Compliance pack · operator-support

NIS2 evidence, collected where releases happen

The NIS2 pack turns evidence your releases already produce into artefacts a supervisor can inspect: a control register, a Statement of Applicability, live effectiveness metrics, and an asset registry. Stella Ops never files and never certifies.

Directive (EU) 2022/2555. Member states had to apply their transposing measures from 18 October 2024; transposition is still ongoing across the EU. For digital-infrastructure and other listed sectors, Implementing Regulation (EU) 2024/2690 details the risk-management measures — its 13 thematic areas are the structure used below.

Product status: v1.0-RC1, release candidate.

Claim boundary

Enabling starts evidence collection in conservative evidence-only mode; it does not claim regulatory compliance.

The operator always remains the regulated decision-maker.

Pack ownership label: operator-support. Stella Ops helps an obligated operator assemble and sign the artefacts a regulator wants. It never files, never certifies, and never makes you compliant.

Stella Ops Compliance workspace showing NIS2, DORA, and CRA pack cards with retention windows and the evidence priority queue
The Compliance workspace in the Stella Ops console, shown with demo data. Packs configure retention and the evidence priority queue; they never change scan results.

What the pack ships

Five artefacts, all built from the same evidence chain that gates your releases. None of them is a separate compliance database you feed by hand.

Control register

Author, publish, and persist NIS2 controls. Every state change lands in a regulatory ledger, so an auditor sees who changed what, and when.

Statement of Applicability export

One signed, deterministic bundle covering all 13 thematic areas. The export has a hard completeness gate: an incomplete SoA is refused, not papered over.

Effectiveness KPI telemetry

31 live metrics across the 13 areas. Values come from the evidence chain, not from self-assessment forms.

Asset registry with event history

Every service, environment, and image digest in scope, with the events behind it. An asset with no events behind it is listed as such.

Per-tenant compliance profile

Each tenant carries its own pack configuration, retention windows, and SoA state. One installation, separate regulatory postures.

Coverage across the 13 thematic areas

Implementing Regulation (EU) 2024/2690 lays out 13 thematic areas for the entity types it covers; the same areas are a useful checklist for any NIS2 programme. Stella Ops is strong where the evidence is technical, partial where the measure is an operator process, and out of scope where software cannot help.

  • Evidence-strong The platform produces the primary evidence itself.
  • Procedural / partial Stella records and exports; the measure itself remains an operator process.
  • Out of scope Out of product scope by design. You attach your own measures; the SoA completeness gate still requires an entry.
#Thematic area (Annex, Impl. Reg. 2024/2690)CoverageWhat Stella Ops provides
1Policy on the security of network and information systemsProcedural / partialThe control register versions and publishes your policy. Writing and operating it is your act.
2Risk management policyProcedural / partialVerdicts, exceptions, and unknowns budgets supply risk inputs. The methodology and acceptance decisions are yours.
3Incident handlingProcedural / partialArticle-23 deadline state machine and CSIRT envelope exist. The operator-facing write path is in progress - see below.
4Business continuity and crisis managementProcedural / partialRunbook-level evidence: what ran where, and when. Stella Ops is not a business-continuity tool.
5Supply chain securityEvidence-strongDigest pinning, provenance attestations, and a tamper-evident ledger. This is the core of the platform.
6Security in acquisition, development and maintenanceEvidence-strongScan-to-Verdict evidence, reachability-aware vulnerability handling, VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context statements, and fix tracking.
7Policies to assess the effectiveness of risk-management measuresProcedural / partial31 KPI metrics feed the assessment. The assessment procedure remains an operator process.
8Basic cyber hygiene practices and security trainingOut of scopeOut of scope. A release control plane should not claim your training programme.
9CryptographyEvidence-strongSigning policy evidence, key inventory, and a post-quantum readiness assessment. Assessment only - Stella Ops does not sign with post-quantum algorithms.
10Human resources securityOut of scopeOut of scope. Vetting and employment controls are not software claims.
11Access controlEvidence-strongRole and scope evidence from the platform's own authorization model. Access changes land in the ledger.
12Asset managementEvidence-strongAsset registry with event history. Identity is digest-first, so an asset cannot silently change under the same name.
13Environmental and physical securityOut of scopeOut of scope. Stella Ops cannot see your server room.

The three out-of-scope areas still count against the Statement of Applicability. You record your own measures for them; the completeness gate refuses to export a bundle with any of the 13 areas left blank.

Incident reporting under Article 23

NIS2 sets three clocks per significant incident: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. The pack tracks these clocks. It does not submit for you yet.

Shipped

  • Deadline state machine - the 24-hour, 72-hour, and one-month clocks run per incident, with Notify alerts before each deadline.
  • CSIRT envelope - a signed envelope carrying the incident facts and references to the evidence behind them.

In progress

  • Operator-facing write path - recording and updating an incident from the console is in progress.
  • Production submission client - today you deliver the envelope to your CSIRT yourself; automated submission is in progress.

Member states route reports differently. Until transposition settles, the envelope targets the evidence, not any single national portal.

Built on the same evidence primitives

The NIS2 pack adds no second evidence store. It reads what every release already writes - the same primitives every other compliance pack uses.

Custody spine

Source → Build → Scan → Verdict → Decision → Deploy → Watch. Each stage is MISSING, RECORDED, or SIGNED - absent evidence stays visible as Missing.

Evidence Locker

Retention-managed storage for the raw artefacts the SoA and KPI exports reference, including SBOM and scan records.

ExportCenter

Signed, deterministic bundles (DSSE). Same inputs yield the same bytes, so an auditor can re-verify offline.

Notify

Deadline and drift alerts, including the Article 23 clocks.

How evidence works

Talk through your NIS2 scope

Bring your estate and your supervisor's questions. We will show you which artefacts the pack produces today - and where you still need your own process.

Read technical docs