NIS2 Evidence Pack
This is the entry point for the NIS2 pack: start here, then follow the pack surfaces for the control register, Statement of Applicability export, Article 23 incident reporting, and the KPI dashboard.
The NIS2 Evidence Pack is an optional Assurance pack for customers/operators that need NIS2-oriented evidence views. Stella supplies control, evidence, export, timeline, and dashboard primitives; the customer/operator remains the regulated decision-maker.
Claim boundary: operator-support.
Primary evidence scope: operator-observed-estate.
The pack is software-estate assurance for systems Stella can monitor, deploy, scan, or control for the operator. It can package evidence from releases, container images, services, integrations, plugins, host agents, policy gates, SBOM/VEX, reachability, and EvidenceLocker bundles. Legal entity classification, governance ownership, physical security, HR/training, business-continuity process evidence, and non-Stella supplier contracts remain operator-supplied.
Pack Surfaces
| Surface | Purpose |
|---|---|
| Control register | Map Policy controls and evidence references to the NIS2 Article 21/Implementing Regulation thematic areas. |
| Statement of Applicability export | Produce signed, deterministic SoA evidence bundles for operator-controlled review or handoff. |
| Incident reporting | Prepare Article 23 milestone envelopes and channel-specific handoff packets. |
| KPI dashboard | Track effectiveness metrics and monthly evidence across the thirteen thematic areas. |
ExportCenter Profiles
| Profile id | Purpose | Compatibility route |
|---|---|---|
nis2.statement-of-applicability | Signed NIS2 SoA evidence bundle. | GET /v1/exports/nis2/soa/profile, POST /v1/exports/nis2/soa/runs |
nis2.effectiveness-report | Signed monthly NIS2 effectiveness report bundle. | stella export nis2-effectiveness, POST /v1/exports/assurance/profiles/nis2.effectiveness-report/runs, GET /v1/exports/assurance/profiles/nis2.effectiveness-report/runs/{runId}, GET /v1/exports/assurance/runs/{runId}/bundle |
Reporting Timeline Profiles
| Profile id | Purpose | Runtime route |
|---|---|---|
nis2.article23.incident | Article 23 incident reporting milestones over the shared Notify timeline. | GET /api/v1/assurance/reporting-timeline-profiles/nis2.article23.incident |
Source Contracts And Module Docs
- Assurance Runtime
- Assurance Scope Model
- Assurance Pack v1
- Assurance Control Register v1
- Assurance Evidence Export v1
- Assurance Reporting Timeline v1
- Assurance Setup Prerequisites v1
- Policy NIS2 control register guide
- ExportCenter architecture
- Notify NIS2 CSIRT channel
- CLI export command guide
- Stella Supplier Evidence Profile v1
Product Boundary
This pack must not say that Stella itself is a customer’s NIS2-regulated entity. It should say that Stella helps a customer maintain evidence, produce signed exports, and prepare operator-owned reporting handoffs.
Do not use this pack as legal advice, automatic regulator submission, a human resources training system, or a physical-security system of record. Tenant supplied evidence remains labelled as tenant supplied.
When Stella Ops itself is part of the customer’s software estate, the stella.supplier-evidence profile may be attached as supplier evidence. That profile does not make Stella the customer’s NIS2-regulated entity.
Change Log
| Date (UTC) | Update |
|---|---|
| 2026-06-16 | Reconciled the pack to verified src/ state. SHIPPED & verified: control register, SoA export (with the 422 SOA_INCOMPLETE completeness gate), KPI telemetry (31 metrics / 13 areas), and asset registry. The remaining real gap is Article 23 incident reporting — no operator write endpoints and no production CSIRT submission client (only a test stub) — detailed in incident-reporting.md. Per-surface status notes added to each pack page. Claim boundary unchanged (operator-support). |
