50 engineering protocols observed directly from your repos and trackers — mapped to all 10 Article 21(2) measures. Real data from your actual toolchain, not questionnaires.
Run Free NIS2 Scan →Concordance observes 50 engineering protocols from your GitHub repos and issue trackers, then maps them to the 10 measures of NIS2 Article 21(2). It reports what it finds — not whether you comply. Compliance decisions rest with your organisation and the relevant national competent authority.
Measure (j) — MFA and secured communications — is outside engineering signal scope. Measures covering organisational policies, HR, physical security, and supplier assessment require evidence beyond what repositories provide.
The NIS2 Directive (EU 2022/2555) is the EU's updated network and information security framework. It expands scope to cover more sectors and imposes stricter cybersecurity requirements on essential and important entities.
Article 21(2) defines 10 minimum risk management measures. These range from risk analysis and incident handling to supply chain security and SDLC practices. Across the EU, national legislation will transpose NIS2 into law, bringing thousands of essential and important entities into scope.
NIS2 is not a certification — there is no audit or certificate to obtain. It's a regulatory obligation: essential and important entities must implement cybersecurity risk-management measures and be prepared for supervision by their national competent authority. Concordance provides continuous evidence mapping — engineering data from your toolchain, structured against Article 21(2) measures, ready when a competent authority asks to see it.
Point Concordance at any public repo. See all 50 protocol scores mapped to Article 21(2) measures. Free, instant, no sign-up.
Read-only OAuth. Create your teams, add your repos. Portfolio view surfaces NIS2-mapped evidence across every team in the org.
NIS2 requires ongoing risk management. Concordance scans continuously, so your evidence mapping stays current. Practices degrade? You see it before anyone asks.
When a competent authority asks what your engineering practices look like, the data is already structured. Per-team, per-measure, mapped to Article 21(2) measures, CyFun tiers, and NIST CSF v2.0 functions.
Scan any public repo. See all 50 protocol scores mapped through the NIS2 lens. Understand what engineering data maps to Article 21(2) on a single repo.
Up to 5 teams, 20 repos. Continuous observation. NIS2 evidence mapping across every team. Plus SOC 2, ISO 27001, Sentinel, and Bastion lenses.
Try a free sample scan on any public repo. When you're ready for org-wide evidence, the NIS2 Signal lens is included with Concordance Pro.