---
title: "NIS2: controls supported by Noraina"
description: "Which NIS2 controls Noraina's infrastructure, backup and Cloudflare services support, how, and what evidence you get for the audit."
url: https://www.noraina.cloud/compliance/nis2/
language: en
---
# NIS2: controls supported by Noraina

Medium and large companies in sectors such as energy, transport, health, digital infrastructure and manufacturing, and their suppliers.

> Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.

## NIS2 Directive (EU) 2022/2555

EU directive on cybersecurity risk-management measures for essential and important entities. References are points of Article 21(2).

6 controls supported.

### Efficient Cloud Instances with replication

- Control: 21.2.c (Business continuity)
- How we help: A second site and tested failover are the disaster-recovery part of the measures NIS2 requires.
- Evidence you get: Disaster-recovery plan inputs, failover test reports.
- Status: Mapping under review

### Efficient Cloud Backup

- Control: 21.2.c (Business continuity); 21.2.h (Cryptography and encryption)
- How we help: Backup management with encryption, the part of NIS2 that decides whether you recover from ransomware.
- Evidence you get: Backup and retention configuration, restore test records.
- Status: Mapping under review

### Efficient Cloud DNS (NorainaDNS)

- Control: 21.2.c (Business continuity)
- How we help: Automates failover between services and, on the Enterprise plan, removes DNS as a single point of failure, part of the business continuity and disaster-recovery measures NIS2 requires.
- Evidence you get: DNS architecture description, failover configuration, failover event history.
- Status: Mapping under review

### Complete edge logging

- Control: 21.2.b (Incident handling)
- How we help: Complete logs are what make incident detection, analysis and reporting possible.
- Evidence you get: Log inventory and the queries used in incident handling.
- Status: Mapping under review

### Application and DDoS protection

- Control: 21.2.e (Security in acquisition)
- How we help: Virtual patching and API schema validation reduce exposure while vulnerabilities are being fixed.
- Evidence you get: WAF rule history and threat reports.
- Status: Mapping under review

### Zero Trust access and data protection

- Control: 21.2.i (Access control policies); 21.2.j (Multi-factor authentication and secured communications)
- How we help: Access control policies enforced per application, with multi-factor authentication and encrypted connections.
- Evidence you get: Access policy export and authentication logs.
- Status: Mapping under review


We reply with the controls we can cover, what stays on your side, and a realistic timeline. https://www.noraina.cloud/compliance/nis2/#assessment
