Compliance / NIS 2 Directive
The NIS 2 Directive requires essential and important entities to take appropriate technical, operational and organisational measures. SecHive produces the technical evidence — controlled, replayable, and labeled — that an auditor or competent authority can read without rebuilding context.
The mapping is intentionally narrow. We list only the articles where SecHive produces a directly defensible artifact, and we name the artifact.
| Article / control | What it requires | SecHive artifact |
|---|---|---|
| Art. 21(2)(a) — Risk analysis | Policies on risk analysis and information system security. | Per-engagement risk register, hypothesis graph, and validated finding set. |
| Art. 21(2)(b) — Incident handling | Detect, respond and recover from incidents. | Reproducible exploit chain — feeds detection engineering and tabletop input. |
| Art. 21(2)(d) — Supply chain | Cybersecurity in supplier and service-provider relationships. | Source-audit run mode against supplier artifacts; PR audit at integration point. |
| Art. 21(2)(e) — Effectiveness testing | Policies and procedures to assess effectiveness of measures. | Per-control proof packs with replay scripts and reviewer disposition. |
| Art. 21(2)(f) — Cyber hygiene | Basic cyber-hygiene practices and training. | Public-safe write-ups suitable for internal training without leaking client material. |
| Art. 21(2)(g) — Cryptography | Use of cryptography and where appropriate, encryption. | Cryptographic-control validation findings: replay, downgrade, key-handling abuse. |
| Art. 21(2)(i) — Network and system security | Vulnerability handling and disclosure. | SecHive coordinates redaction-safe disclosure and tracks remediation status. |
| Art. 23 — Reporting | Significant incident reporting to CSIRT / authority. | Incident-shaped report bundle with timestamps, scope, and chain of custody. |
What you can put in front of an auditor or a security review.
replay.sh per finding.SecHive renders an evidence matrix per engagement. Below is one row, redacted.
# evidence-row.yaml — redacted control: Art. 21(2)(e) # effectiveness testing finding_id: VTX-RPL-0042 mode: black-box target: redacted target_ref: image@sha256:9c4e… # pinned artifact: path: artifacts/replay.sh sha256: 7c3a… signed: cosign:sechive-key disposition: reviewer: redacted-operator state: confirmed retest: status: fixed @ 2026-04-18 evidence: artifacts/retest-receipt.json
Bring the scope and the auditor's evidence list. We will produce the technical artifacts.