⚓ Running on beta — hold tight, things may still shake.

EU NIS2 Directive

NIS2 Article 21(2)(e) evidence, without the week-before-audit scramble

Article 21(2)(e) requires cybersecurity risk-management measures covering security in the acquisition, development, and maintenance of network and information systems — including vulnerability handling and disclosure. Regulators and auditors testing this want a documented, ongoing process, not a policy document that's never actually been followed.

What "essential" and "important" entities need to show

NIS2 applies to a broad range of essential and important entities across the EU, and vulnerability handling is one of the ten baseline measures explicitly named in Article 21(2). In practice, that means being able to show:

  • • Ongoing monitoring for newly disclosed vulnerabilities affecting the systems you actually operate.
  • • A consistent process for handling what's found — not an ad hoc reaction each time something surfaces.
  • • A record of who assessed each vulnerability, what they decided, and when.
  • • Reporting that can be produced for a supervisory authority on request, covering a specific period.

Given NIS2's penalty regime and the tight incident-reporting timelines elsewhere in the directive, "we'll figure it out if asked" is a much riskier position here than it is for SOC 2 or ISO 27001.

How TrawlSec generates this evidence

TrawlSec monitors NVD and EUVD — ENISA's own EU vulnerability database, launched under NIS2 — plus any custom feeds you add, matched against the assets you tell it you run. Every finding gets a logged disposition: confirmed, ignored, or false positive, with who made the call and why.

Closing a review period locks that record in and exports into a report scoped to the window a supervisory authority is asking about — the handling process becomes the evidence, automatically.

See it before you sign up

The live demo has sample findings, a review queue, and a real generated PDF report — no account required.

View live demo