How Does Continuous Controls Validation Work For NIS2 (CyFun)?
Continuous Controls Validation: NIS2 (CyFun) maps your validated vulnerability findings against the CyberFundamentals (CyFun) framework used to demonstrate NIS2 compliance, organized by NIST CSF function and linked directly to the relevant NIS2 Article 21(2) measures.
Version Number: v1.0.0
Published Date: 27 Aug 2026
____________________________________________________________________________
What is it?
This report constitutes evidence-based control validation using validated Edgescan findings. It does not constitute a formal CyFun certification audit or an official NIS2 conformity determination. Control applicability depends on your organization's designated CyFun assurance level (Basic, Important, or Essential) and your NIS2 entity classification (Essential or Important Entity).
How it works?
-
NIST CSF Function Breakdown
-
Current control violations are grouped by NIST CSF function, Protect, Identify, Detect, and Respond, giving an at-a-glance view of where weaknesses are concentrated.
-
-
Control-by-Control Detail
-
Each affected CyFun control (for example PR.IP-12 Vulnerability Management Plan, PR.AC-3 Remote Access Management, PR.DS-1/2 Data-at-Rest and Data-in-Transit Protection, PR.AC-4 Access Permissions, PR.PT-3 Least Functionality, PR.IP-1 Baseline Configuration, DE.CM-8 Vulnerability Scans) is presented with its control intent and lowest applicable CyFun assurance level.
-
-
Current Violations & Avoided Non-Compliances
-
Each control lists the specific open findings evidencing a violation, plus any previously remediated findings that avoided a violation.
-
-
NIS2 Article 21(2) Mapping
-
Every control is explicitly linked to the specific NIS2 Article 21(2) measure(s) it supports, for example Article 21(2)(e) security in acquisition, development and maintenance, or Article 21(2)(i) multi-factor authentication and secured communications.
-
-
Remediation Guidance
-
Each control section closes with prioritized remediation steps addressing the specific violations found.
-
Features & Benefits
-
Regulation-Linked: Ties technical findings directly to the specific legal measures they support or violate, not just a generic framework.
-
Assurance-Level Aware: Flags the minimum CyFun assurance level each control applies at, so effort can be targeted appropriately.
-
Evidence, Not Assertion: Every violation and every avoided non-compliance is backed by a real, validated finding.
-
Regulatory Reporting Ready: Structured to support NIS2-related reporting obligations and internal governance reviews.
Common Use-Cases
-
NIS2 Compliance Programmes: Provide ongoing evidence of control status ahead of formal NIS2 conformity assessment.
-
Regulatory Reporting: Support internal or external reporting on NIS2 Article 21(2) measures.
-
Gap Analysis: Identify which CyFun controls have the most outstanding violations and prioritize remediation accordingly.
-
Board & Regulator-Facing Summaries: Present cybersecurity risk management posture in terms directly aligned to NIS2 obligations.