NIS2 Compliance Automation

NIS2 evidence, incident reporting, and supply-chain controls — automated.

NIS2 demands board-level accountability, 24-hour incident notifications, and provable supply-chain security. Lojycal turns each requirement into a live, signed stream of evidence — no spreadsheets, no last-minute scrambles before ENISA or your national CSIRT come asking.

What NIS2 actually demands

NIS2 (Directive (EU) 2022/2555) raises the bar from its predecessor — broader scope, harder deadlines, and personal liability for management. Four things must be true on any given day, not just at year-end.

  • Board-approved cyber risk management

    Article 21 mandates a documented set of technical, operational, and organisational measures — owned and signed off by management.

  • 24/72-hour incident notification

    Significant incidents need an early warning within 24 hours, a full notification within 72, and a final report within one month.

  • Supply-chain security

    Direct suppliers and service providers must be assessed for cyber risk, with evidence of contractual controls and ongoing monitoring.

  • Continuous attestable evidence

    National competent authorities can request evidence of compliance at any time. Audits are no longer the worst case — supervised inspections are.

The Lojycal NIS2 engine

Four connected workspaces produce every artefact your competent authority — or the management board — will ask for.

Risk & measures register

Every Article 21 measure with owner, status, and management sign-off. Linked to the underlying control in Lojycal that operates it.

Trust Center

Incident timeline

Detected events flow from your SIEM/EDR into a WORM incident ledger. Early-warning, full notification, and final-report templates auto-populate.

SIEM Egress + Audit Log

Supply-chain ledger

Vendor inventory with cyber-risk tier, contract clauses, and last-attestation date. Drift triggers a re-review automatically.

Vendor Governance + SaaS

Evidence pack

Signed exports for inspectors: measures, incident records, supplier attestations, and management-review minutes — verifiable independently.

Trust Center → Evidence Pack

Article 21 measures → Lojycal controls

Lojycal automatically produces evidence for the majority of Article 21 measures. A sampled view:

Art. 21 measureExample obligationLojycal source
(a) Risk analysis & info-system securityDocumented risk register with treatmentTrust Center → Risk
(b) Incident handlingDetection, response, 24/72h notificationSIEM + Incident Ledger
(c) Business continuityBackup, recovery, crisis managementAsset Lifecycle + Backup Evidence
(d) Supply-chain securityVendor assessment & monitoringVendor Governance + SaaS SSPM
(e) Secure acquisition & developmentVulnerability handling, secure SDLCWorkflows + Change Audit
(f) Effectiveness assessmentInternal review of cyber measuresTrust Center → Access Reviews
(g) Cyber hygiene & trainingAwareness training, basic hygieneHR Automation
(h) CryptographyPolicies and key managementKMS + Crypto Posture
(i) HR security & access controlJoiner/mover/leaver, RBAC, MFARBAC + HR Automation
(j) MFA & secure commsMFA on all privileged accessAAL2 Enforcement

Sampled — not exhaustive. Coverage depends on which Lojycal modules and connectors you have enabled.

Inspectors don't accept screenshots

Under NIS2, national competent authorities can carry out on-site inspections, off-site supervision, ad-hoc audits, and security scans. The artefact that fails fastest under that pressure is the static screenshot.

Lojycal writes every workflow run, every dual-control decision, every policy change to a WORM (write-once, read-many) audit log. The Trust Center bundles selected windows into a signed Evidence Pack — JSON, CSV and PDF, with a detached HMAC signature using a per-organisation key — that an inspector can verify independently, without ever logging into your tenant.

From scoping to inspection-ready — a 90-day path

Most teams treat NIS2 as a paperwork project and run out of time. Lojycal collapses it into a quarter because the evidence collects itself from day one.

  1. Days 0–30

    Phase 1 — Scoping & measures

    Confirm essential vs. important entity classification. Map the 10 Article 21 measure groups to existing controls. Lojycal pre-fills the measures register for every control it already operates.

  2. Days 31–60

    Phase 2 — Incident & supply-chain

    Wire the SIEM/EDR egress, populate the supplier ledger with cyber-risk tier, and connect contracts. The incident timeline starts collecting from day one.

  3. Days 61–90

    Phase 3 — Management review & rehearsal

    Rehearse the 24h / 72h / 1-month notification flow. Run a management review. Produce a signed Evidence Pack ready to hand to your national CSIRT on request.

NIS2 automation — common questions

What is NIS2 automation?

NIS2 automation is the practice of generating Article 21 measure evidence, incident notifications, supplier attestations, and management-review records directly from live operational systems — instead of producing them manually before each inspection. Lojycal automates the measures register, the incident timeline, the supply-chain ledger, and the signed Evidence Pack end-to-end.

Does Lojycal replace my national competent authority's audit?

No. NIS2 inspections are carried out by national competent authorities (e.g. BSI in Germany, ANSSI in France, NCSC-NL in the Netherlands). Lojycal automates everything you bring to that inspection: the measures register, the incident records, the supplier risk register and the signed Evidence Pack. Inspectors verify the artefacts; we generate them continuously.

How does Lojycal handle the 24-hour / 72-hour incident notification deadlines?

Detected events flow from your SIEM, EDR, MDM and SaaS connectors into the incident ledger. An incident hitting the 'significant' threshold automatically opens a 24-hour early-warning draft and a 72-hour full-notification draft, populated from the evidence already captured. The compliance owner edits and submits — they don't start from a blank page.

How is supply-chain security evidenced?

Lojycal's Vendor Governance and SaaS SSPM modules inventory every supplier with cyber-risk tier, contractual security clauses, last-attestation date and observed posture (e.g. SSO, MFA enforcement, audit-log retention). Drift — a missed attestation, a downgraded posture — triggers a re-review workflow automatically.

We're an 'important entity', not 'essential'. Does this still apply?

Yes. Both essential and important entities under NIS2 are subject to the same Article 21 measures and the same incident-reporting deadlines. The difference is the supervision regime — important entities face ex-post supervision rather than ex-ante. The evidence Lojycal produces is identical for both.

How does NIS2 differ from ISO 27001 in what Lojycal automates?

ISO 27001 is voluntary and certification-driven (a third-party auditor issues a certificate). NIS2 is mandatory and supervision-driven (a national authority can inspect at any time). Lojycal's underlying evidence is largely shared — an ISO 27001 Annex A.5.23 control on cloud supplier security maps directly to NIS2 Article 21(d). The mapping is bidirectional inside the Trust Center.

Run NIS2 as a live system, not a board paper.

Every Article 21 measure. Every notified incident. Every supplier attestation. One signed source of truth.