NIS2 makes cybersecurity a management-liability issue and demands measures you can demonstrate — not just document. enclaive strengthens your program across the Article 21 measures, and supplies technical enforcement and continuous evidence for the three that are hardest to prove: cryptography that reaches data in use, access control that binds your providers, and evidence you can produce on demand.
Built and operated in Germany. Trusted in EU public-sector and critical-infrastructure programs.
NIS2 (Directive (EU) 2022/2555) is the EU's cybersecurity baseline for essential and important entities across 18 sectors — energy, transport, health, digital infrastructure, manufacturing, public administration and more. It replaced the original NIS Directive with a far wider scope and far sharper teeth.
Three features make it different from the compliance you've done before:
Article 21 is the directive's list of required cybersecurity measures — from risk analysis and cryptography to access control and supply-chain security. Most of them are familiar ground. Three are structurally hard, because conventional tooling can document them but not prove them.
enclaive solves the three hard measures with encryption in use (confidential VMs, Kubernetes and databases), customer-held keys released only against attestation (vHSM + Nitride), and continuous evidence packs from the eMCP console. Below, the Article 21 areas where that adds technical enforcement, and the evidence each produces.
Encryption at rest, in transit and in use: workloads run in hardware-sealed environments with memory encrypted during processing.
Attestation records showing which workloads run encrypted-in-use, continuously.
Attested workload identity with least-privilege access; infrastructure operators technically excluded from workload data — including cloud admins.
Access-path inventory before/after; key-release logs bound to verified identities.
Remote attestation verifies that workloads run genuine, unmodified code on genuine hardware — regardless of who supplies or operates the infrastructure.
Cryptographic integrity reports any authorized party can independently verify.
Attested CI/CD: signing keys and pipeline secrets released only to build environments that prove their integrity.
Signed-release records and pipeline attestation logs for the software you ship and deploy.
Evidence packs generated from live operations: attestation status, key custody coverage, policy enforcement — on demand.
A current audit file whenever the authority, the auditor or the board asks.
Article references are indicative pointers to the directive's minimum-measure areas, not legal advice.
What enclaive does is narrower and more valuable: for the measures above, it replaces policy-based assurance with technical enforcement, and periodic evidence-gathering with continuous proof. Your compliance program keeps its scope — but its hardest technical claims become demonstrable instead of asserted, and management signs the declaration standing on enforcement rather than trust. And when the supervisory authority audits, the evidence is already there: attestation records and evidence packs cut audit preparation from weeks of assembly to an export.
What GRC owners ask
Does deploying enclaive make us NIS2 compliant?
No — and be suspicious of any vendor who says yes. NIS2 compliance is an organizational state: governance, processes, training and reporting alongside technical measures. enclaive makes specific technical measures enforceable and provable; the box above states the boundary plainly.
Are we even in scope?
That's a legal determination for your counsel or DPO, based on sector, size and national implementation. If you are in scope, the technical measures on this page are the ones auditors probe hardest.
How does this help with the 24-hour and 72-hour incident reporting duties?
Indirectly but materially: attestation and access-path records shorten the “what could have been read” question, which is usually what delays a report. The reporting duty itself stays yours.
We're a financial entity — does DORA or NIS2 apply to us?
DORA is lex specialis for financial entities, and the technical enforcement is the same underneath. See the DORA page for that framing.
We're ISO 27001 certified. What does this add?
Certification shows your management system works. NIS2 supervisors can still ask whether a specific measure is effective — that's where continuous, generated evidence beats a point-in-time audit.
Our cloud provider says they're NIS2 compliant. Doesn't that cover us?
Their compliance covers their obligations, not yours — and it doesn't answer whether their administrators can read your workloads. Operator exclusion is what turns that from a contractual promise into a technical fact.
Bring your gap analysis, or start one
Tell us where your NIS2 journey stands — the measures still open, the finding you're remediating, or the declaration your management won't sign yet. We'll show you which controls close the technical gaps and what the evidence looks like.
.png)
