Reference
- 10 measures
- 5 evidenced
- 3 partial
- 2 unassessed
- Kubernetes · Azure · AWS
- Free to cite
Every measure, every control identifier, including the empty ones.
Most vendors publish a compliance percentage and keep the mapping behind it private. This is the mapping. If you disagree with an entry, you can see exactly what you are disagreeing with.
Book a baseline assessment- 10 measures
- 5 evidenced
- 3 partial
- 2 unassessed
- Kubernetes · Azure · AWS
- Free to cite
QubeAuditor
This is a published crosswalk from the ten NIS2 Article 21(2) risk-management measures to the specific technical control identifiers that evidence each one, across Kubernetes, Azure and AWS. Five measures are evidenced by technical controls, three are partially evidenced because part of the measure is organisational, and two have no technical signal at any scope. It is a mapping, not a compliance assessment.
At a glance
The whole mapping in five numbers.
These figures are generated from the same crosswalk the platform uses to produce reports, so this page cannot describe coverage the product does not have.
- evidenced
- 21.2(b), 21.2(d), 21.2(e), 21.2(f), 21.2(h)
- partially evidenced
- 21.2(g), 21.2(i), 21.2(j)
- no technical signal
- 21.2(a), 21.2(c)
- distinct control identifiers
- 55
- Article 21(2) measures
- 10
Method
How an entry gets into this table.
A mapping is a claim about what evidence means. These are the rules that claim follows, so you can judge whether the mapping is reasonable rather than taking the result on trust.
A control must be observable
An entry exists only where a scanner can read a concrete property of a real resource. Intent, policy documents and process maturity are not observable from configuration, so they never produce an entry.
Evidence is not satisfaction
A mapped control evidences part of a measure. It does not establish that the measure is met, because Article 21 is assessed against an entity's whole risk-management approach. The mapping supplies inputs to that assessment.
Partial is labelled, not rounded up
Where a measure has both a technical and an organisational component, it is marked partial and the report says which part the evidence covers. Training, human resources security and per-application MFA are the recurring examples.
Empty stays empty
Two measures have no control at any scope. They are reported as unassessed in every report and no future mapping will quietly fill them from an adjacent signal, because that is how a crosswalk stops being checkable.
Matrix
Coverage by scope.
Which scopes produce evidence for which measure. A filled cell means at least one control at that scope evidences the measure, not that a given estate passes it.
| Measure | Kubernetes | Azure | AWS |
|---|---|---|---|
| 21.2(a)nis2Measures.21.2(a)unassessed | no control mapped | no control mapped | no control mapped |
| 21.2(b)nis2Measures.21.2(b) | no control mapped | evidenced | evidenced |
| 21.2(c)nis2Measures.21.2(c)unassessed | no control mapped | no control mapped | no control mapped |
| 21.2(d)nis2Measures.21.2(d) | no control mapped | evidenced | evidenced |
| 21.2(e)nis2Measures.21.2(e) | evidenced | evidenced | evidenced |
| 21.2(f)nis2Measures.21.2(f) | evidenced | evidenced | evidenced |
| 21.2(g)nis2Measures.21.2(g)partial | evidenced | evidenced | evidenced |
| 21.2(h)nis2Measures.21.2(h) | no control mapped | evidenced | evidenced |
| 21.2(i)nis2Measures.21.2(i)partial | evidenced | evidenced | evidenced |
| 21.2(j)nis2Measures.21.2(j)partial | no control mapped | evidenced | evidenced |
- A control at this scope evidences the measure
- No control mapped at this scope
- partial
- Technical evidence exists, but part of the measure is organisational and stays outside scanner reach
- unassessed
- No control at any scope, always reported as not assessed
The mapping
Measure by measure.
Each measure with the control identifiers behind it, grouped by the catalogue they come from. Identifiers are stable and appear verbatim in the technical assessment and the evidence pack.
21.2(a)nis2Measures.21.2(a)
unassessedNo control at any scope evidences this measure. It is reported as unassessed in every assessment, and no scanner result will change that.
21.2(b)nis2Measures.21.2(b)
evidenced- Azure containers
- CAZ-5.1
- Azure subscription
- CIS-AZ-5.1.1
- AWS containers
- CAW-5.1 · CAW-5.2
- AWS account
- CIS-AWS-3.1
21.2(c)nis2Measures.21.2(c)
unassessedNo control at any scope evidences this measure. It is reported as unassessed in every assessment, and no scanner result will change that.
