NIS2 Article 21 asks covered entities to manage risk, incidents, continuity, supply chain, cryptography, access, and training. A document platform in that environment needs to support evidence in each area.
| NIS2 area | Sovereign evidence expectation |
|---|---|
| Risk analysis | Deployment review, data-flow map, roles, regions, and processor inventory. |
| Incident handling | Audit logs, owner contacts, notification workflow, and exportable event records. |
| Continuity | Backup/restore plan, restore testing, and documented recovery ownership. |
| Supply chain | Pinned components, deployment evidence, and sub-processor review. |
| Cryptography | TLS, encryption-at-rest posture, and customer-managed key custody planning. |