NIS2 · CyberFundamentals Framework

How actasec covers CyFun®2025

We mapped all 133 individual requirements of the CyberFundamentals Framework — the self-assessment tool published by the Centre for Cybersecurity Belgium and used for NIS2 readiness at the IMPORTANT assurance level — against what actasec’s platform and advisory services actually deliver today.

133 requirements mapped23 Key MeasuresIMPORTANT assurance levelCyFun®2025
Combined Coverage
82%

Requirements addressed once the platform is paired with actasec’s advisory and managed services.

Key Measures Addressed
21 / 23

The specific requirements CyFun flags as priority, each independently scored to a ≥3/5 target.

Platform-Direct
29

Requirements a shipped actasec feature satisfies on its own — no services required.

How we get you there

Every requirement, one of three ways

Platform

A shipped actasec feature — asset inventory, vulnerability scanning, risk register, ITSM incidents, vendor management, security training — satisfies the requirement outright.

Platform + Services

The platform covers part of it; an actasec service — CISO-as-a-Service, Programme Design, Security Assessments, Cloud Security, Penetration Testing, or SOC-as-a-Service — closes the rest.

Client-owned

A small number of requirements — mostly budget decisions, physical security, and backup infrastructure — stay with the client no matter which vendor they choose.

Priority requirements

The 23 Key Measures

CyFun flags these as priority — each needs its own ≥3/5 maturity score, independent of the category average.

GV.RR-02.1

Roles, responsibilities & authorities for info/cyber security (staff, suppliers, customers, partners) documented, reviewed, authorized, updated, communicated, coordinated internally & externally.

Platform + ServicesFully Addressed

Fully once combined — Resolver Groups alone only cover ticket-queue ownership, a narrow slice; Programme Design's RACI closes the rest.

ID.AM-08.2

OS and critical-component security patches and updates must be installed.

PlatformFully Addressed

Fully — Vulnerability Management finds unpatched systems directly and ITSM tracks remediation to closure.

ID.RA-08.1

A vulnerability management plan established and implemented to identify, analyze, evaluate, mitigate and communicate all vulnerability types, including coordinated vulnerability disclosure (CVD).

Platform + ServicesFully Addressed

Fully once combined — the internal lifecycle is already handled; Programme Design adds the missing external CVD intake.

PR.AA-01.1

Identities and credentials of authorized users, services and equipment must be managed.

Platform + ServicesFully Addressed

Fully once combined — actasec covers its own identities directly; Cloud Security's IAM review extends coverage client-wide.

PR.AA-03.2

Multi-factor authentication (MFA) must be mandatory for remote access to organizational networks.

Platform + ServicesFully Addressed

Fully once combined — actasec enforces its own MFA directly; Cloud Security validates/extends it client-wide.

PR.AA-03.3

Usage restrictions, connection requirements and authorization procedures defined, documented and implemented for remote access to critical systems.

Platform + ServicesFully Addressed

Fully via Cloud Security's remote-access review and Programme Design's documentation.

PR.AA-05.1

Access permissions, rights and authorizations defined, managed, enforced and reviewed.

Platform + ServicesFully Addressed

Fully once combined — platform RBAC covers actasec itself; Cloud Security extends it client-wide.

PR.AA-05.2

Established who needs access to critical information/technology and by what means they obtain it.

Platform + ServicesFully Addressed

Fully via Cloud Security's IAM risk analysis.

PR.AA-05.3

Access rights, privileges and authorizations restricted to what's specifically needed for the role (least privilege).

Platform + ServicesFully Addressed

Fully once combined — platform RBAC direct for itself; Cloud Security extends it client-wide.

PR.AA-05.4

No one should hold administrative privileges for routine, day-to-day tasks.

Platform + ServicesPartially Addressed

Partially — the review surfaces violations, but day-to-day enforcement remains the client's own operational discipline.

PR.DS-11.1

Backups of critical organizational data made and stored on a system different from the device holding the original data.

Client-ownedNot Addressed

Not addressed — the one Key Measure that stays genuinely client-owned even combined with services; we can review the evidence, not run the backups.

PR.PS-01.1

A baseline configuration developed, documented and maintained for business-critical systems.

Platform + ServicesFully Addressed

Fully via Cloud Security's CIS Benchmark hardening and IaC review.

