Skip to content

Every measure, every control identifier, including the empty ones.

Most vendors publish a compliance percentage and keep the mapping behind it private. This is the mapping. If you disagree with an entry, you can see exactly what you are disagreeing with.

Book a baseline assessment
  • 10 measures
  • 5 evidenced
  • 3 partial
  • 2 unassessed
  • Kubernetes · Azure · AWS
  • Free to cite

QubeAuditor

This is a published crosswalk from the ten NIS2 Article 21(2) risk-management measures to the specific technical control identifiers that evidence each one, across Kubernetes, Azure and AWS. Five measures are evidenced by technical controls, three are partially evidenced because part of the measure is organisational, and two have no technical signal at any scope. It is a mapping, not a compliance assessment.

At a glance

The whole mapping in five numbers.

These figures are generated from the same crosswalk the platform uses to produce reports, so this page cannot describe coverage the product does not have.

evidenced
21.2(b), 21.2(d), 21.2(e), 21.2(f), 21.2(h)
partially evidenced
21.2(g), 21.2(i), 21.2(j)
no technical signal
21.2(a), 21.2(c)
distinct control identifiers
55
Article 21(2) measures
10

Method

How an entry gets into this table.

A mapping is a claim about what evidence means. These are the rules that claim follows, so you can judge whether the mapping is reasonable rather than taking the result on trust.

A control must be observable

An entry exists only where a scanner can read a concrete property of a real resource. Intent, policy documents and process maturity are not observable from configuration, so they never produce an entry.

Evidence is not satisfaction

A mapped control evidences part of a measure. It does not establish that the measure is met, because Article 21 is assessed against an entity's whole risk-management approach. The mapping supplies inputs to that assessment.

Partial is labelled, not rounded up

Where a measure has both a technical and an organisational component, it is marked partial and the report says which part the evidence covers. Training, human resources security and per-application MFA are the recurring examples.

Empty stays empty

Two measures have no control at any scope. They are reported as unassessed in every report and no future mapping will quietly fill them from an adjacent signal, because that is how a crosswalk stops being checkable.

Matrix

Coverage by scope.

Which scopes produce evidence for which measure. A filled cell means at least one control at that scope evidences the measure, not that a given estate passes it.

NIS2 Article 21(2) risk-management measures and the scopes at which QubeAuditor produces technical evidence for them.
MeasureKubernetesAzureAWS
21.2(a)nis2Measures.21.2(a)unassessedno control mappedno control mappedno control mapped
21.2(b)nis2Measures.21.2(b)no control mappedevidencedevidenced
21.2(c)nis2Measures.21.2(c)unassessedno control mappedno control mappedno control mapped
21.2(d)nis2Measures.21.2(d)no control mappedevidencedevidenced
21.2(e)nis2Measures.21.2(e)evidencedevidencedevidenced
21.2(f)nis2Measures.21.2(f)evidencedevidencedevidenced
21.2(g)nis2Measures.21.2(g)partialevidencedevidencedevidenced
21.2(h)nis2Measures.21.2(h)no control mappedevidencedevidenced
21.2(i)nis2Measures.21.2(i)partialevidencedevidencedevidenced
21.2(j)nis2Measures.21.2(j)partialno control mappedevidencedevidenced
A control at this scope evidences the measure
No control mapped at this scope
partial
Technical evidence exists, but part of the measure is organisational and stays outside scanner reach
unassessed
No control at any scope, always reported as not assessed

The mapping

Measure by measure.

Each measure with the control identifiers behind it, grouped by the catalogue they come from. Identifiers are stable and appear verbatim in the technical assessment and the evidence pack.

  1. 21.2(a)nis2Measures.21.2(a)

    unassessed

    No control at any scope evidences this measure. It is reported as unassessed in every assessment, and no scanner result will change that.

  2. 21.2(b)nis2Measures.21.2(b)

    evidenced
    Azure containers
    CAZ-5.1
    Azure subscription
    CIS-AZ-5.1.1
    AWS containers
    CAW-5.1 · CAW-5.2
    AWS account
    CIS-AWS-3.1
  3. 21.2(c)nis2Measures.21.2(c)

    unassessed

    No control at any scope evidences this measure. It is reported as unassessed in every assessment, and no scanner result will change that.

