Recent Breaches
Breaches
2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen
View All →
Glowing EU regulatory shield surrounded by floating compliance documents
NIS2

Physical Compliance with NIS2 Directive Requirements

NIS2 requires essential and important entities to implement appropriate technical measures for network security, access control, and incident handling. Control provides physical enforcement that demonstrably exceeds directive requirements.

Back to Control

Key threats addressed

Configuration drift in firewallsUnverifiable segmentationPersonal management liabilitySlow incident notificationGaps between point-in-time audits

Overview

Continuous physical evidence for Article 21.

NIS2 raises the bar from configured controls to demonstrably effective controls, with personal accountability at board level. Control replaces software-only segmentation with hardware-enforced zone boundaries and produces continuous, signed evidence of separation, access governance and incident handling that auditors can verify directly.

NIS2

NIS2 requires appropriate and proportionate measures. For essential services that underpin national infrastructure, appropriate means physical, not just logical.

Art. 21

Full Article 21 requirements coverage

100%

Physical network segmentation enforcement

24hr

Incident notification capability support

Full

Automated compliance evidence generation

The Compliance Challenge

NIS2 demands demonstrable security measures.

Proportionate Measures

NIS2 requires measures proportionate to the risk. For essential services, this means demonstrating that security measures go beyond standard software controls.

Network Segmentation

Article 21 requires network segmentation, but many organisations rely on VLAN-based separation that can be bypassed through misconfiguration.

Management Accountability

NIS2 introduces personal liability for management bodies. Demonstrating appropriate measures requires evidence that goes beyond compliance checklists.

Pain points

  • Firewall rule sets drift between audits, leaving unmonitored gaps in segmentation.
  • VLAN-based separation cannot be evidenced as continuously effective.
  • Incident reporting timelines collapse without out-of-band recovery infrastructure.
  • Boards face personal liability and need verifiable proof, not policy attestations.

The Scenario

Scenario: NIS2 Audit with Physical Evidence

An essential entity faces its first NIS2 compliance audit. The assessor examines network segmentation controls and finds that existing firewall-based segmentation, while configured correctly today, has experienced three misconfiguration incidents in the past year that temporarily created paths between zones. Each incident violated NIS2 requirements for the duration it existed. The organisation cannot demonstrate continuous compliance. With Control, the organisation presents physical zone boundary evidence showing continuous, unbroken zone separation. Conduit activations are logged with multi-party authorisation records. The assessor can verify that physical boundaries were maintained at all times, providing evidence of continuous compliance.

"Our auditor asked us to prove that our network segmentation had been continuously effective for the past twelve months. With firewall logs, we could show configuration at a point in time. We could not prove there had been no gaps between audits."

NIS2 mapping

Where NIS2 Article 21 measures meet Control modules.

NIS2 Article 21 names the measures essential and important entities must implement. Control provides the physical enforcement layer that turns those measures into evidence rather than intent.

Reference: Directive (EU) 2022/2555 (NIS2), Article 21(2)(a) to (j), with cross-reference to NCSC CAF outcomes.

SEC 01

Risk and security policies (Art. 21(2)(a)-(b))

  • 21(2)(a)

    Risk analysis and information security policies

    Continuous attestation of conduit state provides the evidence behind the policy.

    FV-Validate module iconValidateFV-Archive module iconArchive
  • 21(2)(b)

    Incident handling

    Firebreak severs governed conduits on alert; restoration is an evidenced Execute event.

    FV-Firebreak module iconFirebreakFV-Execute module iconExecute
SEC 02

Continuity and supply chain (Art. 21(2)(c)-(d))

  • 21(2)(c)

    Business continuity and crisis management

    Offline recovery copies remain reachable even when the live network is gone.

    FV-Archive module iconArchiveFV-Transfer module iconTransfer
  • 21(2)(d)

    Supply chain security

    Vendor reach is severed by default and opened only as a time-bound, scoped session.

    FV-Firebreak module iconFirebreakFV-Relay module iconRelayFV-Lock module iconLock
SEC 03

Acquisition, development, vulnerability (Art. 21(2)(e)-(f))

  • 21(2)(e)

    Security in acquisition, development, and maintenance

    Maintenance windows are governed Relay sessions with multi-party approval.

    FV-Relay module iconRelayFV-Execute module iconExecute
  • 21(2)(f)

    Effectiveness of measures

    Validate provides continuous, signed evidence that boundaries hold.

    FV-Validate module iconValidate
SEC 04

Hygiene, cryptography, access (Art. 21(2)(g)-(i))

  • 21(2)(g)

    Cyber hygiene and training

    Named access removes shared, evergreen credentials from the workflow.

    FV-Lock module iconLockFV-Unlink module iconUnlink
  • 21(2)(i)

    Human resources security and access control

    Trust is revoked at the boundary when relationships end.

    FV-Unlink module iconUnlinkFV-Lock module iconLock
SEC 05

Authentication and communications (Art. 21(2)(j))

  • 21(2)(j)

    Multi-factor and secured communications

    Cross-zone reach uses named, scoped, time-bound conduits.

    FV-Lock module iconLockFV-Relay module iconRelayFV-Isolate module iconIsolate

Modules & symbols

FV-Validate module iconValidateIntegrity check
FV-Archive module iconArchiveDisconnected copy
FV-Firebreak module iconFirebreakPhysical sever
FV-Execute module iconExecuteApproved action
FV-Transfer module iconTransferControlled move
FV-Relay module iconRelayTime-bound path
FV-Lock module iconLockNamed access
FV-Unlink module iconUnlinkRemove trust
FV-Isolate module iconIsolateZone boundary
Direct mapModule satisfies clause

Featured In

TechRadar Pro logoSecurity Buyer logoYahoo Finance logoSecurityBrief logoChannel Insider logo

Key Capabilities

EU Data Sovereignty

Data residency within UK and EU jurisdictions supports NIS2 requirements for appropriate data handling and sovereignty.

Management Accountability

Documented multi-party authorisation and governance processes demonstrate management oversight required by Article 20.

Continuous Evidence

Automated compliance logging generates continuous NIS2 evidence, eliminating gaps between point-in-time assessments.

Incident Response

Physical zone isolation capabilities support the rapid incident containment required by NIS2 notification timelines.

Audit-Ready Records

Tamper-proof logs provide complete audit trails for every network boundary state, access authorisation, and incident response action.

Recovery Assurance

Verified control-plane baselines demonstrate business continuity capability that exceeds NIS2 operational restoration requirements.

Demo to Live

Adoption Guide

Step 1

NIS2 Gap Assessment

Map your current security measures against NIS2 Article 21 requirements to identify where physical enforcement strengthens your compliance position.

Step 2

Compliance Architecture Design

Design physical zone boundaries and access controls that satisfy and exceed NIS2 requirements for your entity classification.

Step 3

Evidence Validation

Deploy Control in a representative environment to validate compliance evidence generation and prepare for your first NIS2 assessment.

Step 4

Full Compliance Deployment

Organisation-wide deployment with continuous compliance evidence, multi-party governance, and verified control-plane baseline assurance.

Step 1

NIS2 Gap Assessment

Map your current security measures against NIS2 Article 21 requirements to identify where physical enforcement strengthens your compliance position.

Step 2

Compliance Architecture Design

Design physical zone boundaries and access controls that satisfy and exceed NIS2 requirements for your entity classification.

Step 3

Evidence Validation

Deploy Control in a representative environment to validate compliance evidence generation and prepare for your first NIS2 assessment.

Step 4

Full Compliance Deployment

Organisation-wide deployment with continuous compliance evidence, multi-party governance, and verified control-plane baseline assurance.

Questions

Frequently Asked

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy