NIS2 compliance for cloud infrastructure — make your architecture audit-ready

Open-source Cozystack (a CNCF project we create and maintain) Ænix Platform, the supported commercial distribution Aenix builds, operates and migrates it.

NIS2 compliance for cloud infrastructure means aligning your platform architecture with the EU NIS2 Directive (EU 2022/2555), which imposes cybersecurity risk-management (Article 21), incident reporting at 24-hour, 72-hour, and one-month timelines (Article 23), and ICT supply-chain risk obligations on essential and important entities and the ICT third parties serving them. Aenix runs NIS2-aligned platform readiness engagements that produce a control-level map, supply-chain mapping to the second hop, an incident-detection capability assessment, and an architecture-level remediation plan, delivered by EU-based engineers. The Aenix Private Cloud Platform is NIS2-aligned by design, built on Cozystack — an Apache 2.0, CNCF project providing Tenant CRD multi-tenancy, Cilium (eBPF) segmentation, customer-controlled encryption, and audit-ready logging.

Quick facts

  • What it is A NIS2-aligned platform readiness engagement that maps your cloud architecture against the EU NIS2 Directive (EU 2022/2555) and produces an architecture-level remediation plan.
  • License Apache 2.0 (no per-CPU / per-core licensing)
  • Status Cozystack is a CNCF project (Sandbox since 2025-02-28; Incubating expected late summer 2026)
  • Who it is for Essential and important entities (energy, transport, banking, healthcare, digital infrastructure, public administration, and more) plus the ICT third parties serving them.
  • Engagement timeline 14-day focused NIS2 variant, or 28-day variant mapping NIS2 + DORA + GDPR in one engagement.
  • Standard covered NIS2 Directive (EU) 2022/2555 — Articles 20 (management-body accountability), 21 (risk-management measures, incl. supply-chain security at 21(2)(d)), 23 (incident reporting), and 12 (coordinated vulnerability disclosure).
  • Key capability Cozystack delivers Tenant CRD multi-tenancy, Cilium/NetworkPolicy segmentation, customer-controlled keys, air-gap support, and full audit trails — sovereignty by architecture.

The NIS2 Directive (EU 2022/2555) is in transposition across EU member states with deadlines that have already passed for many. For essential and important entities — energy, transport, banking, financial market infrastructures, healthcare, drinking water, digital infrastructure, public administration, postal, waste, ICT services, and several other sectors — NIS2 imposes specific cybersecurity and incident-management requirements that map directly to cloud architecture.

Ænix runs NIS2-aligned platform readiness engagements for in-scope entities and the ICT third parties serving them. Output: a control-level map of where you stand today, where the gaps are, and what an architecture-level remediation plan looks like.

Pairs with: Ænix Private Cloud Platform — NIS2-aligned by design (Art. 21 risk-management measures, Art. 23 incident reporting, Art. 12 coordinated vulnerability disclosure). Tenant CRD with NetworkPolicy / Cilium for segmentation, customer-controlled encryption, audit-ready logging. Free NIS2 Compliance Checklist →.

EU-based engineers · Mutual NDA · No hyperscaler bias · Written deliverables

Who has NIS2 in scope

The measured evidence behind these controls — full CIS Kubernetes Benchmark results, Kubernetes conformance listings, and a plain statement of what Aenix does and does not claim — lives on the compliance evidence pages. Nothing there is a certification; it is the run output and the reasoning, published so an assessor can check it.

NIS2 applies broadly to:

  • Essential entities — energy, transport, banking, financial market infrastructures, healthcare, drinking water, wastewater, digital infrastructure (IXPs, DNS, TLD, cloud providers, datacenter providers, CDN, MSPs, MSSPs, public electronic comms), public administration, space.
  • Important entities — postal, waste management, chemical, food, manufacturing of critical products, digital service providers (online marketplaces, search engines, social platforms), R&D.
  • ICT third parties serving in-scope entities.

If your sector is in scope or your customers are in scope, NIS2 architectural requirements apply.


What NIS2 requires of cloud architecture

1. Risk management measures (Article 21) Documented cybersecurity risk-management practices covering policies on risk analysis, ICT asset management, incident handling, business continuity, supply chain security, vulnerability handling, security in network/IS acquisition.

2. Incident reporting (Article 23) Incidents reported to CSIRT/competent authority within 24 hours (early warning), 72 hours (incident notification), and one month (final report). Architecture must support detection and reporting at these timelines.

3. Supply-chain security (Article 21(2)(d)) Risk-management measures must cover the security of the supply chain, including the relationships between the entity and its direct suppliers and service providers. In practice that means supplier mapping, exit readiness, and supplier monitoring — not a questionnaire on file.

