Skip to content
Tenant Excellence

Applies toEuropean Union

NIS2

Article 21 security measures of Directive (EU) 2022/2555 for essential and important entities, evaluated from tenant configuration.

From Complete

Scope as evaluated

  • Access control, MFA and identity policies (Art. 21(2)(i), (j))
  • Incident handling and logging prerequisites (Art. 21(2)(b))
  • Supply-chain and basic cyber-hygiene settings (Art. 21(2)(d), (g))

Read from the tenant

  • Conditional Access, MFA and legacy authentication
  • Audit-log and alert configuration
  • Email authentication and sharing controls

Sample controls

  • Art. 21(2)(j) Multi-factor authentication
  • Art. 21(2)(i) Access control policies
  • Art. 21(2)(b) Incident handling
Results are configuration indications drawn from your tenant. They are not an audit opinion or a certification.

In depth

Give the auditor a link, not a folder

Every covered control shows the data Microsoft Graph returned and the endpoint it came from. One click creates a read-only snapshot for one framework; it needs no account and expires after 24 hours.

  • Structured proof per control, with its Graph or ARM source
  • Scoped to one framework, read-only, no sign-in for the auditor
  • Expires after 24 hours; creation is written to the audit log
Learn more

Questions

Questions about NIS2

Does NIS2 have a certification?

No. Member-state authorities supervise compliance; the assessment gives you configuration evidence for that conversation.

Are governance measures covered?

Only where they leave a trace in configuration. Management approval, training and policies appear as not assessed.

Is the auditor view available for NIS2?

Yes, in Complete and Premium.

Request a demo

Which frameworks do you report against?

Tell us in the demo request and we will show the matching controls on a demo tenant.

0 / 2,000