Skip to content

A compliance percentage is not evidence.

NIS2 Article 21(2) lists ten risk-management measures. Container and cloud posture scanning can produce technical evidence for five of them, partial evidence for three more, and nothing at all for two. Here is exactly which is which.

Book a baseline assessment
  • Technical evidence
  • Not certification
  • Partial by design
  • Gaps stated

QubeAuditor

QubeAuditor produces technical evidence for the NIS2 Article 21(2) risk-management measures that container and cloud posture scanning can observe. It evidences five measures outright, three partially, and reports two as unassessed because no scanner signal exists for them. It does not certify NIS2 compliance, and no scanner can.

The claim

What we will and will not say about NIS2.

The NIS2 Directive (EU) 2022/2555 has applied since 18 October 2024, and Article 34 sets maximum fines of at least EUR 10 million or 2% of worldwide annual turnover for essential entities. That urgency has produced a lot of marketing that a supervisory authority would not accept.

What QubeAuditor produces

  • Traceable technical evidence for specific Article 21(2) measures, tied to the control that evidences them
  • The scanner and version that produced each result, and the resource it applies to
  • An explicit unassessed state for anything not covered
  • A history of what failed, what was accepted with a rationale and expiry, and what was verified fixed
  • An evidence pack with a manifest, hashes, and a list of what is missing

What it will never claim

  • That you are NIS2 compliant, or that any scan can certify compliance
  • That an organisational measure has been satisfied because a technical control passed
  • That a permission-denied check is a pass
  • That the coverage is complete, when it is documented as partial

Coverage

The Article 21(2) coverage matrix.

Each measure below is mapped to the CIS Kubernetes, CIS Azure and AWS container control identifiers that technically evidence it. The mapping is reviewable data with a stated rationale and a citable source for each entry, rather than an opaque score.

NIS2 Article 21(2) risk-management measures and the scopes at which QubeAuditor produces technical evidence for them.
MeasureKubernetesAzureAWS
21.2(a)nis2Measures.21.2(a)unassessedno control mappedno control mappedno control mapped
21.2(b)nis2Measures.21.2(b)evidenced by CAZ-5.1 · CIS-AZ-5.1.1 · CIS-AWS-3.1 · CAW-5.1 · CAW-5.2no control mappedevidencedevidenced
21.2(c)nis2Measures.21.2(c)unassessedno control mappedno control mappedno control mapped
21.2(d)nis2Measures.21.2(d)evidenced by CAZ-7.1 · CAZ-7.2 · CAW-7.1 · CAW-7.2 · CAW-7.3no control mappedevidencedevidenced
21.2(e)nis2Measures.21.2(e)evidenced by CIS-5.3.1 · CIS-5.3.2 · CAZ-3.1 · CAZ-3.2 · CAZ-3.3 · CAZ-3.4 · CAW-3.1 · CAW-3.2 · CAW-3.3evidencedevidencedevidenced
21.2(f)nis2Measures.21.2(f)evidenced by CIS-5.4.1 · CIS-5.4.2 · CAZ-6.1 · CAZ-6.2 · CAW-6.1 · CAW-6.2evidencedevidencedevidenced
21.2(g)nis2Measures.21.2(g)partialevidenced by CIS-5.2.1 · CIS-5.2.5 · CIS-5.2.6 · CIS-5.2.7 · CIS-5.2.8 · CIS-5.7.2 · CIS-5.7.3 · CAZ-8.3 · CAW-8.1 · CAW-8.2 · CAW-8.3 · CAW-8.4 · CAW-8.5evidencedevidencedevidenced
21.2(h)nis2Measures.21.2(h)evidenced by CAZ-4.1 · CAZ-4.2 · CIS-AZ-3.1 · CIS-AWS-2.2.1 · CAW-4.1no control mappedevidencedevidenced
21.2(i)nis2Measures.21.2(i)partialevidenced by CIS-5.1.1 · CIS-5.6.1 · CIS-5.7.1 · CAZ-1.1 · CAZ-1.2 · CAZ-1.3 · CIS-AZ-1.1.1 · CIS-AWS-1.1 · CAW-1.1 · CAW-1.2evidencedevidencedevidenced
21.2(j)nis2Measures.21.2(j)partialevidenced by CIS-AZ-1.1.2 · CIS-AWS-1.5no control mappedevidencedevidenced
A control at this scope evidences the measure
No control mapped at this scope
partial
Technical evidence exists, but part of the measure is organisational and stays outside scanner reach
unassessed
No control at any scope, always reported as not assessed

An empty cell is not an oversight. Measures with no controls mapped to them always score unassessed, by construction, so the mapping cannot be quietly extended to make a report look better.

