import { Link } from 'react-router-dom' import { ShieldCheckIcon } from '@heroicons/react/24/outline' type Coverage = 'covered' | 'partial' | 'roadmap' | 'na' type Requirement = { article: string label: string coverage: Coverage netork: string } const REQUIREMENTS: Requirement[] = [ { article: 'Art. 21 (2a)', label: 'Risk analysis & information system security policies', coverage: 'partial', netork: 'Config drift detection, SNMP health metrics, and security agent coverage across all devices provide a continuous risk baseline. A formal risk register is out of scope for netOrk.', }, { article: 'Art. 21 (2b)', label: 'Incident handling', coverage: 'partial', netork: 'Wazuh alert history, CrowdSec decisions, and Graylog syslog per device surface incidents at the network layer. A structured incident record with NIS2 Art. 23 reporting timers is on the roadmap.', }, { article: 'Art. 21 (2c)', label: 'Business continuity, backup management, disaster recovery', coverage: 'roadmap', netork: 'Git-backed configuration snapshots (on roadmap) provide config-level recovery. Backup monitoring for individual devices is not yet implemented.', }, { article: 'Art. 21 (2d)', label: 'Supply chain security', coverage: 'partial', netork: 'Vendor, model, firmware, and OS version are tracked per device after every poll. EOL tracking against endoflife.date is on the roadmap to flag unsupported software.', }, { article: 'Art. 21 (2e)', label: 'Vulnerability handling in acquisition, development & maintenance', coverage: 'covered', netork: 'Per-device update status and installed package list tracked on every poll. Wazuh CVE counts by severity (critical / high / medium) linked directly to each device record. CVE cross-reference against NVD/OSV (without Wazuh) is on the roadmap.', }, { article: 'Art. 21 (2f)', label: 'Assessing effectiveness of cybersecurity measures', coverage: 'partial', netork: 'The audit log records all orchestration actions. A per-site compliance dashboard (on roadmap) will aggregate security agent coverage, drift status, and patch metrics into a single view.', }, { article: 'Art. 21 (2g)', label: 'Basic cyber hygiene & cybersecurity training', coverage: 'na', netork: 'Out of scope for a network orchestration platform. Training and hygiene policies are handled at the organizational level.', }, { article: 'Art. 21 (2h)', label: 'Access control, asset management, human resources security', coverage: 'covered', netork: 'Full device inventory maintained automatically via discovery and continuous polling. RBAC with four built-in roles (viewer / operator / engineer / administrator) and custom role combinations. Complete audit log of all orchestration actions.', }, { article: 'Art. 21 (2i)', label: 'Multi-factor authentication', coverage: 'roadmap', netork: 'TOTP-based MFA for netOrk user accounts is on the roadmap. Current authentication is JWT-based (username + password).', }, { article: 'Art. 21 (2j)', label: 'Physical and environmental security', coverage: 'na', netork: 'Out of scope. Physical security of the infrastructure hosting netOrk is an organizational and facility concern.', }, ] const EVIDENCE = [ { trigger: 'Every device poll', produces: [ 'Installed package list with versions', 'Available update count', 'Interface status, ARP table, DHCP leases', 'VLAN membership vs. desired state (drift)', 'SNMP health metrics (CPU, memory, interface counters)', 'Wazuh agent status and CVE counts by severity', 'Graylog syslog forwarding status', 'CrowdSec decisions and ban counts', ], }, { trigger: 'Every user action', produces: [ 'Audit log entry: user, timestamp, resource, action', 'Before/after values for configuration changes', ], }, { trigger: 'On demand', produces: [ 'Topology graph — network segmentation view', 'Subnet browser — IP space coverage', 'VLAN matrix — which devices carry which VLANs', 'Audit log export to PDF / CSV (roadmap)', ], }, ] function CoverageTag({ coverage }: { coverage: Coverage }) { if (coverage === 'covered') return ( ✓ Covered ) if (coverage === 'partial') return ( ⚠ Partial ) if (coverage === 'roadmap') return ( → Roadmap ) return ( — N/A ) } export default function Nis2() { return (
{/* Header */}

NIS2 & netOrk

NIS2 Art. 21 defines ten categories of technical and organizational measures. Some of them are directly addressed by what netOrk does every day. This page maps each requirement to netOrk's current capabilities — honestly, including what's partial and what's not applicable.

{/* Art. 21 mapping */}

Art. 21 — requirement by requirement

{REQUIREMENTS.map((r, i) => (
{r.article} {r.label}

{r.netork}

))}
{/* Legend */}
netOrk covers this today partially covered — see description planned — see roadmap outside scope of a network management tool
{/* Evidence produced */}

What netOrk produces as evidence

NIS2 audits require demonstrable outputs, not just claimed controls. Here's what netOrk generates automatically.

{EVIDENCE.map((e) => (

{e.trigger}

    {e.produces.map((item) => (
  • {item}
  • ))}
))}
{/* Roadmap callout */}

What's coming

{[ { title: 'CVE tracking per device', detail: 'Automatic cross-reference of installed packages against NVD / OSV — no Wazuh agent required.', }, { title: 'Configuration backup & versioning', detail: 'Git-backed config snapshots after every poll. Detect unauthorized changes, compare over time.', }, { title: 'Compliance dashboard', detail: 'Per-site Art. 21 checklist: asset coverage, patch status, agent deployment, drift, syslog, audit activity.', }, { title: 'Audit log export', detail: 'PDF and CSV export filtered by date range, device, user, or action — ready to hand to an auditor.', }, { title: 'Incident workflow', detail: 'Structured incident records with NIS2 Art. 23 reporting timers (24 h / 72 h) and external webhook delivery.', }, { title: 'EOL tracking', detail: 'Flag devices running end-of-life firmware or OS versions via the endoflife.date API.', }, { title: 'MFA (TOTP)', detail: 'Time-based one-time passwords as a second factor for netOrk user accounts (Art. 21 (2i)).', }, ].map((item) => (

{item.title}

{item.detail}

))}
Full roadmap →
{/* CTA */}

Start with the foundation.

Asset inventory, continuous polling, drift detection, RBAC, and a full audit log — deployed in one command.

Get started →
) }