling and disclosure, including detection of inadvertently exposed assets.
    Exposed files & admin panels
    We probe for publicly accessible .env, .git, backups, admin panels and other sensitive paths that should never be reachable.
    EMAIL-1
    Art. 21(2)(g) Cyber hygiene & training
    Basic cyber hygiene practices (incl. email authentication) and training must be implemented.
    Email authentication (SPF / DKIM / DMARC)
    We resolve and validate SPF, DKIM and DMARC records, including DMARC enforcement policy and reporting addresses.
    TLS-1
    Art. 21(2)(h) Cryptography
    Policies and procedures regarding the use of cryptography and, where appropriate, encryption.
    Encrypted transport (TLS 1.2+)
    We verify the certificate chain, expiry, supported TLS versions and cipher suites on every public hostname.
    SUB-1
    Art. 21(2)(d) Supply-chain security & asset management
    Maintain an accurate inventory of network and information systems and address security in direct-supplier relationships, including third-party services exposed via your public domain (the third-party data flow map).
    Third-party data flow map (subdomains & external services)
    We enumerate subdomains via Certificate Transparency logs, fingerprint every third-party service they load (analytics, payments, chat, CDNs, tag managers, ad networks, fonts) and map where browser-side data flows. This is the externally-observable evidence regulators ask for under supplier, supply-chain and processor-inventory clauses.
    Honest scope

    What we don’t cover for NIS2 Directive

    External monitoring is one part of compliance. These areas need other evidence — typically from your GRC platform, HR system, or internal logging:

    • Internal access control, MFA on privileged accounts (Art. 21(2)(j))
    • Business continuity, backup management and crisis management (Art. 21(2)(c))
    • Formal incident notification submission to the national CSIRT (we surface the trigger; you submit)
    FAQ

    NIS2 Directive questions

    See your NIS2 Directive readiness now

    One scan. Every clause on this page evaluated against your live domain. Auditor-ready PDF in your inbox.

    https://

    170+ checks · 10 layers · Results in <60s · No signup

    ISO 27001Aligned
    SOC 2 Type IIControls
    GDPRCompliant
    AES-256Encryption