Compliance
Implementing NIS2 risk management technically
NIS2 requires ongoing risk management: handle vulnerabilities, secure the supply chain, manage incidents. blacklens.io delivers the technical evidence, continuously rather than once a year.
What NIS2 requires
Directive (EU) 2022/2555 applies to essential and important entities. These four points shape the technical implementation.
Management is accountable
Management bodies approve the measures, oversee their implementation and undergo training.
Ten minimum measures
From risk analysis and vulnerability handling to MFA, as an ongoing process.
Report in 24 h, 72 h, 1 month
Early warning, incident notification and final report for significant incidents.
18 sectors
Rule of thumb: from 50 employees or EUR 10 million turnover. Suppliers often by contract.
Technical guidance, not legal advice. Which obligations apply to you is for your legal department, auditor or supervisory authority to confirm.
Article 21 mapped to blacklens.io
For each measure with a technical core, the capability that provides the evidence. The remaining measures are covered in the FAQ.
Art. 21(2)(a)
Art. 21(2)(e)
Art. 21(2)(d)
Art. 21(2)(b)
- CVE published08:12
- 2 assets in your inventory affected09:00
- Confirmed by PoC scan09:26
- Alert sent to Microsoft Teams09:27
Art. 21(2)(f)
Visuals show sample data.
Four steps to continuous evidence
- 1
Define the scope
Add domains, IP ranges and cloud accounts. Scope suggestions show what is still missing.
- 2
Scan outside and inside
The external attack surface is tracked automatically, Sentry scans the internal network on schedule.
- 3
Add suppliers
Import your supplier list as CSV; leak site matching then runs automatically.
- 4
Schedule the evidence
Executive and vulnerability reports go to management, ISMS and auditor on schedule.
Example from practice
Critical infrastructure operator prepares for a NIS2 audit
A critical infrastructure company had to implement NIS2 technically and prove it in an audit. With blacklens.io, attack surface and vulnerabilities were monitored continuously, prioritised and documented in automated reports.
Result
In the audit, the technical protection of the external systems was rated "exemplary and consistently documented".
- Assigned to IT operations
- Update installed
- Re-scan confirmed: closed automatically
Visuals show sample data.
Frequently asked questions
- NIS2, Directive (EU) 2022/2555, replaces the 2016 NIS Directive and covers essential and important entities in 18 sectors, as a rule of thumb from 50 employees or EUR 10 million annual turnover. Besides energy, transport, health and digital infrastructure this includes manufacturing, food, chemicals, postal services and IT service providers. In Austria it is transposed through the NISG, in Germany through the NIS2UmsuCG; in both cases the technical requirements come from Article 21. When in doubt, have your legal department check whether your company is covered.
NIS2 evidence that is ready before the audit
Start with your domains and see how inventory, findings and reports come together. Or discuss your NIS2 implementation with us in a demo.
- 14 days free, all features
- No credit card required
- We walk you through your first findings