4. Management-body accountability (Article 20) Management bodies must approve the risk-management measures, oversee their implementation, and follow cybersecurity training — and can be held liable for failure to do so. Compliance is not delegated entirely to technical teams.

For control-level checklist, see the NIS2 requirements article.


Where most cloud setups fail NIS2 audit

Incident detection too slow for 24-hour deadline Detection requires telemetry and monitoring tuned to recognize the kinds of events NIS2 considers reportable. Most cloud setups have observability for performance, not for incident detection at NIS2 timelines.

ICT supply chain mapped only to first hop NIS2 requires visibility into the supply chain for critical-function ICT third parties. Most organizations cannot enumerate beyond their direct vendors.

Backup and BCP works on paper, not in drill NIS2 requires business continuity. Most BCP plans are documents that have never been tested under realistic failure scenarios.

Vulnerability management is reactive Patch cycles run on monthly cadence; critical vulnerabilities get emergency patches. NIS2 expects more proactive vulnerability handling for critical infrastructure.


How Ænix helps

NIS2 obligations
Art. 21 risk-management measuresArt. 23 incident reportingArt. 21(2)(d) supply-chain security
mapped control-by-control by
Ænix engagement on Cozystack
Tenant CRD multi-tenancyCilium/NetworkPolicy segmentationCustomer-controlled keysAudit-ready logging
produces
Audit-ready architecture
Architecture-level remediation plan

The NIS2 engagement runs as part of our Platform Readiness Assessment with sovereignty + regulator-gap workstream emphasized. The 14- or 28-day engagement produces:

  • NIS2 control-level map — control-by-control review of what your architecture demonstrates
  • Supply chain mapping — to second hop for critical-function ICT third parties
  • Incident detection and reporting capability assessment — telemetry and processes against the 24/72-hour/one-month timelines
  • Business continuity and vulnerability management posture
  • Architecture-level remediation plan

Delivered by EU-based engineers with regulator-dialog experience. Same engineers also run DORA compliance — the 28-day variant maps both regulators in one engagement.


Why Ænix specifically

  • EU-based engineers with experience inside the same regulatory frameworks as your customers.
  • No hyperscaler bias. Recommendations reflect technical fit and regulatory alignment, not partnership economics.
  • Open-source platform foundation. Cozystack supports air-gap, customer-controlled keys, full audit trails — sovereignty-by-architecture.
  • Cross-regulator engagement — DORA + NIS2 + GDPR mapped together in 28-day variant.

WhenWhatOutput
Day 030-min discovery call (free)Confirm fit, narrow NIS2 scope (which sectors / which obligations)
Days 1-13 (or 1-27)Sovereignty + regulator-gap workstreamDaily updates, three checkpoints
Day 14 (or 28)Executive readout (60-90 min)Written report: NIS2 control map, supply-chain map, BCP/incident posture, remediation plan


14-day (focused NIS2)

On request

28-day (NIS2 + DORA + GDPR overlay)

On request




Ænix is the team behind Cozystack — a CNCF Project, Kubernetes Certified Distribution.

Frequently asked questions

Has the NIS2 transposition deadline passed?

Yes. For most EU member states the 17 October 2024 transposition deadline has passed and competent authorities are operational. Some member states’ transpositions remain delayed, but in-scope entities should treat the obligations as live.

Is there a NIS2 certification we can obtain?

No. NIS2 is outcome-based. National cybersecurity certification schemes may be referenced in implementing rules, but there is no single NIS2 stamp or certificate to achieve.

How does NIS2 differ from DORA?

DORA is sector-specific to financial services; NIS2 is sectoral but far broader. Many entities fall under both with overlapping but not identical requirements. The 28-day Aenix engagement variant maps both regulators, plus GDPR, in a single engagement.

What does the Aenix NIS2 engagement produce?

A NIS2 control-level map, supply-chain mapping to the second hop for critical-function ICT third parties, an incident detection and reporting capability assessment against the 24/72-hour and one-month timelines, a business continuity and vulnerability management posture review, and an architecture-level remediation plan.

How does Cozystack support NIS2 requirements?

Cozystack provides Tenant CRD multi-tenancy with Cilium (eBPF) and NetworkPolicy segmentation, customer-controlled encryption keys, air-gap deployment, and full audit logging. These map to the risk-management measures listed in Article 21(2) — access control, network security, business continuity, and the telemetry that makes Article 23 reporting windows achievable — giving sovereignty by architecture rather than by add-on.

Who delivers the engagement?

EU-based engineers with experience inside the same regulatory frameworks as your customers and with regulator-dialog experience. Recommendations reflect technical fit and regulatory alignment, with no hyperscaler partnership bias.

Ready to talk?

Book a 30-minute discovery call — no commitment. We confirm fit, the right platform, and the next steps.