FrameworkNIS 2 DirectiveEU 2022/2555Article 21(2)(a–i), Art. 23

Compliance / NIS 2 Directive

§ NIS 2 Directive

A technical-research reference for NIS 2.

The NIS 2 Directive requires essential and important entities to take appropriate technical, operational and organisational measures. This page illustrates how controlled, replayable research artifacts may support an organization's evidence work.

FrameworkNIS 2 Directive
JurisdictionEU 2022/2555
ReferenceArticle 21(2)(a–i), Art. 23
ScopeEssential & important entities
SecHive evidencetechnical
Auditor opinionout of scope
Important boundary. This page is an illustrative reference mapping. Framework references describe evidence mapping and control alignment. SecHive is not presently certified or independently audited under these frameworks unless explicitly stated. This page is not legal advice, evidence that SecHive implements these controls, or a claim that any organization satisfies NIS 2 Directive.
§ Articles → Evidence

How research artifacts may relate to NIS 2 Directive.

The mapping is intentionally narrow and illustrative. The final relevance and sufficiency of evidence must be determined by the organization and its qualified assessor.

Article / controlWhat it requiresSecHive artifact
Art. 21(2)(a) — Risk analysisPolicies on risk analysis and information system security.Per-engagement risk register, hypothesis graph, and validated finding set.
Art. 21(2)(b) — Incident handlingDetect, respond and recover from incidents.Reproducible exploit chain — feeds detection engineering and tabletop input.
Art. 21(2)(d) — Supply chainCybersecurity in supplier and service-provider relationships.Source-audit run mode against supplier artifacts; PR audit at integration point.
Art. 21(2)(e) — Effectiveness testingPolicies and procedures to assess effectiveness of measures.Per-control proof packs with replay scripts and reviewer disposition.
Art. 21(2)(f) — Cyber hygieneBasic cyber-hygiene practices and training.Public-safe write-ups suitable for internal training without leaking client material.
Art. 21(2)(g) — CryptographyUse of cryptography and where appropriate, encryption.Cryptographic-control validation findings: replay, downgrade, key-handling abuse.
Art. 21(2)(i) — Network and system securityVulnerability handling and disclosure.SecHive coordinates redaction-safe disclosure and tracks remediation status.
Art. 23 — ReportingSignificant incident reporting to CSIRT / authority.Incident-shaped report bundle with timestamps, scope, and chain of custody.
§ Review view

How artifacts can be organized.

A practical format for technical review; acceptance by an auditor or assessor is not implied.

For the CISO

  • Mappable evidence per Article 21(2) sub-clause.
  • Time-bounded findings with severity and impact.
  • Retest records that close the loop with the engineering team.

For the legal / compliance team

  • Redaction manifests for cross-border or supplier engagements.
  • Operator identity recorded on every disposition.
  • Artifact hashes on report bundles.

For engineering

  • Deterministic replay.sh per finding.
  • Source references when source mode is enabled.
  • Negative evidence for refuted candidates.

For the auditor

  • Run-mode-labeled evidence rows.
  • sha256 binding to underlying artifacts.
  • Methodology spine consistent across engagements.
§ Sample evidence

A page from the matrix.

SecHive renders an evidence matrix per engagement. Below is one row, redacted.

EVIDENCE ROW — sample
# evidence-row.yaml — redacted
control:    Art. 21(2)(e)  # effectiveness testing
finding_id: VTX-RPL-0042
mode:       black-box
target:     redacted
target_ref: image@sha256:9c4e…  # pinned
artifact:
  path:    artifacts/replay.sh
  sha256:  7c3a…
  review:  human-approved
disposition:
  reviewer:  redacted-operator
  state:    confirmed
retest:
  status:    fixed @ 2026-04-18
  evidence:  artifacts/retest-receipt.json

What a reviewer sees

  • The control id and the finding id, bound together.
  • A run-mode label (black-box, source-aware, etc.).
  • A sha256 of the underlying artifact.
  • A reviewer disposition with operator identity.
  • A retest record if the finding has been remediated.
See the full output matrix

Discuss a NIS 2 Directive reference mapping.

Bring an authorized scope and the evidence questions you are working through.