  4. 21.2(d)nis2Measures.21.2(d)

    evidenced
    Azure containers
    CAZ-7.1 · CAZ-7.2
    AWS containers
    CAW-7.1 · CAW-7.2 · CAW-7.3
  5. 21.2(e)nis2Measures.21.2(e)

    evidenced
    CIS Kubernetes
    CIS-5.3.1 · CIS-5.3.2
    Azure containers
    CAZ-3.1 · CAZ-3.2 · CAZ-3.3 · CAZ-3.4
    AWS containers
    CAW-3.1 · CAW-3.2 · CAW-3.3
  6. 21.2(f)nis2Measures.21.2(f)

    evidenced
    CIS Kubernetes
    CIS-5.4.1 · CIS-5.4.2
    Azure containers
    CAZ-6.1 · CAZ-6.2
    AWS containers
    CAW-6.1 · CAW-6.2
  7. 21.2(g)nis2Measures.21.2(g)

    partial
    CIS Kubernetes
    CIS-5.2.1 · CIS-5.2.5 · CIS-5.2.6 · CIS-5.2.7 · CIS-5.2.8 · CIS-5.7.2 · CIS-5.7.3
    Azure containers
    CAZ-8.3
    AWS containers
    CAW-8.1 · CAW-8.2 · CAW-8.3 · CAW-8.4 · CAW-8.5
  8. 21.2(h)nis2Measures.21.2(h)

    evidenced
    Azure containers
    CAZ-4.1 · CAZ-4.2
    Azure subscription
    CIS-AZ-3.1
    AWS containers
    CAW-4.1
    AWS account
    CIS-AWS-2.2.1
  9. 21.2(i)nis2Measures.21.2(i)

    partial
    CIS Kubernetes
    CIS-5.1.1 · CIS-5.6.1 · CIS-5.7.1
    Azure containers
    CAZ-1.1 · CAZ-1.2 · CAZ-1.3
    Azure subscription
    CIS-AZ-1.1.1
    AWS containers
    CAW-1.1 · CAW-1.2
    AWS account
    CIS-AWS-1.1
  10. 21.2(j)nis2Measures.21.2(j)

    partial
    Azure subscription
    CIS-AZ-1.1.2
    AWS account
    CIS-AWS-1.5

Identifiers

How to read a control identifier.

The prefix says which catalogue a control comes from, which is what lets you trace an entry back to its published source.

CIS-5.x
CIS Kubernetes Benchmark, section 5 (policies), executed through Trivy against the live cluster
CAZ-x.x
Container Assurance Azure: the 17 curated container-scope controls for Container Apps, Container App Environments, Container Instances and Dynamic Session Pools
CAW-x.x
Container Assurance Workload: the 22 AWS ECS and ECR controls, aligned to CIS and the AWS Foundational Security Best Practices
CIS-AZ-x.x.x
CIS Microsoft Azure Foundations Benchmark, assessed at subscription scope through Prowler
CIS-AWS-x.x
CIS Amazon Web Services Foundations Benchmark, assessed at account scope through Prowler

Reuse

Cite it, quote it, argue with it.

This mapping is published so it can be used in your own documentation, an auditor's working papers, or a rebuttal. Attribution is appreciated and no permission is needed.

Konzern AI DOO. NIS2 Article 21(2) technical control crosswalk. QubeAuditor. https://qubeauditor.com/nis2-article-21-controls

Questions

Questions about the mapping

Can I use this crosswalk in my own documentation?

Yes. It is published for that purpose and no permission is needed. Attribution to Konzern AI DOO with a link to this page is appreciated. The mapping is maintained alongside the platform's own crosswalk configuration, so it reflects what the product actually assesses rather than a marketing summary of it.

Why do two measures have no controls at all?

Risk analysis and information system security policies (a) requires a documented process and management approval, neither of which is observable from infrastructure configuration. Business continuity, backup management and disaster recovery (c) is not observable either, because the existence of a snapshot is not evidence that a restore was tested. Both are reported as unassessed rather than inferred from adjacent technical signals.

What does a filled cell in the matrix mean?

It means at least one control at that scope produces evidence relevant to that measure. It does not mean a particular estate passes the measure, and it does not mean the measure is fully covered. The result for a specific environment comes from running the controls against it, and any control that cannot execute is reported as unassessed.

How does a mapping like this get reviewed?

Each entry carries a written rationale explaining why the named controls evidence that measure, and a citable source such as ENISA guidance, the relevant ISO/IEC 27001 control, or the CIS benchmark section. That means an auditor can review the reasoning itself rather than only the output, which is the difference between a crosswalk and a score.

Read next

Or start with something you already have

Bring one recent security report from the vendor operating your estate. We will map how many of its findings have an accountable owner, a verification state, and evidence you could hand to an auditor.

Book a baseline assessment

Contact

Book a baseline assessment

Tell us what you run and who operates it. We will come back with a scope, a timeline and a fixed price for one estate.