NIS2

Article 21, mapped to document workflows

NIS2 Article 21 asks covered entities to manage risk, incidents, continuity, supply chain, cryptography, access, and training. A document platform in that environment needs to support evidence in each area.

MAPPING

Public control map

NIS2 areaSovereign evidence expectation
Risk analysisDeployment review, data-flow map, roles, regions, and processor inventory.
Incident handlingAudit logs, owner contacts, notification workflow, and exportable event records.
ContinuityBackup/restore plan, restore testing, and documented recovery ownership.
Supply chainPinned components, deployment evidence, and sub-processor review.
CryptographyTLS, encryption-at-rest posture, and customer-managed key custody planning.