A verdict per measure
Each Article 21 measure gets met, partial, unknown or not met — and under it, the exact records the verdict rests on: audit entries with the person who acted, signed continuity bundles, drill receipts, case timings.
The directive requires risk-management measures, business continuity and incident reporting discipline. AegiFlow's evidence-first operation maps naturally onto these duties for your web services.
A practical mapping between the directive's technical measures and the operational evidence the platform keeps.
| NIS2 measure (Art. 21) | AegiFlow evidence |
|---|---|
| Incident handling | Correlated cases with one accountable timeline: signals, decisions, actions and outcomes, retained for audit. |
| Business continuity and crisis management | Signed static continuity bundles keep approved public content available while the origin is isolated. |
| Backup management and disaster recovery | Recovery drills executed on a validation hostname, with pass/fail receipts — recovery is exercised, not assumed. |
| Supply-chain security | A signed, read-only software inventory matched against public advisories with exact package versions. |
| Effectiveness assessment | Capability states with freshness: a check that has not run recently is shown as Unknown, never as green. |
AegiFlow provides operational evidence, not legal advice. The compliance determination and reporting duties remain with your organization and its advisors.
The evidence above was always there. What was missing was a document that fixes it in time.
Each Article 21 measure gets met, partial, unknown or not met — and under it, the exact records the verdict rests on: audit entries with the person who acted, signed continuity bundles, drill receipts, case timings.
A measure with no recent evidence is reported as Unknown. It is neither a pass nor a failure, and calling it either would be the fastest way to make the document worthless to the person reading it.
Every report carries a content hash, and the table it lives in accepts inserts only — no updates, no deletes. A report somebody could rewrite after the fact would be worth nothing to a regulator.
Training, human resources security and secured emergency communications are organisational. The document names them and says plainly that we see none of them, rather than leaving a reader to assume they are covered.
Start in observation and build the operational record NIS2 conversations ask for.