How does the NIS2 compliance report relate to ENISA’s recommendations?
Closed beta starting September 2026
The new report engine is accessible via a closed beta starting in September 2026. If you would like to participate in the beta, please reach out to your Customer Success Manager.
This is an overview of how the NIS2 compliance report meets the requirements set out in ENISA’s Technical Implementation Guidance for NIS2 compliance. Each row below matches an ENISA requirement with where you'll see it in the NIS2 compliance report. Rows marked "Coming later in 2026" are on the roadmap and are not yet in the report.
Disclaimer
Nothing in the report constitutes legal advice, and NIS2 requirements vary by member state.
|
What ENISA expects: |
Where you'll find it in the report: |
|
Information from trusted vulnerability sources - suppliers, service providers, security authorities, CSIRTs, and other trusted sources. |
Holm Security's Security Research team continuously monitors these sources and creates vulnerability tests you can run through the platform. |
|
A framework for assessing vulnerability severity based on models such as CVSS and EPSS. |
The platform uses CVSS and EPSS to help you prioritize vulnerabilities. |
|
Continuous assessments covering relevant assets. |
The "Assessment schedule coverage" section shows how many in-scope assets are covered by active scheduled scans, and which ones aren't. |
|
A list of all relevant vulnerabilities affecting your assets. |
The report includes a full list of relevant vulnerabilities based on your settings, showing affected assets, owners, related assessment schedules, remediation tickets, and comments. |
|
Documented policy for remediation times by severity. |
The report lets you configure maximum remediation time for each severity level, applied globally or per asset group (tags). |
|
Documented policy for exploit likelihood (EPSS) thresholds. |
The report lets you configure an EPSS threshold, applied globally or per asset group (tags). |
|
Documented actions taken on specific vulnerabilities. |
You can add comments before the report is generated, which are then included in the shared output. |
|
Documentation of the settings and methodology used for each assessment. |
The "Scan profile details" and "Report settings" sections describe exactly how each assessment was performed and how the report was configured. |
|
Coming later in 2026: |
The report will include an assessment log showing when each assessment ran. |
|
Coming later in 2026: |
The report will let you configure maximum severity levels for specific assets and asset groups (tags). |
What is EPSS?
The Exploit Prediction Scoring System (EPSS) estimates the likelihood that a vulnerability will be exploited in the wild within the next 30 days, expressed as a percentage from 0% to 100%.
- 1% means the vulnerability is relatively unlikely to be exploited.
- 25% means there is a meaningful exploitation likelihood.
- 90% and above means the vulnerability is extremely likely to be exploited.
What is CVSS?
The Common Vulnerability Scoring System (CVSS) is a standardized way to measure the severity of a vulnerability on a scale from 0.0 to 10.0. In the platform, the CVSS score is translated into a severity level.
How does Holm Security translate the CVSS score versions to severity?
Read more
Download and read ENISA’s technical implementation guidance for NIS2 (external link)
Related articles
What is the NIS2 compliance report?
What are ENISA’s recommendations for vulnerability management?
How do I set up a NIS2 compliance report?
What are the recommended settings in the NIS2 compliance report?
Disclaimer
Nothing in the report constitutes legal advice, and requirements for NIS2 compliance vary by member state.