Compliance · NIS2 directive
NIS2 doesn't ask who can access your systems.
It demands proof. Deliver it

NIS2 makes cybersecurity a management-liability issue and demands measures you can demonstrate — not just document. enclaive strengthens your program across the Article 21 measures, and supplies technical enforcement and continuous evidence for the three that are hardest to prove: cryptography that reaches data in use, access control that binds your providers, and evidence you can produce on demand.

Built and operated in Germany. Trusted in EU public-sector and critical-infrastructure programs.

Evidence generated from live operations, not spreadsheets
Technical enforcement where you rely on policy today
Works alongside your existing security stack
CONFIDENTIAL COMPUTING LAYER OF GERMANY'S GOVTECH-PLATFORM
What NIS2 actually demands

NIS2 (Directive (EU) 2022/2555) is the EU's cybersecurity baseline for essential and important entities across 18 sectors — energy, transport, health, digital infrastructure, manufacturing, public administration and more. It replaced the original NIS Directive with a far wider scope and far sharper teeth.

Three features make it different from the compliance you've done before:

OFFICIAL TEXT: DIRECTIVE (EU) 2022/2555 ON EUR-LEX — https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng — SEE ANNEXES I AND II FOR THE SECTORS AND ENTITY CATEGORIES IN SCOPE. WHETHER YOUR ORGANIZATION IS IN SCOPE, AND UNDER WHICH NATIONAL IMPLEMENTATION, IS A LEGAL DETERMINATION — YOUR COUNSEL OR DPO SHOULD MAKE IT. WHAT THIS PAGE COVERS IS THE TECHNICAL HALF: THE MEASURES THEMSELVES, AND HOW TO MAKE THEM PROVABLE.
Management is personally on the hook
+
Measures must be demonstrable
+
The penalties are real
+
Where NIS2 programs get stuck

Article 21 is the directive's list of required cybersecurity measures — from risk analysis and cryptography to access control and supply-chain security. Most of them are familiar ground. Three are structurally hard, because conventional tooling can document them but not prove them.

01
Cryptography with a hole in it
+
02
Access control you can't enforce on your provider
+
03
Evidence assembled under pressure
+
How enclaive maps to the hard measures

enclaive solves the three hard measures with encryption in use (confidential VMs, Kubernetes and databases), customer-held keys released only against attestation (vHSM + Nitride), and continuous evidence packs from the eMCP console. Below, the Article 21 areas where that adds technical enforcement, and the evidence each produces.

Show
enclaive control
Evidence produced
NIS2 requirement area
enclaive control
Cryptography & encryption
Art. 21(2)(h)

Encryption at rest, in transit and in use: workloads run in hardware-sealed environments with memory encrypted during processing.

Access control & asset management
Art. 21(2)(i)

Attested workload identity with least-privilege access; infrastructure operators technically excluded from workload data — including cloud admins.

Supply chain security
Art. 21(2)(d)

Remote attestation verifies that workloads run genuine, unmodified code on genuine hardware — regardless of who supplies or operates the infrastructure.

Security in acquisition & development
Art. 21(2)(e)

Attested CI/CD: signing keys and pipeline secrets released only to build environments that prove their integrity.

Effectiveness assessment
Art. 21(2)(f)

Evidence packs generated from live operations: attestation status, key custody coverage, policy enforcement — on demand.

Demonstrating control effectiveness
Testing & supervision (Art. 24–26)

Article references are indicative pointers to the directive's minimum-measure areas, not legal advice.

What enclaive does and doesn't do for NIS2

No product makes you NIS2 compliant, including ours.
NIS2 is an organizational obligation: governance, risk analysis, incident response, training and reporting duties stay with you, and a vendor who tells you otherwise is selling you an audit finding.

What enclaive does is narrower and more valuable: for the measures above, it replaces policy-based assurance with technical enforcement, and periodic evidence-gathering with continuous proof. Your compliance program keeps its scope — but its hardest technical claims become demonstrable instead of asserted, and management signs the declaration standing on enforcement rather than trust. And when the supervisory authority audits, the evidence is already there: attestation records and evidence packs cut audit preparation from weeks of assembly to an export.

FAQ

What GRC owners ask

Q·01

Does deploying enclaive make us NIS2 compliant?

No — and be suspicious of any vendor who says yes. NIS2 compliance is an organizational state: governance, processes, training and reporting alongside technical measures. enclaive makes specific technical measures enforceable and provable; the box above states the boundary plainly.

Q·02

Are we even in scope?

That's a legal determination for your counsel or DPO, based on sector, size and national implementation. If you are in scope, the technical measures on this page are the ones auditors probe hardest.

+
Q·03

How does this help with the 24-hour and 72-hour incident reporting duties?

Indirectly but materially: attestation and access-path records shorten the “what could have been read” question, which is usually what delays a report. The reporting duty itself stays yours.

+
Q·04

We're a financial entity — does DORA or NIS2 apply to us?

DORA is lex specialis for financial entities, and the technical enforcement is the same underneath. See the DORA page for that framing.

+
Q·05

We're ISO 27001 certified. What does this add?

Certification shows your management system works. NIS2 supervisors can still ask whether a specific measure is effective — that's where continuous, generated evidence beats a point-in-time audit.

+
Q·06

Our cloud provider says they're NIS2 compliant. Doesn't that cover us?

Their compliance covers their obligations, not yours — and it doesn't answer whether their administrators can read your workloads. Operator exclusion is what turns that from a contractual promise into a technical fact.

+
Get started

Bring your gap analysis, or start one

Tell us where your NIS2 journey stands — the measures still open, the finding you're remediating, or the declaration your management won't sign yet. We'll show you which controls close the technical gaps and what the evidence looks like.

Certifications & security
Certified ISO/IEC 27001
IT Security made in Germany — TeleTrusT