NIS2 and the AIC Kits
The NIS2 Directive (EU) 2022/2555 sets cybersecurity risk-management measures for essential and important entities in the European Union. Analog Informatics Corporation (AIC) kits cover access control, cryptography, incident handling, and continuous monitoring on paths the kit manages. The national competent authority decides compliance. The kits run in a secure enclave, air-gapped or generally connected.

Article 21(2) Measures
| Measure | What the Kit Does |
|---|---|
| (a) Risk analysis and information system security policies | Current State Compliance records findings. Policy stays with the organization. |
| (b) Incident handling | Incident Response records the event and can alert. |
| (c) Business continuity, backup, disaster recovery, and crisis management | Recovery stays with the organization. High-availability database failover is available. |
| (d) Supply chain security | Supplier review stays with the organization. |
| (e) Security in acquisition, development, and maintenance, including vulnerability handling | Findings can be recorded. Vulnerability analysis is planned as an add-on module. Maintenance sessions go through Privileged Access Management. |
| (f) Assessing the effectiveness of risk-management measures | Current State Compliance and the Assessment Binder. |
| (g) Basic cyber hygiene and cybersecurity training | Training and attestation, and configuration compliance. |
| (h) Cryptography and encryption | Validated cryptography on kit paths. |
| (i) Human resources security, access control, and asset management | Privileged access, access review on kit accounts, and inventory of enrolled systems. |
| (j) Multi-factor or continuous authentication and secured communications | Kit sign-in with another step beyond a password. Secured voice and video stay with the organization. |
Screenshots
More on Product Screenshots.
An assessment organization, certification body, or regulator decides whether a requirement is satisfied.