NIS2

NIS2 readiness built from asset evidence, not a questionnaire

NIS2 Article 21(2) asks operators to run appropriate technical and organisational risk-management measures. AssetObserve maps read-only scan evidence from your own network onto those measures, so the readiness discussion starts from what is actually deployed rather than from memory.

Most NIS2 preparation stalls at the same place: nobody can say with confidence what is on the network, which of it is unpatched, and which of it is exploited in the wild today. AssetObserve answers that from evidence, then shows the remaining gaps as explicit open questions instead of hiding them behind a score.

What the scan can evidence on its own

Measures where read-only collection produces a real artefact.

Asset inventory and scope Authorized discovery across Windows, Linux, macOS, network devices via SNMP, VMware, Active Directory and cloud tenants, with coverage tracking that keeps unreachable, excluded and credential-failed targets visible instead of letting them quietly disappear from the count.
Vulnerability handling Installed-software inventory matched against a locally mirrored NVD corpus, then enriched with the CISA Known Exploited Vulnerabilities catalog and FIRST.org EPSS exploit-probability scores, so triage is exploit-aware rather than a raw CVE count. Matches are labelled 'possible match, not confirmed'.
Patch and lifecycle posture Patch staleness per host, end-of-life product matching, and exposed legacy protocols such as SMBv1 or self-signed TLS.
Backup and continuity signals Backup summaries, Volume Shadow Copy service state, recent backup failures and stale hypervisor snapshots.
Access control signals Local administrator sprawl, domain administrator counts, stale accounts and password-policy minimums collected read-only over LDAPS and WinRM.

What only a human can close

Measures where a declaration and a document are the evidence.

Incident-handling roles, crisis communication, tested recovery procedures, supplier security obligations, staff training and governance ownership cannot be established by scanning anything. AssetObserve treats these as declaration-backed controls: a named person records the answer, attaches the document, and the assessment shows a declaration-only control as exactly that.

The result is two separate numbers rather than one flattering percentage: how much is evidenced automatically, and how much rests on a human statement.

What you get out

Reports that a management team and an auditor can both read.

A NIS2 readiness report as HTML or PDF, a technical findings report, and a prioritised action plan, each rendered in German, English or Turkish from the same underlying evidence. Accepted risks are recorded with a business reason, a scope and an optional expiry, so a deliberate decision is visible as a decision rather than as an unresolved finding.

Where the claim stops

Common questions

01/ Does the NIS2 report make our organisation NIS2 compliant?

No. It prepares you. The report maps your evidence to the Article 21(2) measures and shows a readiness score alongside the open questions that remain. Compliance is a legal determination about your entity, not an output of a scan.

02/ Which NIS2 measures can be evidenced automatically?

Asset inventory and scope, vulnerability handling, patch and lifecycle posture, backup signals, and technical access-control signals. Incident handling, supplier obligations, training and governance need a human declaration with an attached document.

03/ Do we need an agent on every machine for NIS2 evidence?

No. One authorized scanner in a reachable position collects network evidence and can document Windows, Linux, macOS, printers, switches and hypervisors. Persistent endpoint mode is optional, mainly for roaming or rarely-connected devices.

04/ How is exploit-aware vulnerability data different from a CVE count?

A raw CVE count treats every match equally. AssetObserve enriches matches with the CISA KEV catalog, which forces a known-exploited vulnerability to critical regardless of its CVSS score, and with FIRST.org EPSS exploit-probability scores, which adjust the ranking within a severity band.