CYBER REGULATIONS

Visibility That Powers NIS2 Compliance

Most organisations have two to five times more suppliers connected to them than they've documented. NIS2 makes supply chain security a legal obligation under Article 21. Compliance starts with a living inventory, not the one in your contracts folder.

NIS2 Article 21 supply chain security compliance dashboard for essential and important entities

How ThingsRecon Supports NIS2 Compliance

continuous monitoring of external attack surface and assets
Map all internet-facing and third-party assets continuously in a living inventory
asset visibility expanding across external environments
Prioritise risks based on exposure, context, and Digital Proximity to your core systems
Use evidence-based reports for internal audits and NIS2 regulatory assessments
focused detection of high-risk assets or vulnerabilities
Deploy agentless scanning that integrates into cybersecurity risk-management and GRC processes

ThingsRecon Capabilities Mapped to NIS2 Requirements

Our discovery data feeds your NIS2 compliance programme by giving visibility across assets, suppliers, and external exposures that inform Article 21 risk-management measures. See how ThingsRecon supports each requirement.

NIS2
Requirement

Article 21(2)(a): Policies on risk analysis and information system security.

Article 21(2)(i): Asset management and access control policies.

What ThingsRecon
delivers

Automated Asset Discovery and Supply Chain Mapping continuously identify domains, IPs, APIs, certificates, and connections, including shadow IT and forgotten infrastructure your asset inventory doesn't capture.

NIS2
Requirement

Article 21(1): Measures must be appropriate, proportionate, and based on the state of the art.

Article 21(2)(f): Policies and procedures to assess the effectiveness of risk-management measures.

What ThingsRecon
delivers

Continuous external discovery with test-over-time comparison shows whether risk actually decreased between assessments, not just whether a policy exists on paper.

NIS2
Requirement

Article 21(2)(d): Supply chain security, including the relationship between an entity and its direct suppliers or service providers.

Article 21(3): Take into account supplier-specific vulnerabilities and the overall quality of their cybersecurity practices.

What ThingsRecon
delivers

Supply chain discovery and Digital Proximity scoring show which suppliers are deeply integrated into your environment, not just which ones exist on a vendor list, so a medium finding on a critical supplier gets prioritised as what it actually is.

NIS2
Requirement

Article 22(1): Coordinated security risk assessments of critical ICT supply chains at Union level.

What ThingsRecon
delivers

Concentration and dependency mapping across your supplier base gives the evidence needed to participate in sector-wide, coordinated risk assessments instead of assessing each supplier in isolation.

NIS2
Requirement

Article 21(2)(e): Security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure.

What ThingsRecon
delivers

A risk scoring engine with 100+ cyber hygiene indicators, including end-of-life software, exploited CVEs, and misconfigured TLS, flags which vulnerabilities sit on infrastructure that actually matters.

NIS2
Requirement

Article 21(2)(b): Incident handling.

Article 24: Notification of significant cyber threats to affected service recipients without undue delay.

What ThingsRecon
delivers

Contextual risk reports and remediation recommendations identify which exposures would meet the threshold for a significant incident or threat before they're exploited.

NIS2
Requirement

Article 23: Reporting of significant incidents within 24 hours, 72 hours, and one month.

Article 32: Management bodies must approve and oversee risk-management measures and can be held personally liable for negligent breaches of duty.

What ThingsRecon
delivers

Reporting insights plug into GRC, SIEM, or board-reporting workflows, giving management the visibility Article 32 requires them to oversee, and shortening the clock between detection and the 24-hour early warning.

Frequently asked questions

How can EASM support NIS2 compliance?

EASM can support NIS2 by helping organisations identify and monitor internet-facing assets, vulnerabilities, misconfigurations and external dependencies. This strengthens the asset visibility needed for risk analysis, vulnerability handling, incident preparedness and supply chain security measures. NIS2 requires appropriate and proportionate risk management rather than the purchase of a specific tool. External discovery should therefore connect findings to ownership, critical services and remediation processes. ThingsRecon adds supplier relationships, evidence and Digital Proximity to the external attack surface, helping teams show which assets and dependencies matter to essential operations and maintain a defensible record of continuous oversight. In practice, teams should record the supporting evidence, confirm ownership and business criticality, and connect the finding to an accountable workflow. This prevents a useful observation from becoming another isolated score or dashboard alert.

What is audit-ready cyber evidence?

Audit-ready cyber evidence is documented, traceable information that demonstrates what was assessed, what was observed, when it was observed and how the organisation responded. Useful evidence includes scope, timestamps, technical findings, supporting records, ownership, remediation status and trend history. It should be reproducible and understandable to reviewers beyond the security team. ThingsRecon produces evidence-backed findings and continuous monitoring records that can support audits and regulatory reporting, while organisations add their control decisions, approvals and internal documentation. In practice, teams should record the supporting evidence, confirm ownership and business criticality, and connect the finding to an accountable workflow. This prevents a useful observation from becoming another isolated score or dashboard alert. The strongest implementation combines external intelligence with internal knowledge, supplier engagement and documented risk decisions, creating a view that remains useful as the digital ecosystem changes.

SEE YOUR EXPOSURE

Test your supply chain against NIS2 requirements.

living map of risk across digital supply chain