Visibility That Powers NIS2 Compliance
Most organisations have two to five times more suppliers connected to them than they've documented. NIS2 makes supply chain security a legal obligation under Article 21. Compliance starts with a living inventory, not the one in your contracts folder.

ThingsRecon Capabilities Mapped to NIS2 Requirements
Our discovery data feeds your NIS2 compliance programme by giving visibility across assets, suppliers, and external exposures that inform Article 21 risk-management measures. See how ThingsRecon supports each requirement.
Requirement
Article 21(2)(a): Policies on risk analysis and information system security.
Article 21(2)(i): Asset management and access control policies.
delivers
Automated Asset Discovery and Supply Chain Mapping continuously identify domains, IPs, APIs, certificates, and connections, including shadow IT and forgotten infrastructure your asset inventory doesn't capture.
Requirement
Article 21(1): Measures must be appropriate, proportionate, and based on the state of the art.
Article 21(2)(f): Policies and procedures to assess the effectiveness of risk-management measures.
delivers
Continuous external discovery with test-over-time comparison shows whether risk actually decreased between assessments, not just whether a policy exists on paper.
Requirement
Article 21(2)(d): Supply chain security, including the relationship between an entity and its direct suppliers or service providers.
Article 21(3): Take into account supplier-specific vulnerabilities and the overall quality of their cybersecurity practices.
delivers
Supply chain discovery and Digital Proximity scoring show which suppliers are deeply integrated into your environment, not just which ones exist on a vendor list, so a medium finding on a critical supplier gets prioritised as what it actually is.
Requirement
Article 22(1): Coordinated security risk assessments of critical ICT supply chains at Union level.
delivers
Concentration and dependency mapping across your supplier base gives the evidence needed to participate in sector-wide, coordinated risk assessments instead of assessing each supplier in isolation.
Requirement
Article 21(2)(e): Security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure.
delivers
A risk scoring engine with 100+ cyber hygiene indicators, including end-of-life software, exploited CVEs, and misconfigured TLS, flags which vulnerabilities sit on infrastructure that actually matters.
Requirement
Article 21(2)(b): Incident handling.
Article 24: Notification of significant cyber threats to affected service recipients without undue delay.
delivers
Contextual risk reports and remediation recommendations identify which exposures would meet the threshold for a significant incident or threat before they're exploited.
Requirement
Article 23: Reporting of significant incidents within 24 hours, 72 hours, and one month.
Article 32: Management bodies must approve and oversee risk-management measures and can be held personally liable for negligent breaches of duty.
delivers
Reporting insights plug into GRC, SIEM, or board-reporting workflows, giving management the visibility Article 32 requires them to oversee, and shortening the clock between detection and the 24-hour early warning.
Frequently asked questions
EASM can support NIS2 by helping organisations identify and monitor internet-facing assets, vulnerabilities, misconfigurations and external dependencies. This strengthens the asset visibility needed for risk analysis, vulnerability handling, incident preparedness and supply chain security measures. NIS2 requires appropriate and proportionate risk management rather than the purchase of a specific tool. External discovery should therefore connect findings to ownership, critical services and remediation processes. ThingsRecon adds supplier relationships, evidence and Digital Proximity to the external attack surface, helping teams show which assets and dependencies matter to essential operations and maintain a defensible record of continuous oversight. In practice, teams should record the supporting evidence, confirm ownership and business criticality, and connect the finding to an accountable workflow. This prevents a useful observation from becoming another isolated score or dashboard alert.
Audit-ready cyber evidence is documented, traceable information that demonstrates what was assessed, what was observed, when it was observed and how the organisation responded. Useful evidence includes scope, timestamps, technical findings, supporting records, ownership, remediation status and trend history. It should be reproducible and understandable to reviewers beyond the security team. ThingsRecon produces evidence-backed findings and continuous monitoring records that can support audits and regulatory reporting, while organisations add their control decisions, approvals and internal documentation. In practice, teams should record the supporting evidence, confirm ownership and business criticality, and connect the finding to an accountable workflow. This prevents a useful observation from becoming another isolated score or dashboard alert. The strongest implementation combines external intelligence with internal knowledge, supplier engagement and documented risk decisions, creating a view that remains useful as the digital ecosystem changes.





