Position
- Technical evidence
- Not certification
- Partial by design
- Gaps stated
A compliance percentage is not evidence.
NIS2 Article 21(2) lists ten risk-management measures. Container and cloud posture scanning can produce technical evidence for five of them, partial evidence for three more, and nothing at all for two. Here is exactly which is which.
Book a baseline assessment- Technical evidence
- Not certification
- Partial by design
- Gaps stated
QubeAuditor
QubeAuditor produces technical evidence for the NIS2 Article 21(2) risk-management measures that container and cloud posture scanning can observe. It evidences five measures outright, three partially, and reports two as unassessed because no scanner signal exists for them. It does not certify NIS2 compliance, and no scanner can.
The claim
What we will and will not say about NIS2.
The NIS2 Directive (EU) 2022/2555 has applied since 18 October 2024, and Article 34 sets maximum fines of at least EUR 10 million or 2% of worldwide annual turnover for essential entities. That urgency has produced a lot of marketing that a supervisory authority would not accept.
What QubeAuditor produces
- Traceable technical evidence for specific Article 21(2) measures, tied to the control that evidences them
- The scanner and version that produced each result, and the resource it applies to
- An explicit unassessed state for anything not covered
- A history of what failed, what was accepted with a rationale and expiry, and what was verified fixed
- An evidence pack with a manifest, hashes, and a list of what is missing
What it will never claim
- That you are NIS2 compliant, or that any scan can certify compliance
- That an organisational measure has been satisfied because a technical control passed
- That a permission-denied check is a pass
- That the coverage is complete, when it is documented as partial
Coverage
The Article 21(2) coverage matrix.
Each measure below is mapped to the CIS Kubernetes, CIS Azure and AWS container control identifiers that technically evidence it. The mapping is reviewable data with a stated rationale and a citable source for each entry, rather than an opaque score.
| Measure | Kubernetes | Azure | AWS |
|---|---|---|---|
| 21.2(a)nis2Measures.21.2(a)unassessed | no control mapped | no control mapped | no control mapped |
| 21.2(b)nis2Measures.21.2(b)evidenced by CAZ-5.1 · CIS-AZ-5.1.1 · CIS-AWS-3.1 · CAW-5.1 · CAW-5.2 | no control mapped | evidenced | evidenced |
| 21.2(c)nis2Measures.21.2(c)unassessed | no control mapped | no control mapped | no control mapped |
| 21.2(d)nis2Measures.21.2(d)evidenced by CAZ-7.1 · CAZ-7.2 · CAW-7.1 · CAW-7.2 · CAW-7.3 | no control mapped | evidenced | evidenced |
| 21.2(e)nis2Measures.21.2(e)evidenced by CIS-5.3.1 · CIS-5.3.2 · CAZ-3.1 · CAZ-3.2 · CAZ-3.3 · CAZ-3.4 · CAW-3.1 · CAW-3.2 · CAW-3.3 | evidenced | evidenced | evidenced |
| 21.2(f)nis2Measures.21.2(f)evidenced by CIS-5.4.1 · CIS-5.4.2 · CAZ-6.1 · CAZ-6.2 · CAW-6.1 · CAW-6.2 | evidenced | evidenced | evidenced |
| 21.2(g)nis2Measures.21.2(g)partialevidenced by CIS-5.2.1 · CIS-5.2.5 · CIS-5.2.6 · CIS-5.2.7 · CIS-5.2.8 · CIS-5.7.2 · CIS-5.7.3 · CAZ-8.3 · CAW-8.1 · CAW-8.2 · CAW-8.3 · CAW-8.4 · CAW-8.5 | evidenced | evidenced | evidenced |
| 21.2(h)nis2Measures.21.2(h)evidenced by CAZ-4.1 · CAZ-4.2 · CIS-AZ-3.1 · CIS-AWS-2.2.1 · CAW-4.1 | no control mapped | evidenced | evidenced |
| 21.2(i)nis2Measures.21.2(i)partialevidenced by CIS-5.1.1 · CIS-5.6.1 · CIS-5.7.1 · CAZ-1.1 · CAZ-1.2 · CAZ-1.3 · CIS-AZ-1.1.1 · CIS-AWS-1.1 · CAW-1.1 · CAW-1.2 | evidenced | evidenced | evidenced |
| 21.2(j)nis2Measures.21.2(j)partialevidenced by CIS-AZ-1.1.2 · CIS-AWS-1.5 | no control mapped | evidenced | evidenced |
- A control at this scope evidences the measure
- No control mapped at this scope
- partial
- Technical evidence exists, but part of the measure is organisational and stays outside scanner reach
- unassessed
- No control at any scope, always reported as not assessed
An empty cell is not an oversight. Measures with no controls mapped to them always score unassessed, by construction, so the mapping cannot be quietly extended to make a report look better.
