How does the NIS2 compliance report relate to ENISA’s recommendations?
This is an overview of how the NIS2 compliance report meets the requirements set out in ENISA’s technical implementation guidance for NIS2 compliance. Each row below matches something ENISA asks for with where you'll see it in the NIS2 compliance report. Rows marked "Coming later in 2026" are on the roadmap and are not yet in the report.
|
What ENISA expects: |
Where you'll find it in the report: |
|
Information from trusted vulnerability sources — suppliers, service providers, security authorities, CSIRTs, and other trusted sources. |
Holm Security's Security Research Team continuously monitors these sources and creates vulnerability tests you can run through the platform. |
|
A framework for assessing vulnerability severity, based on models such as CVSS and EPSS. |
The platform uses CVSS and EPSS to help you prioritize vulnerabilities. |
|
Continuous assessments covering relevant assets. |
The "Assessment schedule coverage" section shows how many in-scope assets are covered by active scheduled scans, and which ones aren't. |
|
A list of all relevant vulnerabilities affecting your assets. |
The report includes a full list of relevant vulnerabilities based on your settings, showing affected assets, owners, related assessment schedules, remediation tickets, and comments. |
|
Documented policy for remediation times by severity. |
The report lets you configure maximum remediation time for each severity level, applied globally or per asset group (tags). |
|
Documented policy for exploit likelihood (EPSS) thresholds. |
The report lets you configure an EPSS threshold, applied globally or per asset group (tags). |
|
Documented actions taken on specific vulnerabilities. |
You can add comments before the report is generated, which are then included in the shared output. |
|
Documentation of the settings and methodology used for each assessment. |
The "Scan profile details" and "Report settings" sections describe exactly how each assessment was performed and how the report was configured. |
|
Coming later in 2026: |
The report will include an assessment log showing when each assessment ran. |
|
Coming later in 2026: |
The report will let you configure maximum severity levels for specific assets and asset groups (tags). |
What is EPSS?
EPSS stands for Exploit Prediction Scoring System. It estimates the likelihood that a vulnerability will be exploited in the wild within the next 30 days, expressed as a percentage from 0% to 100%.
- 1% means the vulnerability is relatively unlikely to be exploited.
- 25% means there is a meaningful exploitation likelihood.
- 90% and above means the vulnerability is extremely likely to be exploited.
What is CVSS?
CVSS stands for Common Vulnerability Scoring System. It is a standardized way to measure the severity of a vulnerability on a scale from 0.0 to 10.0. In the platform, the CVSS score is translated into a severity level: Info (0.0), Low (0.1–3.9), Medium (4.0–6.9), High (7.0–8.9), or Critical (9.0–10.0).
Read more
Download and read ENISA’s technical implementation guidance for NIS2 (external link)
Related articles
Cominig soon.