21.2(d)nis2Measures.21.2(d)
evidenced- Azure containers
- CAZ-7.1 · CAZ-7.2
- AWS containers
- CAW-7.1 · CAW-7.2 · CAW-7.3
21.2(e)nis2Measures.21.2(e)
evidenced- CIS Kubernetes
- CIS-5.3.1 · CIS-5.3.2
- Azure containers
- CAZ-3.1 · CAZ-3.2 · CAZ-3.3 · CAZ-3.4
- AWS containers
- CAW-3.1 · CAW-3.2 · CAW-3.3
21.2(f)nis2Measures.21.2(f)
evidenced- CIS Kubernetes
- CIS-5.4.1 · CIS-5.4.2
- Azure containers
- CAZ-6.1 · CAZ-6.2
- AWS containers
- CAW-6.1 · CAW-6.2
21.2(g)nis2Measures.21.2(g)
partial- CIS Kubernetes
- CIS-5.2.1 · CIS-5.2.5 · CIS-5.2.6 · CIS-5.2.7 · CIS-5.2.8 · CIS-5.7.2 · CIS-5.7.3
- Azure containers
- CAZ-8.3
- AWS containers
- CAW-8.1 · CAW-8.2 · CAW-8.3 · CAW-8.4 · CAW-8.5
21.2(h)nis2Measures.21.2(h)
evidenced- Azure containers
- CAZ-4.1 · CAZ-4.2
- Azure subscription
- CIS-AZ-3.1
- AWS containers
- CAW-4.1
- AWS account
- CIS-AWS-2.2.1
21.2(i)nis2Measures.21.2(i)
partial- CIS Kubernetes
- CIS-5.1.1 · CIS-5.6.1 · CIS-5.7.1
- Azure containers
- CAZ-1.1 · CAZ-1.2 · CAZ-1.3
- Azure subscription
- CIS-AZ-1.1.1
- AWS containers
- CAW-1.1 · CAW-1.2
- AWS account
- CIS-AWS-1.1
21.2(j)nis2Measures.21.2(j)
partial- Azure subscription
- CIS-AZ-1.1.2
- AWS account
- CIS-AWS-1.5
Identifiers
How to read a control identifier.
The prefix says which catalogue a control comes from, which is what lets you trace an entry back to its published source.
- CIS-5.x
- CIS Kubernetes Benchmark, section 5 (policies), executed through Trivy against the live cluster
- CAZ-x.x
- Container Assurance Azure: the 17 curated container-scope controls for Container Apps, Container App Environments, Container Instances and Dynamic Session Pools
- CAW-x.x
- Container Assurance Workload: the 22 AWS ECS and ECR controls, aligned to CIS and the AWS Foundational Security Best Practices
- CIS-AZ-x.x.x
- CIS Microsoft Azure Foundations Benchmark, assessed at subscription scope through Prowler
- CIS-AWS-x.x
- CIS Amazon Web Services Foundations Benchmark, assessed at account scope through Prowler
Reuse
Cite it, quote it, argue with it.
This mapping is published so it can be used in your own documentation, an auditor's working papers, or a rebuttal. Attribution is appreciated and no permission is needed.
Konzern AI DOO. NIS2 Article 21(2) technical control crosswalk. QubeAuditor. https://qubeauditor.com/nis2-article-21-controls
Questions
Questions about the mapping
Can I use this crosswalk in my own documentation?
Why do two measures have no controls at all?
What does a filled cell in the matrix mean?
How does a mapping like this get reviewed?
Read next
- What this mapping means in practice
The position behind the crosswalk: what QubeAuditor will claim about NIS2, and what it refuses to claim.
- The CAZ controls in full
All 17 Azure container-scope controls, with the condition each one detects.
- The CAW controls in full
All 22 AWS ECS and ECR controls, with the condition each one detects.
- How a control result becomes evidence
From scan output to a hashed artifact in an evidence pack, including how an unassessed result is recorded.
Or start with something you already have
Bring one recent security report from the vendor operating your estate. We will map how many of its findings have an accountable owner, a verification state, and evidence you could hand to an auditor.
Book a baseline assessmentContact
Book a baseline assessment
Tell us what you run and who operates it. We will come back with a scope, a timeline and a fixed price for one estate.