NIS2 active defense
A cornerstone for EU essential and important entities: how Threxen’s NIS2-aligned tenants run operational resilience as a workload, satisfy the 24-hour / 72-hour / one-month reporting cadence, and keep the supply-chain surface auditable.
NIS2 — Directive (EU) 2022/2555 — recasts the earlier NIS Directive and obligates essential and important entities in sectors ranging from energy and transport to health and digital infrastructure. Article 21(2) sets ten risk-management measures (a–j): policies on risk analysis and IS security (a), incident handling (b), business continuity and crisis management (d, including backup), supply-chain security (e), vulnerability handling and disclosure (f), cryptography and encryption (g), and human resources security and access control (j, c). Article 23 sets reporting — an early warning within 24 hours of awareness, an incident notification within 72 hours, and a final report within one month. A Threxen tenant pinned to the NIS2 pack under /app/settings/policy cites Art. 21(2)(b) incident handling as the live policy the agents act on, and emits the same sealed packet at every reporting boundary.
The cross-border delegation under NIS2 differs from DORA: a Threxen tenant that resolves to an incident touching multiple Member States routes the packet via the national CSIRT or single point of contact (Article 23 reads as a national incident-reporting cadence, not as a cross-border regulator one), and sectoral escalation is named in the same packet via Art. 24(2) crisis management. Supply-chain security under Art. 21(2)(e) is the surface where the decoy-fingerprinted tooling names its origin; the assessor reads the same chain the regulator reads.
Active-defense containment under NIS2 reduces to the obligations an ENISA-aligned reviewer looks for: Art. 21(2)(f) vulnerability handling drives decoy-surface attribution, Art. 21(2)(g) cryptography drives per-tenant key envelopes, and Art. 23 reporting drives packet-sealing cadence. The packet above is the same one across all five packs — an analyst who has seen a DORA packet reads an NIS2 packet — and the article → control mapping is at /resources/sector-coverage.
Read this regulator alongside its four peers.
The same four capabilities — host isolation, live credential poisoning, decoy surface, and the hash-chained evidence packet — are mapped onto each named article, requirement, or control of every regulated framework Threxen ships a policy pack for. The comparison matrix is the single page that lays them side by side.
▸ four sibling pillars · one matrix page · biometric-style read-across without re-reading five essays · security & compliance posture on the trust center