Skip to content

A compliance percentage is not evidence.

NIS2 Article 21(2) lists ten risk-management measures. Container and cloud posture scanning can produce technical evidence for six of them, partial evidence for three more, and nothing at all for two. Here is exactly which is which.

Book a baseline assessment
  • Technical evidence
  • Not certification
  • Partial by design
  • Gaps stated

The claim

What we will and will not say about NIS2.

The NIS2 Directive (EU) 2022/2555 has applied since 18 October 2024, and Article 34 sets maximum fines of at least EUR 10 million or 2% of worldwide annual turnover for essential entities. That urgency has produced a lot of marketing that a supervisory authority would not accept.

What QubeAuditor produces

  • Traceable technical evidence for specific Article 21(2) measures, tied to the control that evidences them
  • The scanner and version that produced each result, and the resource it applies to
  • An explicit unassessed state for anything not covered
  • A history of what failed, what was accepted with a rationale and expiry, and what was verified fixed
  • An evidence pack with a manifest, hashes, and a list of what is missing

What it will never claim

  • That you are NIS2 compliant, or that any scan can certify compliance
  • That an organisational measure has been satisfied because a technical control passed
  • That a permission-denied check is a pass
  • That the coverage is complete, when it is documented as partial

Coverage

The Article 21(2) coverage matrix.

Each measure below is mapped to the CIS Kubernetes, CIS Azure and AWS container control identifiers that technically evidence it. The mapping is reviewable data with a stated rationale and a citable source for each entry, not an opaque score.

NIS2 Article 21(2) risk-management measures and the scopes at which QubeAuditor produces technical evidence for them.
MeasureKubernetesAzureAWS
21.2(a)Risk analysis and information system security policiesunassessedno control mappedno control mappedno control mapped
21.2(b)Incident handlingevidenced by CAZ-5.1 · CIS-AZ-5.1.1 · CIS-AWS-3.1 · CAW-5.1 · CAW-5.2no control mappedevidencedevidenced
21.2(c)Business continuity, backup management and disaster recoveryunassessedno control mappedno control mappedno control mapped
21.2(d)Supply chain securityevidenced by CAZ-7.1 · CAZ-7.2 · CAW-7.1 · CAW-7.2 · CAW-7.3no control mappedevidencedevidenced
21.2(e)Security in acquisition, development and maintenanceevidenced by CIS-5.3.1 · CIS-5.3.2 · CAZ-3.1 · CAZ-3.2 · CAZ-3.3 · CAZ-3.4 · CAW-3.1 · CAW-3.2 · CAW-3.3evidencedevidencedevidenced
21.2(f)Effectiveness of cybersecurity risk-management measuresevidenced by CIS-5.4.1 · CIS-5.4.2 · CAZ-6.1 · CAZ-6.2 · CAW-6.1 · CAW-6.2evidencedevidencedevidenced
21.2(g)Basic cyber hygiene and cybersecurity trainingpartialevidenced by CIS-5.2.1 · CIS-5.2.5 · CIS-5.2.6 · CIS-5.2.7 · CIS-5.2.8 · CIS-5.7.2 · CIS-5.7.3 · CAZ-8.3 · CAW-8.1 · CAW-8.2 · CAW-8.3 · CAW-8.4 · CAW-8.5evidencedevidencedevidenced
21.2(h)Cryptography and encryptionevidenced by CAZ-4.1 · CAZ-4.2 · CIS-AZ-3.1 · CIS-AWS-2.2.1 · CAW-4.1no control mappedevidencedevidenced
21.2(i)HR security, access control policies and asset managementpartialevidenced by CIS-5.1.1 · CIS-5.6.1 · CIS-5.7.1 · CAZ-1.1 · CAZ-1.2 · CAZ-1.3 · CIS-AZ-1.1.1 · CIS-AWS-1.1 · CAW-1.1 · CAW-1.2evidencedevidencedevidenced
21.2(j)Multi-factor authentication and secure communicationspartialevidenced by CIS-AZ-1.1.2 · CIS-AWS-1.5no control mappedevidencedevidenced
A control at this scope evidences the measure
No control mapped at this scope
partial
Technical evidence exists, but part of the measure is organisational and stays outside scanner reach
unassessed
No control at any scope — always reported as not assessed

An empty cell is not an oversight. Measures with no controls mapped to them always score unassessed, by construction — the mapping cannot be quietly extended to make a report look better.

Out of scope

The two measures no scanner can reach.

These stay unassessed in every QubeAuditor report. If a tool tells you otherwise, ask it which technical signal it used.

21(2)(a) — Risk analysis and information system security policies

An organisational measure. It requires a documented risk assessment process and approved policies. There is no scanner signal for whether a risk assessment was performed, by whom, or whether management approved the result.

21(2)(c) — Business continuity, backup management and disaster recovery

Backup and disaster-recovery procedures are not directly observable from container or cloud security posture. The existence of a snapshot is not evidence that a restore was tested, and a scanner cannot tell you whether the recovery objective was met.

And three that are only partly reachable

21(2)(g) — Basic cyber hygiene and cybersecurity training

Workload hardening is evidenced: privileged containers, root users, capabilities, seccomp and security context, plus the ECS equivalents. Training is not — no posture scan can tell you whether anyone attended it.

21(2)(i) — Human resources security, access control and asset management

Access control and asset management are evidenced through RBAC, managed identity, least-privilege and namespace boundaries. Human resources security is an organisational control and stays outside the technical scope.

21(2)(j) — Multi-factor authentication and secure communications

Cloud-identity MFA is evidenced at subscription and account scope. Per-application and per-workload MFA — SSO app assignments, VPN, bastion step-up — is not observable through posture scanning, so a pass here evidences cloud-identity MFA only.

Other frameworks

NIS2 is not the only mapping.

The same normalised findings feed every framework view. All coverage is partial and labelled as such.

CIS Kubernetes
Workload, RBAC and network controls, executed through Trivy against the CIS Kubernetes Benchmark
NSA/CISA
Kubernetes hardening guidance
PCI DSS
Segmentation, hardening and vulnerability management mappings
CIS Azure
Curated container-scope controls plus subscription-scope posture through Prowler
AWS container security
22 catalogued Container Assurance Workload controls, aligned to CIS and FSBP, plus account posture through Prowler
SOC 2
Through Kubescape framework scans, where enabled
MITRE ATT&CK
Through Kubescape framework scans, where enabled

Questions

NIS2 questions

Or start with something you already have

Bring one recent security report from the vendor operating your estate. We will map how many of its findings have an accountable owner, a verification state, and evidence you could hand to an auditor.

Book a baseline assessment

Contact

Book a baseline assessment

Tell us what you run and who operates it. We will come back with a scope, a timeline and a fixed price for one estate.