NIS2

NIS2 asks for proof, not promises. AegiFlow produces the proof.

The directive requires risk-management measures, business continuity and incident reporting discipline. AegiFlow's evidence-first operation maps naturally onto these duties for your web services.

Operational viewIllustrative. No customer data.
01

What NIS2 expects, and what AegiFlow records

A practical mapping between the directive's technical measures and the operational evidence the platform keeps.

NIS2 measure (Art. 21)AegiFlow evidence
Incident handlingCorrelated cases with one accountable timeline: signals, decisions, actions and outcomes, retained for audit.
Business continuity and crisis managementSigned static continuity bundles keep approved public content available while the origin is isolated.
Backup management and disaster recoveryRecovery drills executed on a validation hostname, with pass/fail receipts — recovery is exercised, not assumed.
Supply-chain securityA signed, read-only software inventory matched against public advisories with exact package versions.
Effectiveness assessmentCapability states with freshness: a check that has not run recently is shown as Unknown, never as green.

AegiFlow provides operational evidence, not legal advice. The compliance determination and reporting duties remain with your organization and its advisors.

02

The report itself

The evidence above was always there. What was missing was a document that fixes it in time.

A verdict per measure

Each Article 21 measure gets met, partial, unknown or not met — and under it, the exact records the verdict rests on: audit entries with the person who acted, signed continuity bundles, drill receipts, case timings.

Unknown is not a pass

A measure with no recent evidence is reported as Unknown. It is neither a pass nor a failure, and calling it either would be the fastest way to make the document worthless to the person reading it.

It cannot be quietly edited

Every report carries a content hash, and the table it lives in accepts inserts only — no updates, no deletes. A report somebody could rewrite after the fact would be worth nothing to a regulator.

Three measures we do not observe

Training, human resources security and secured emergency communications are organisational. The document names them and says plainly that we see none of them, rather than leaving a reader to assume they are covered.

Bring your web services under evidence.

Start in observation and build the operational record NIS2 conversations ask for.