See the full control mapping for the identifiers behind every measure, grouped by the catalogue they come from.

Out of scope

The two measures no scanner can reach.

These stay unassessed in every QubeAuditor report. If a tool tells you otherwise, ask it which technical signal it used.

21(2)(a) Risk analysis and information system security policies

An organisational measure. It requires a documented risk assessment process and approved policies. There is no scanner signal for whether a risk assessment was performed, by whom, or whether management approved the result.

21(2)(c) Business continuity, backup management and disaster recovery

Backup and disaster-recovery procedures are not directly observable from container or cloud security posture. The existence of a snapshot is not evidence that a restore was tested, and a scanner cannot tell you whether the recovery objective was met.

And three that are only partly reachable

21(2)(g) Basic cyber hygiene and cybersecurity training

Workload hardening is evidenced: privileged containers, root users, capabilities, seccomp and security context, plus the ECS equivalents. Training is not, because no posture scan can tell you whether anyone attended it.

21(2)(i) Human resources security, access control and asset management

Access control and asset management are evidenced through RBAC, managed identity, least-privilege and namespace boundaries. Human resources security is an organisational control and stays outside the technical scope.

21(2)(j) Multi-factor authentication and secure communications

Cloud-identity MFA is evidenced at subscription and account scope. Per-application and per-workload MFA, meaning SSO app assignments, VPN and bastion step-up, is not observable through posture scanning, so a pass here evidences cloud-identity MFA only.

Other frameworks

NIS2 is not the only mapping.

The same normalised findings feed every framework view. All coverage is partial and labelled as such.

CIS Kubernetes
Workload, RBAC and network controls, executed through Trivy against the CIS Kubernetes Benchmark
NSA/CISA
Kubernetes hardening guidance
PCI DSS
Segmentation, hardening and vulnerability management mappings
CIS Azure
Curated container-scope controls plus subscription-scope posture through Prowler
AWS container security
22 catalogued Container Assurance Workload controls, aligned to CIS and FSBP, plus account posture through Prowler
SOC 2
Through Kubescape framework scans, where enabled
MITRE ATT&CK
Through Kubescape framework scans, where enabled

Questions

NIS2 questions

Can a scanner prove NIS2 compliance?

No. NIS2 Article 21(2) mixes technical and organisational measures, and compliance is assessed against an entity's whole risk-management approach, not against a tool's output. A scanner can produce technical evidence for some measures. QubeAuditor does that, states which measures it covers, and reports the rest as unassessed.

Which NIS2 measures can container scanning actually evidence?

Incident handling (b) through log forwarding and audit-trail controls; supply chain security (d) through registry provenance, immutable tags and scan-on-push; network and system security (e) through segmentation and public-exposure controls; effectiveness of risk-management measures (f) through secret and cryptographic-material handling; cyber hygiene (g) through workload hardening; cryptography (h) through TLS and encryption enforcement; access control (i) through RBAC, managed identity and least privilege; and MFA (j) at cloud-identity scope.

What does 'not assessed' mean in a QubeAuditor report?

It means no control was evaluated for that measure, either because no scanner signal exists for it or because a check could not run, for example when a permission was denied. It is never converted into a pass. Auditors treat a silently omitted control as a credibility problem, so the platform makes the gap explicit instead.

Is the NIS2 mapping auditable?

Yes. Each measure maps to named control identifiers, and each mapping carries a written rationale explaining why those controls evidence that measure, plus a citable source such as ENISA guidance, the relevant ISO/IEC 27001 control, or the CIS benchmark section. An auditor can check the mapping itself, not just the result. The whole crosswalk is published on this site.

Does this replace our NIS2 consultant?

No, and it works better alongside one. The technical evidence workstream is a component of a broader governance engagement covering risk management, continuity, training and incident processes. Consultants use QubeAuditor to produce the evidence for the technical measures rather than assembling it by hand from scanner exports.

Read next

Or start with something you already have

Bring one recent security report from the vendor operating your estate. We will map how many of its findings have an accountable owner, a verification state, and evidence you could hand to an auditor.

Book a baseline assessment

Contact

Book a baseline assessment

Tell us what you run and who operates it. We will come back with a scope, a timeline and a fixed price for one estate.