xsenv

NIS2, measure by measure.

NIS2 asks essential and important entities for ten kinds of security measures and for fast incident reports. xsenv carries out five of the measures for everything it runs, and gives you evidence for three more. It does not make you compliant: nobody can sell that. Here is exactly where the line falls.

MeasurexsenvWhat xsenv doesWhat stays yours
(a) Risk analysis and security policiesArticle 21(2): policies on risk analysis and information system security Yours An always-current inventory of people, devices, servers and assets, and documentation of every part of the platform, to start the analysis from. The analysis and the policies themselves.
(b) Incident handlingArticle 21(2): incident handling Gives evidence Detection: security events from every machine checked against rules, a person on call alerted, every event kept 90 days on your servers so an incident can be reconstructed. Deciding and responding in your business, and reporting to the authority.
(c) Business continuityArticle 21(2): backup management, disaster recovery and crisis management Carries out Two nodes and a witness, so losing any one machine stops nothing. Encrypted backups in another location, restore-tested. Failover tested by cutting power. The whole environment rebuildable from code, credentials and backups. Crisis management, and the continuity of your other systems.
(d) Supply chain securityArticle 21(2): security aspects of the relationships with direct suppliers and service providers Gives evidence Third-party components are upstream open source, pinned to exact versions; our own software is built reproducibly and signed. A handover package lets you run everything without us. Assessing your suppliers, us included. We give you what that assessment needs.
(e) Maintenance and vulnerability handlingArticle 21(2): security in acquisition, development and maintenance, including vulnerability handling and disclosure Carries out Updates to the operating system and every component, with reboots one machine at a time at night. Every running component scanned for known vulnerabilities each night. Your own applications and their development.
(f) Assessing effectivenessArticle 21(2): policies and procedures to assess the effectiveness of the measures Gives evidence Failover tests, restore tests, port scans and the alert history, as evidence for your reviews. The assessment itself, and your audits.
(g) Cyber hygiene and trainingArticle 21(2): basic cyber hygiene practices and cybersecurity training Yours Hygiene enforced where software can: no sign-in with a password alone, a vault for every person, devices that belong to whoever signed in on them. Training your people.
(h) Cryptography and encryptionArticle 21(2): policies and procedures on cryptography and encryption Carries out Traffic between machines and devices inside WireGuard, TLS on every service, encrypted backups, password vaults encrypted on each person's own devices. Your policy, and encryption in your own applications.
(i) Access control and asset managementArticle 21(2): human resources security, access control policies and asset management Carries out One sign-in for people and applications, groups that decide what each person reaches on the network, every access recorded, and an inventory of every device. Hiring, roles and the rest of the human-resources side.
(j) Multi-factor authenticationArticle 21(2): multi-factor or continuous authentication, secured communications Carries out Every person signs in with a passkey or a hardware security key. A password alone is never enough. Secured voice, video and chat, which xsenv does not provide.

Reporting an incident in time.

A significant incident must reach the authority three times: an early warning within 24 hours, a notification within 72 hours, and a final report within one month. The hard part is knowing early and knowing what happened. The SIEM alerts a person on call when something looks wrong and keeps the trail on your servers: who signed in from where, which device connected, what changed. The report is yours to make; we help you read the trail.

In Romania.

NIS2 became law through emergency ordinance OUG 155/2024, in force since December 2024 and approved by Law 124/2025. The single competent authority is DNSC, the National Cyber Security Directorate: entities register with it, report incidents to it, and are supervised by it.

If you make connected products.

The Cyber Resilience Act (Regulation (EU) 2024/2847) obliges manufacturers to report actively exploited vulnerabilities and severe incidents from 11 September 2026, and applies in full from 11 December 2027. xsenv does not certify products. It can keep the management of a fleet of Linux devices off the public internet, on your private network with access rules of their own, and bring their events into your SIEM.

Sources.