See the full control mapping for the identifiers behind every measure, grouped by the catalogue they come from.
Out of scope
The two measures no scanner can reach.
These stay unassessed in every QubeAuditor report. If a tool tells you otherwise, ask it which technical signal it used.
21(2)(a) Risk analysis and information system security policies
An organisational measure. It requires a documented risk assessment process and approved policies. There is no scanner signal for whether a risk assessment was performed, by whom, or whether management approved the result.
21(2)(c) Business continuity, backup management and disaster recovery
Backup and disaster-recovery procedures are not directly observable from container or cloud security posture. The existence of a snapshot is not evidence that a restore was tested, and a scanner cannot tell you whether the recovery objective was met.
And three that are only partly reachable
21(2)(g) Basic cyber hygiene and cybersecurity training
Workload hardening is evidenced: privileged containers, root users, capabilities, seccomp and security context, plus the ECS equivalents. Training is not, because no posture scan can tell you whether anyone attended it.
21(2)(i) Human resources security, access control and asset management
Access control and asset management are evidenced through RBAC, managed identity, least-privilege and namespace boundaries. Human resources security is an organisational control and stays outside the technical scope.
21(2)(j) Multi-factor authentication and secure communications
Cloud-identity MFA is evidenced at subscription and account scope. Per-application and per-workload MFA, meaning SSO app assignments, VPN and bastion step-up, is not observable through posture scanning, so a pass here evidences cloud-identity MFA only.
Other frameworks
NIS2 is not the only mapping.
The same normalised findings feed every framework view. All coverage is partial and labelled as such.
- CIS Kubernetes
- Workload, RBAC and network controls, executed through Trivy against the CIS Kubernetes Benchmark
- NSA/CISA
- Kubernetes hardening guidance
- PCI DSS
- Segmentation, hardening and vulnerability management mappings
- CIS Azure
- Curated container-scope controls plus subscription-scope posture through Prowler
- AWS container security
- 22 catalogued Container Assurance Workload controls, aligned to CIS and FSBP, plus account posture through Prowler
- SOC 2
- Through Kubescape framework scans, where enabled
- MITRE ATT&CK
- Through Kubescape framework scans, where enabled
Questions
NIS2 questions
Can a scanner prove NIS2 compliance?
Which NIS2 measures can container scanning actually evidence?
What does 'not assessed' mean in a QubeAuditor report?
Is the NIS2 mapping auditable?
Does this replace our NIS2 consultant?
Read next
- The full Article 21(2) control mapping
Measure by measure, every control identifier that evidences it, grouped by catalogue. Published so it can be checked.
- How the evidence is produced
Scan orchestration, the deterministic finding key, the append-only history, and how an artifact gets its hash.
- Why a CNAPP dashboard is not audit evidence
What a posture score gives you, what an auditor asks for, and why those are different artifacts.
- Delivering NIS2 evidence to a client base
Multi-tenant scanning and branded reporting for consultancies running this across several clients.
Or start with something you already have
Bring one recent security report from the vendor operating your estate. We will map how many of its findings have an accountable owner, a verification state, and evidence you could hand to an auditor.
Book a baseline assessmentContact
Book a baseline assessment
Tell us what you run and who operates it. We will come back with a scope, a timeline and a fixed price for one estate.