Position
- Technical evidence
- Not certification
- Partial by design
- Gaps stated
A compliance percentage is not evidence.
NIS2 Article 21(2) lists ten risk-management measures. Container and cloud posture scanning can produce technical evidence for six of them, partial evidence for three more, and nothing at all for two. Here is exactly which is which.
Book a baseline assessment- Technical evidence
- Not certification
- Partial by design
- Gaps stated
The claim
What we will and will not say about NIS2.
The NIS2 Directive (EU) 2022/2555 has applied since 18 October 2024, and Article 34 sets maximum fines of at least EUR 10 million or 2% of worldwide annual turnover for essential entities. That urgency has produced a lot of marketing that a supervisory authority would not accept.
What QubeAuditor produces
- Traceable technical evidence for specific Article 21(2) measures, tied to the control that evidences them
- The scanner and version that produced each result, and the resource it applies to
- An explicit unassessed state for anything not covered
- A history of what failed, what was accepted with a rationale and expiry, and what was verified fixed
- An evidence pack with a manifest, hashes, and a list of what is missing
What it will never claim
- That you are NIS2 compliant, or that any scan can certify compliance
- That an organisational measure has been satisfied because a technical control passed
- That a permission-denied check is a pass
- That the coverage is complete, when it is documented as partial
Coverage
The Article 21(2) coverage matrix.
Each measure below is mapped to the CIS Kubernetes, CIS Azure and AWS container control identifiers that technically evidence it. The mapping is reviewable data with a stated rationale and a citable source for each entry, not an opaque score.
| Measure | Kubernetes | Azure | AWS |
|---|---|---|---|
| 21.2(a)Risk analysis and information system security policiesunassessed | no control mapped | no control mapped | no control mapped |
| 21.2(b)Incident handlingevidenced by CAZ-5.1 · CIS-AZ-5.1.1 · CIS-AWS-3.1 · CAW-5.1 · CAW-5.2 | no control mapped | evidenced | evidenced |
| 21.2(c)Business continuity, backup management and disaster recoveryunassessed | no control mapped | no control mapped | no control mapped |
| 21.2(d)Supply chain securityevidenced by CAZ-7.1 · CAZ-7.2 · CAW-7.1 · CAW-7.2 · CAW-7.3 | no control mapped | evidenced | evidenced |
| 21.2(e)Security in acquisition, development and maintenanceevidenced by CIS-5.3.1 · CIS-5.3.2 · CAZ-3.1 · CAZ-3.2 · CAZ-3.3 · CAZ-3.4 · CAW-3.1 · CAW-3.2 · CAW-3.3 | evidenced | evidenced | evidenced |
| 21.2(f)Effectiveness of cybersecurity risk-management measuresevidenced by CIS-5.4.1 · CIS-5.4.2 · CAZ-6.1 · CAZ-6.2 · CAW-6.1 · CAW-6.2 | evidenced | evidenced | evidenced |
| 21.2(g)Basic cyber hygiene and cybersecurity trainingpartialevidenced by CIS-5.2.1 · CIS-5.2.5 · CIS-5.2.6 · CIS-5.2.7 · CIS-5.2.8 · CIS-5.7.2 · CIS-5.7.3 · CAZ-8.3 · CAW-8.1 · CAW-8.2 · CAW-8.3 · CAW-8.4 · CAW-8.5 | evidenced | evidenced | evidenced |
| 21.2(h)Cryptography and encryptionevidenced by CAZ-4.1 · CAZ-4.2 · CIS-AZ-3.1 · CIS-AWS-2.2.1 · CAW-4.1 | no control mapped | evidenced | evidenced |
| 21.2(i)HR security, access control policies and asset managementpartialevidenced by CIS-5.1.1 · CIS-5.6.1 · CIS-5.7.1 · CAZ-1.1 · CAZ-1.2 · CAZ-1.3 · CIS-AZ-1.1.1 · CIS-AWS-1.1 · CAW-1.1 · CAW-1.2 | evidenced | evidenced | evidenced |
| 21.2(j)Multi-factor authentication and secure communicationspartialevidenced by CIS-AZ-1.1.2 · CIS-AWS-1.5 | no control mapped | evidenced | evidenced |
- A control at this scope evidences the measure
- No control mapped at this scope
- partial
- Technical evidence exists, but part of the measure is organisational and stays outside scanner reach
- unassessed
- No control at any scope — always reported as not assessed
An empty cell is not an oversight. Measures with no controls mapped to them always score unassessed, by construction — the mapping cannot be quietly extended to make a report look better.
Out of scope
The two measures no scanner can reach.
These stay unassessed in every QubeAuditor report. If a tool tells you otherwise, ask it which technical signal it used.
21(2)(a) — Risk analysis and information system security policies
An organisational measure. It requires a documented risk assessment process and approved policies. There is no scanner signal for whether a risk assessment was performed, by whom, or whether management approved the result.
21(2)(c) — Business continuity, backup management and disaster recovery
Backup and disaster-recovery procedures are not directly observable from container or cloud security posture. The existence of a snapshot is not evidence that a restore was tested, and a scanner cannot tell you whether the recovery objective was met.
And three that are only partly reachable
21(2)(g) — Basic cyber hygiene and cybersecurity training
Workload hardening is evidenced: privileged containers, root users, capabilities, seccomp and security context, plus the ECS equivalents. Training is not — no posture scan can tell you whether anyone attended it.
21(2)(i) — Human resources security, access control and asset management
Access control and asset management are evidenced through RBAC, managed identity, least-privilege and namespace boundaries. Human resources security is an organisational control and stays outside the technical scope.
21(2)(j) — Multi-factor authentication and secure communications
Cloud-identity MFA is evidenced at subscription and account scope. Per-application and per-workload MFA — SSO app assignments, VPN, bastion step-up — is not observable through posture scanning, so a pass here evidences cloud-identity MFA only.
Other frameworks
NIS2 is not the only mapping.
The same normalised findings feed every framework view. All coverage is partial and labelled as such.
- CIS Kubernetes
- Workload, RBAC and network controls, executed through Trivy against the CIS Kubernetes Benchmark
- NSA/CISA
- Kubernetes hardening guidance
- PCI DSS
- Segmentation, hardening and vulnerability management mappings
- CIS Azure
- Curated container-scope controls plus subscription-scope posture through Prowler
- AWS container security
- 22 catalogued Container Assurance Workload controls, aligned to CIS and FSBP, plus account posture through Prowler
- SOC 2
- Through Kubescape framework scans, where enabled
- MITRE ATT&CK
- Through Kubescape framework scans, where enabled
Questions
NIS2 questions
Or start with something you already have
Bring one recent security report from the vendor operating your estate. We will map how many of its findings have an accountable owner, a verification state, and evidence you could hand to an auditor.
Book a baseline assessmentContact
Book a baseline assessment
Tell us what you run and who operates it. We will come back with a scope, a timeline and a fixed price for one estate.