Skip to content
  • There are no suggestions because the search field is empty.

What is the NIS2 compliance report?

The NIS2 compliance report provides a structured view of how your vulnerability and risk management practices align with the requirements of the NIS2 Directive. You can use it internally to demonstrate compliance and share it with national authorities when they ask for evidence.

What NIS2 expects from vulnerability management

NIS2 expects organizations to manage vulnerabilities as an ongoing, documented, and risk-based process. That means vulnerabilities should be identified quickly, assessed in your specific context, prioritized by risk, remediated or otherwise formally treated, and reviewed on a regular basis.

The technical detail behind this expectation comes from the Commission Implementing Regulation (EU) 2024/2690, with practical guidance provided by ENISA's Technical Implementation Guidance. The NIS2 compliance report is built to reflect both.

What the report contains

The report is generated from your live data in Security Center. It shows the current compliance status of your assets, the assessments that produced the data, and the evidence you can share with an auditor:

  • A compliance verdict for each asset, showing whether it passes your defined thresholds.
  • The reason each asset is non-compliant, tied to specific vulnerabilities.
  • The owner, open remediation tickets, and due dates for each non-compliant asset.
  • Coverage of your active assessment schedules, so you can see which assets are being scanned regularly and which are not.
  • Full scan profile details describing how each assessment was performed.

How the report is configured

The report is configured based on ENISA's recommendations and your organization's own requirements. This produces a compliance report tailored to your environment, ready to demonstrate NIS2 compliance for vulnerability management.

You control the thresholds that determine compliance for your organization: remediation windows for each severity level, EPSS thresholds, and which asset groups they apply to. This lets you hold high-risk assets to a stricter standard while applying a baseline to the rest of the estate.

How to use the report

There are three ways the report is typically used:

  • Internal reporting
    Share it with your security or risk team, or with the board, to show current status against your defined compliance policy.
  • Audit response
    Share it with a national authority or auditor as evidence of your vulnerability management process.
  • Supply chain requests
    Share it with enterprise customers or partners who need to verify your compliance posture.