NIS2 Evidence Pack

This is the entry point for the NIS2 pack: start here, then follow the pack surfaces for the control register, Statement of Applicability export, Article 23 incident reporting, and the KPI dashboard.

The NIS2 Evidence Pack is an optional Assurance pack for customers/operators that need NIS2-oriented evidence views. Stella supplies control, evidence, export, timeline, and dashboard primitives; the customer/operator remains the regulated decision-maker.

Claim boundary: operator-support.

Primary evidence scope: operator-observed-estate.

The pack is software-estate assurance for systems Stella can monitor, deploy, scan, or control for the operator. It can package evidence from releases, container images, services, integrations, plugins, host agents, policy gates, SBOM/VEX, reachability, and EvidenceLocker bundles. Legal entity classification, governance ownership, physical security, HR/training, business-continuity process evidence, and non-Stella supplier contracts remain operator-supplied.

Pack Surfaces

SurfacePurpose
Control registerMap Policy controls and evidence references to the NIS2 Article 21/Implementing Regulation thematic areas.
Statement of Applicability exportProduce signed, deterministic SoA evidence bundles for operator-controlled review or handoff.
Incident reportingPrepare Article 23 milestone envelopes and channel-specific handoff packets.
KPI dashboardTrack effectiveness metrics and monthly evidence across the thirteen thematic areas.

ExportCenter Profiles

Profile idPurposeCompatibility route
nis2.statement-of-applicabilitySigned NIS2 SoA evidence bundle.GET /v1/exports/nis2/soa/profile, POST /v1/exports/nis2/soa/runs
nis2.effectiveness-reportSigned monthly NIS2 effectiveness report bundle.stella export nis2-effectiveness, POST /v1/exports/assurance/profiles/nis2.effectiveness-report/runs, GET /v1/exports/assurance/profiles/nis2.effectiveness-report/runs/{runId}, GET /v1/exports/assurance/runs/{runId}/bundle

Reporting Timeline Profiles

Profile idPurposeRuntime route
nis2.article23.incidentArticle 23 incident reporting milestones over the shared Notify timeline.GET /api/v1/assurance/reporting-timeline-profiles/nis2.article23.incident

Source Contracts And Module Docs

Product Boundary

This pack must not say that Stella itself is a customer’s NIS2-regulated entity. It should say that Stella helps a customer maintain evidence, produce signed exports, and prepare operator-owned reporting handoffs.

Do not use this pack as legal advice, automatic regulator submission, a human resources training system, or a physical-security system of record. Tenant supplied evidence remains labelled as tenant supplied.

When Stella Ops itself is part of the customer’s software estate, the stella.supplier-evidence profile may be attached as supplier evidence. That profile does not make Stella the customer’s NIS2-regulated entity.

Change Log

Date (UTC)Update
2026-06-16Reconciled the pack to verified src/ state. SHIPPED & verified: control register, SoA export (with the 422 SOA_INCOMPLETE completeness gate), KPI telemetry (31 metrics / 13 areas), and asset registry. The remaining real gap is Article 23 incident reporting — no operator write endpoints and no production CSIRT submission client (only a test stub) — detailed in incident-reporting.md. Per-surface status notes added to each pack page. Claim boundary unchanged (operator-support).