Ejerblik does not make you NIS2 compliant
Ejerblik provides the inventory of software, user accounts, access and suppliers that CIS18 controls 2, 5, 6 and 15 are built on, and that NIS2 Article 21 assumes under asset management, access control and supply chain security. That is the foundation beneath the requirements. The security work itself sits with your IT partner.
We could write that you meet the documentation requirements because your assets are in Ejerblik. It would not be true, and it would not hold up in front of an accountant, an insurer or the IT adviser your customer is going to ask anyway.
So it is set out control by control instead. The two matrices below are our own assessment of what the platform actually contains, held up against CIS Controls version 8.1 and NIS2 Article 21(2).
Three layers, three owners
The inventory and the security work are two different jobs. Ejerblik handles the first. Your IT partner handles the third. The assessment in between, you do together.
Which systems you have, who owns them, who has access, which supplier is behind them, and when the agreement renews. It is a data problem, and without that layer none of the others can be documented.
What is critical, what an outage costs, what you act on first. Ejerblik gives you the structure through eleven ready-made reviews, among them an IT risk assessment built on the NIS2 method. The adviser brings the expertise, and management approves. Management approval is a requirement in its own right under NIS2.
Updates, backup, logging, monitoring, contingency planning and the technical implementation of the controls. Ejerblik documents that two-factor authentication is switched on. Ejerblik does not switch it on.
CIS Controls version 8.1
CIS18 is a voluntary framework, not a legal requirement, but it is widely used as the practical route to meeting the technical requirements in NIS2. Controls 2, 5 and 6 all sit in Implementation Group 1, the most basic measures, described as essential cyber hygiene. That is the starting line, and it is where most owner-managed companies stand today.
Provides means that Ejerblik holds the documentation itself as structured data. Supports means that the topic is asked about in one of the platform reviews, but is not captured as a field on the asset. Out of scope means that the control is a technical measure or an operational task that belongs with the IT partner. Read more about CIS18 →
NIS2, Article 21(2)
The ten risk management measures a covered entity has to have in place. On top of those come Article 20 on management approval and liability, and Article 23 on reporting within 24 and 72 hours of a significant incident. Neither of the last two is covered by Ejerblik.
Very few owner-managed companies are directly covered by NIS2 themselves. The requirement reaches them through the supply chain, because point (d) obliges the covered companies to manage security at their suppliers. Read more about NIS2 →
What Ejerblik is not
- Ejerblik is not a security tool. We do not scan for vulnerabilities, we do not monitor your network, and we do not enable two-factor authentication for you.
- Ejerblik does not keep track of your computers, phones and network equipment. We cover software, accounts, access and suppliers.
- Ejerblik is not a statement of legal compliance. An inventory is a precondition for being able to document, not proof that the requirements are met.
- Ejerblik does not replace an IT supplier or a security adviser. The platform is built to work alongside them.
The assessments are based on the Ejerblik data model and review templates, held up against CIS Controls version 8.1 and NIS2 Articles 20, 21 and 23. They are our own, and they have not been confirmed by an external auditor or a certification body. This page is not legal advice, and it does not constitute a statement that a company complies with NIS2.
We update the mapping when the platform changes and when the frameworks change. If you disagree with an assessment, we would like to hear from you on the contact page.