NIS2 evidence, incident reporting, and supply-chain controls — automated.
NIS2 demands board-level accountability, 24-hour incident notifications, and provable supply-chain security. Lojycal turns each requirement into a live, signed stream of evidence — no spreadsheets, no last-minute scrambles before ENISA or your national CSIRT come asking.
What NIS2 actually demands
NIS2 (Directive (EU) 2022/2555) raises the bar from its predecessor — broader scope, harder deadlines, and personal liability for management. Four things must be true on any given day, not just at year-end.
Board-approved cyber risk management
Article 21 mandates a documented set of technical, operational, and organisational measures — owned and signed off by management.
24/72-hour incident notification
Significant incidents need an early warning within 24 hours, a full notification within 72, and a final report within one month.
Supply-chain security
Direct suppliers and service providers must be assessed for cyber risk, with evidence of contractual controls and ongoing monitoring.
Continuous attestable evidence
National competent authorities can request evidence of compliance at any time. Audits are no longer the worst case — supervised inspections are.
The Lojycal NIS2 engine
Four connected workspaces produce every artefact your competent authority — or the management board — will ask for.
Risk & measures register
Every Article 21 measure with owner, status, and management sign-off. Linked to the underlying control in Lojycal that operates it.
Trust Center
Incident timeline
Detected events flow from your SIEM/EDR into a WORM incident ledger. Early-warning, full notification, and final-report templates auto-populate.
SIEM Egress + Audit Log
Supply-chain ledger
Vendor inventory with cyber-risk tier, contract clauses, and last-attestation date. Drift triggers a re-review automatically.
Vendor Governance + SaaS
Evidence pack
Signed exports for inspectors: measures, incident records, supplier attestations, and management-review minutes — verifiable independently.
Trust Center → Evidence Pack
Article 21 measures → Lojycal controls
Lojycal automatically produces evidence for the majority of Article 21 measures. A sampled view:
| Art. 21 measure | Example obligation | Lojycal source |
|---|---|---|
| (a) Risk analysis & info-system security | Documented risk register with treatment | Trust Center → Risk |
| (b) Incident handling | Detection, response, 24/72h notification | SIEM + Incident Ledger |
| (c) Business continuity | Backup, recovery, crisis management | Asset Lifecycle + Backup Evidence |
| (d) Supply-chain security | Vendor assessment & monitoring | Vendor Governance + SaaS SSPM |
| (e) Secure acquisition & development | Vulnerability handling, secure SDLC | Workflows + Change Audit |
| (f) Effectiveness assessment | Internal review of cyber measures | Trust Center → Access Reviews |
| (g) Cyber hygiene & training | Awareness training, basic hygiene | HR Automation |
| (h) Cryptography | Policies and key management | KMS + Crypto Posture |
| (i) HR security & access control | Joiner/mover/leaver, RBAC, MFA | RBAC + HR Automation |
| (j) MFA & secure comms | MFA on all privileged access | AAL2 Enforcement |
Sampled — not exhaustive. Coverage depends on which Lojycal modules and connectors you have enabled.
Inspectors don't accept screenshots
Under NIS2, national competent authorities can carry out on-site inspections, off-site supervision, ad-hoc audits, and security scans. The artefact that fails fastest under that pressure is the static screenshot.
Lojycal writes every workflow run, every dual-control decision, every policy change to a WORM (write-once, read-many) audit log. The Trust Center bundles selected windows into a signed Evidence Pack — JSON, CSV and PDF, with a detached HMAC signature using a per-organisation key — that an inspector can verify independently, without ever logging into your tenant.
From scoping to inspection-ready — a 90-day path
Most teams treat NIS2 as a paperwork project and run out of time. Lojycal collapses it into a quarter because the evidence collects itself from day one.
- Days 0–30
Phase 1 — Scoping & measures
Confirm essential vs. important entity classification. Map the 10 Article 21 measure groups to existing controls. Lojycal pre-fills the measures register for every control it already operates.
- Days 31–60
Phase 2 — Incident & supply-chain
Wire the SIEM/EDR egress, populate the supplier ledger with cyber-risk tier, and connect contracts. The incident timeline starts collecting from day one.
- Days 61–90
Phase 3 — Management review & rehearsal
Rehearse the 24h / 72h / 1-month notification flow. Run a management review. Produce a signed Evidence Pack ready to hand to your national CSIRT on request.
NIS2 automation — common questions
What is NIS2 automation?
NIS2 automation is the practice of generating Article 21 measure evidence, incident notifications, supplier attestations, and management-review records directly from live operational systems — instead of producing them manually before each inspection. Lojycal automates the measures register, the incident timeline, the supply-chain ledger, and the signed Evidence Pack end-to-end.
Does Lojycal replace my national competent authority's audit?
No. NIS2 inspections are carried out by national competent authorities (e.g. BSI in Germany, ANSSI in France, NCSC-NL in the Netherlands). Lojycal automates everything you bring to that inspection: the measures register, the incident records, the supplier risk register and the signed Evidence Pack. Inspectors verify the artefacts; we generate them continuously.
How does Lojycal handle the 24-hour / 72-hour incident notification deadlines?
Detected events flow from your SIEM, EDR, MDM and SaaS connectors into the incident ledger. An incident hitting the 'significant' threshold automatically opens a 24-hour early-warning draft and a 72-hour full-notification draft, populated from the evidence already captured. The compliance owner edits and submits — they don't start from a blank page.
How is supply-chain security evidenced?
Lojycal's Vendor Governance and SaaS SSPM modules inventory every supplier with cyber-risk tier, contractual security clauses, last-attestation date and observed posture (e.g. SSO, MFA enforcement, audit-log retention). Drift — a missed attestation, a downgraded posture — triggers a re-review workflow automatically.
We're an 'important entity', not 'essential'. Does this still apply?
Yes. Both essential and important entities under NIS2 are subject to the same Article 21 measures and the same incident-reporting deadlines. The difference is the supervision regime — important entities face ex-post supervision rather than ex-ante. The evidence Lojycal produces is identical for both.
How does NIS2 differ from ISO 27001 in what Lojycal automates?
ISO 27001 is voluntary and certification-driven (a third-party auditor issues a certificate). NIS2 is mandatory and supervision-driven (a national authority can inspect at any time). Lojycal's underlying evidence is largely shared — an ISO 27001 Annex A.5.23 control on cloud supplier security maps directly to NIS2 Article 21(d). The mapping is bidirectional inside the Trust Center.
Run NIS2 as a live system, not a board paper.
Every Article 21 measure. Every notified incident. Every supplier attestation. One signed source of truth.
