Skip to content

Compliance

Implementing NIS2 risk management technically

NIS2 requires ongoing risk management: handle vulnerabilities, secure the supply chain, manage incidents. blacklens.io delivers the technical evidence, continuously rather than once a year.

NIS2 evidenceas PDF
Asset inventory and exposure scoreNIS2 Art. 21 (2) acontinuous
Supplier watchlistNIS2 Art. 21 (2) dabout every 30 min
Vulnerability reportNIS2 Art. 21 (2) emonthly
Executive report with trendNIS2 Art. 21 (2) fweekly

What NIS2 requires

Directive (EU) 2022/2555 applies to essential and important entities. These four points shape the technical implementation.

Art. 20

Management is accountable

Management bodies approve the measures, oversee their implementation and undergo training.

Art. 21(2)

Ten minimum measures

From risk analysis and vulnerability handling to MFA, as an ongoing process.

Art. 23

Report in 24 h, 72 h, 1 month

Early warning, incident notification and final report for significant incidents.

Annexes I and II

18 sectors

Rule of thumb: from 50 employees or EUR 10 million turnover. Suppliers often by contract.

Technical guidance, not legal advice. Which obligations apply to you is for your legal department, auditor or supervisory authority to confirm.

Article 21 mapped to blacklens.io

For each measure with a technical core, the capability that provides the evidence. The remaining measures are covered in the FAQ.

Art. 21(2)(a)

Newly discovered assets+4 since yesterday
beispiel-gmbh.atRoot domain
vpn.beispiel-gmbh.atFortiGate SSL-VPN 7.0.12Critical
dev-old.beispiel-gmbh.atGitLab 15.2Shadow ITHigh
mail.beispiel-gmbh.atExchange Server 2019Medium
203.0.113.24OpenSSH 8.9NewInfo

Visuals show sample data.

Four steps to continuous evidence

  1. 1

    Define the scope

    Add domains, IP ranges and cloud accounts. Scope suggestions show what is still missing.

  2. 2

    Scan outside and inside

    The external attack surface is tracked automatically, Sentry scans the internal network on schedule.

  3. 3

    Add suppliers

    Import your supplier list as CSV; leak site matching then runs automatically.

  4. 4

    Schedule the evidence

    Executive and vulnerability reports go to management, ISMS and auditor on schedule.

Example from practice

Critical infrastructure operator prepares for a NIS2 audit

A critical infrastructure company had to implement NIS2 technically and prove it in an audit. With blacklens.io, attack surface and vulnerabilities were monitored continuously, prioritised and documented in automated reports.

  • Result

    In the audit, the technical protection of the external systems was rated "exemplary and consistently documented".

Remediationone workflow for every source
12Open
5In progress
2Risk accepted
48Closed
CVE-2024-21762
  1. Assigned to IT operations
  2. Update installed
  3. Re-scan confirmed: closed automatically

Visuals show sample data.

Frequently asked questions

NIS2, Directive (EU) 2022/2555, replaces the 2016 NIS Directive and covers essential and important entities in 18 sectors, as a rule of thumb from 50 employees or EUR 10 million annual turnover. Besides energy, transport, health and digital infrastructure this includes manufacturing, food, chemicals, postal services and IT service providers. In Austria it is transposed through the NISG, in Germany through the NIS2UmsuCG; in both cases the technical requirements come from Article 21. When in doubt, have your legal department check whether your company is covered.

NIS2 evidence that is ready before the audit

Start with your domains and see how inventory, findings and reports come together. Or discuss your NIS2 implementation with us in a demo.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings