Compliance pack · operator-support
NIS2 evidence, collected where releases happen
The NIS2 pack turns evidence your releases already produce into artefacts a supervisor can inspect: a control register, a Statement of Applicability, live effectiveness metrics, and an asset registry. Stella Ops never files and never certifies.
Directive (EU) 2022/2555. Member states had to apply their transposing measures from 18 October 2024; transposition is still ongoing across the EU. For digital-infrastructure and other listed sectors, Implementing Regulation (EU) 2024/2690 details the risk-management measures — its 13 thematic areas are the structure used below.
Product status: v1.0-RC1, release candidate.
Claim boundary
Enabling starts evidence collection in conservative evidence-only mode; it does not claim regulatory compliance.
The operator always remains the regulated decision-maker.
Pack ownership label: operator-support. Stella Ops helps an obligated operator assemble and sign the artefacts a regulator wants. It never files, never certifies, and never makes you compliant.

What the pack ships
Five artefacts, all built from the same evidence chain that gates your releases. None of them is a separate compliance database you feed by hand.
Control register
Author, publish, and persist NIS2 controls. Every state change lands in a regulatory ledger, so an auditor sees who changed what, and when.
Statement of Applicability export
One signed, deterministic bundle covering all 13 thematic areas. The export has a hard completeness gate: an incomplete SoA is refused, not papered over.
Effectiveness KPI telemetry
31 live metrics across the 13 areas. Values come from the evidence chain, not from self-assessment forms.
Asset registry with event history
Every service, environment, and image digest in scope, with the events behind it. An asset with no events behind it is listed as such.
Per-tenant compliance profile
Each tenant carries its own pack configuration, retention windows, and SoA state. One installation, separate regulatory postures.
Coverage across the 13 thematic areas
Implementing Regulation (EU) 2024/2690 lays out 13 thematic areas for the entity types it covers; the same areas are a useful checklist for any NIS2 programme. Stella Ops is strong where the evidence is technical, partial where the measure is an operator process, and out of scope where software cannot help.
- Evidence-strong The platform produces the primary evidence itself.
- Procedural / partial Stella records and exports; the measure itself remains an operator process.
- Out of scope Out of product scope by design. You attach your own measures; the SoA completeness gate still requires an entry.
| # | Thematic area (Annex, Impl. Reg. 2024/2690) | Coverage | What Stella Ops provides |
|---|---|---|---|
| 1 | Policy on the security of network and information systems | Procedural / partial | The control register versions and publishes your policy. Writing and operating it is your act. |
| 2 | Risk management policy | Procedural / partial | Verdicts, exceptions, and unknowns budgets supply risk inputs. The methodology and acceptance decisions are yours. |
| 3 | Incident handling | Procedural / partial | Article-23 deadline state machine and CSIRT envelope exist. The operator-facing write path is in progress - see below. |
| 4 | Business continuity and crisis management | Procedural / partial | Runbook-level evidence: what ran where, and when. Stella Ops is not a business-continuity tool. |
| 5 | Supply chain security | Evidence-strong | Digest pinning, provenance attestations, and a tamper-evident ledger. This is the core of the platform. |
| 6 | Security in acquisition, development and maintenance | Evidence-strong | Scan-to-Verdict evidence, reachability-aware vulnerability handling, VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context statements, and fix tracking. |
| 7 | Policies to assess the effectiveness of risk-management measures | Procedural / partial | 31 KPI metrics feed the assessment. The assessment procedure remains an operator process. |
| 8 | Basic cyber hygiene practices and security training | Out of scope | Out of scope. A release control plane should not claim your training programme. |
| 9 | Cryptography | Evidence-strong | Signing policy evidence, key inventory, and a post-quantum readiness assessment. Assessment only - Stella Ops does not sign with post-quantum algorithms. |
| 10 | Human resources security | Out of scope | Out of scope. Vetting and employment controls are not software claims. |
| 11 | Access control | Evidence-strong | Role and scope evidence from the platform's own authorization model. Access changes land in the ledger. |
| 12 | Asset management | Evidence-strong | Asset registry with event history. Identity is digest-first, so an asset cannot silently change under the same name. |
| 13 | Environmental and physical security | Out of scope | Out of scope. Stella Ops cannot see your server room. |
The three out-of-scope areas still count against the Statement of Applicability. You record your own measures for them; the completeness gate refuses to export a bundle with any of the 13 areas left blank.
Incident reporting under Article 23
NIS2 sets three clocks per significant incident: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. The pack tracks these clocks. It does not submit for you yet.
Shipped
- Deadline state machine - the 24-hour, 72-hour, and one-month clocks run per incident, with Notify alerts before each deadline.
- CSIRT envelope - a signed envelope carrying the incident facts and references to the evidence behind them.
In progress
- Operator-facing write path - recording and updating an incident from the console is in progress.
- Production submission client - today you deliver the envelope to your CSIRT yourself; automated submission is in progress.
Member states route reports differently. Until transposition settles, the envelope targets the evidence, not any single national portal.
Built on the same evidence primitives
The NIS2 pack adds no second evidence store. It reads what every release already writes - the same primitives every other compliance pack uses.
Custody spine
Source → Build → Scan → Verdict → Decision → Deploy → Watch. Each stage is MISSING, RECORDED, or SIGNED - absent evidence stays visible as Missing.
Evidence Locker
Retention-managed storage for the raw artefacts the SoA and KPI exports reference, including SBOM and scan records.
ExportCenter
Signed, deterministic bundles (DSSE). Same inputs yield the same bytes, so an auditor can re-verify offline.
Notify
Deadline and drift alerts, including the Article 23 clocks.
Talk through your NIS2 scope
Bring your estate and your supervisor's questions. We will show you which artefacts the pack produces today - and where you still need your own process.