PR.PS-04.1

Logs should be maintained, documented and monitored.

Platform + ServicesFully Addressed

Fully via SOC-as-a-Service's SIEM deployment and management.

PR.PS-04.2

Log records include an authorized time source or internal clock timestamp compared/synchronized against an authorized time source.

Platform + ServicesFully Addressed

Fully — a standard part of SOC-as-a-Service's SIEM configuration.

PR.IR-01.1

Firewalls installed, configured and actively updated across all networks used by the organization to protect against unauthorized access and cyber threats.

Platform + ServicesFully Addressed

Fully via Cloud Security and Penetration Testing's direct firewall review/hardening.

PR.IR-01.2

Network segmentation and segregation implemented in line with trust boundaries and asset criticality to limit threat propagation.

Platform + ServicesFully Addressed

Fully via Cloud Security's network security assessment.

PR.IR-01.3

Connections between critical system components identified, documented and controlled, without exception.

Platform + ServicesFully Addressed

Fully via Cloud Security and Penetration Testing.

PR.IR-01.4

Adequate boundary-protection measures implemented to monitor/control communications at key external/internal system boundaries (IT and OT).

Platform + ServicesFully Addressed

Fully via Cloud Security and Penetration Testing.

DE.CM-01.2

Antivirus, anti-spyware and other anti-malware programs must be installed and kept updated.

Platform + ServicesFully Addressed

Fully via SOC-as-a-Service's EDR integration.

DE.CM-01.3

Unauthorized use of business-critical systems monitored and identified, through detection of unauthorized local, network, and remote connections.

Platform + ServicesFully Addressed

Fully via SOC-as-a-Service's 24/7 monitoring.

DE.AE-03.1

Logging functionality of protection/detection tools enabled; logs saved, retained for a predefined period and periodically reviewed for unusual/harmful activity.

Platform + ServicesFully Addressed

Fully via SOC-as-a-Service's SIEM/log management.

RS.CO-02.2

Cybersecurity incidents communicated to relevant external stakeholders within IR-plan-defined timelines, including reporting significant incidents to authorities per legal requirements.

Platform + ServicesFully Addressed

Fully once combined — the platform tracks the clock, CISO-as-a-Service handles the regulatory notification itself.

RS.MI-01.2

Unauthorized access or data leaks detected and appropriately mitigated, including monitoring of critical systems at external boundaries and key internal points.

Platform + ServicesFully Addressed

Fully via SOC-as-a-Service's monitoring and analyst-led containment.

Full detail

All 133 requirements

Grouped by CyFun function, category, and subcategory. Expand a function to see how each of its requirements is addressed.

Govern96% · 3 platform / 19 combined / 1 client-owned

Organizational Context (GV.OC)

GV.OC-01Organizational mission is understood and underpins cyber risk management
GV.OC-01.1
Organizational mission established, communicated, and used as the basis for cyber risk management.
Platform + Services
Risk Register ties decisions to business context. Programme Design facilitates the mission/context workshop and documents it.
GV.OC-03Legal, regulatory & contractual cybersecurity requirements are understood and managed
GV.OC-03.1
Legal and regulatory cybersecurity requirements identified and implemented.
Platform + Services
Documents Library hosts the requirement register. Security Assessments' gap analysis identifies applicable legal/regulatory requirements.
GV.OC-03.2
Legal, regulatory & contractual cyber obligations managed continuously to stay current and effective.
Platform + Services
Documents Library's review lifecycle. CISO-as-a-Service's regulatory engagement keeps requirements current.
GV.OC-04Critical objectives/capabilities/services expected by external stakeholders are understood & communicated
GV.OC-04.1
Critical objectives/capabilities/services external stakeholders rely on identified, documented, prioritized in risk assessment.
Platform + Services
Risk Register + Vendor Management hold the record. Programme Design scopes and documents critical objectives.
GV.OC-04.2
Cybersecurity requirements for essential operations defined, validated by tests/audits, records kept, updated periodically.
Platform + Services
Penetration Testing / Security Assessments provide the validating tests & audits. Risk Register records outcomes.
GV.OC-05The organization's own dependencies and services are understood & communicated
GV.OC-05.1
Organization's own supply-chain role, external dependencies and downstream interactions identified, documented, communicated.
Platform + Services
Vendor Management tracks upstream dependencies; Assets tracks internal services. Programme Design documents the supply-chain role.

Risk Management Strategy (GV.RM)

GV.RM-01Risk management objectives are established and agreed
GV.RM-01.1
Cybersecurity/information risk objectives identified, agreed by stakeholders, approved by senior management.
Platform + Services
Risk Register hosts the objectives. Programme Design's risk framework design sets them with leadership.
GV.RM-02Risk appetite & tolerance statements are established, communicated, maintained
GV.RM-02.1
Risk appetite & tolerance statements defined, documented, approved by senior management, communicated, maintained.
Platform + Services
Risk scoring implies thresholds. Programme Design defines the appetite/tolerance statements themselves.
GV.RM-03Cyber risk activities are integrated into enterprise risk management processes
GV.RM-03.1
Comprehensive enterprise-wide cyber/info risk management strategy developed, updated when it changes.
Platform + Services
Risk Register operationalizes the strategy day to day. Programme Design authors the strategy document itself.
GV.RM-03.2
Cyber/info risks documented as part of enterprise risk processes, formally approved by senior management, updated on change.
Platform
Risk Register: cyber risks documented, approved by leadership, updated on change — this is exactly what it's built for.
GV.RM-04Strategic risk-response direction is established and communicated
GV.RM-04.1
A high-level risk-response plan/vision is formally set and clearly communicated, incl. available strategies by risk appetite.
Platform + Services
Risk Register treatment plans capture direction per risk. CISO-as-a-Service / Programme Design set the strategic direction.
GV.RM-05Communication lines for cyber risk, including supplier-originated risk
GV.RM-05.1
Clear communication lines for cyber risk established, including risk from suppliers and third parties.
Platform + Services
Vendor Management + Risk Register linking. CISO-as-a-Service establishes the escalation lines.

Roles, Responsibilities & Authorities (GV.RR)

GV.RR-02Roles/responsibilities/authorities for cyber risk management are established & communicated
GV.RR-02.1K
Roles, responsibilities & authorities for info/cyber security (staff, suppliers, customers, partners) documented, reviewed, authorized, updated, communicated, coordinated internally & externally.
Platform + Services
Resolver Groups cover ITSM queue ownership only. Programme Design's governance model design (RACI) covers the rest, hosted in Documents Library.
GV.RR-03Adequate resources are allocated proportional to strategy/roles/policies
GV.RR-03-1
Sufficient resources allocated in line with cyber risk strategy, roles, responsibilities and policies.
Client-owned
A budget/headcount decision. CISO-as-a-Service advises on resourcing as part of strategy, but can't make the allocation for the client.
GV.RR-03-2
Roles/responsibilities assigned for reviewing and updating response & recovery plans as the risk landscape changes.
Platform + Services
Programme Design assigns this as part of governance design; ITSM Resolver Groups operationalize the resulting ownership.
GV.RR-04Cybersecurity is included in HR practices
GV.RR-04.1
Personnel with access to the organization's most critical info/technology must be authenticated.
Platform + Services
actasec's own MFA/SSO covers this directly for platform access. Cloud Security's IAM review extends it across the client's broader personnel/systems.
GV.RR-04.2
A cybersecurity HR process developed and maintained — recruitment, employment, and termination.
Platform + Services
CISO-as-a-Service designs the HR-integrated process (onboarding/offboarding). Training Suite delivers the ongoing-employment awareness piece.

Policy (GV.PO)

GV.PO-01Cybersecurity policy is established, communicated and enforced
GV.PO-01.1
Info/cybersecurity policies & procedures established, documented, reviewed, approved, updated on change, communicated, applied.
Platform
Documents Library: full policy lifecycle — author, review, approve, version, publish, re-communicate on update.
GV.PO-01.2
Org-level policies include cryptography/encryption use, reflect changing threats/tech/roles, approved & overseen by senior management.
Platform + Services
Documents Library hosts the policy. Programme Design authors the cryptography-specific content; Cloud Security validates the technical encryption controls it describes.

Supply Chain Risk Management (GV.SC)

GV.SC-02Roles/responsibilities for suppliers/customers/partners are established & coordinated
GV.SC-02.1
Third-party suppliers must notify any transfer, termination or transition of personnel with physical/logical access to critical system elements.
Platform + Services
A supplier's own contractual notification duty. Programme Design/CISO-as-a-Service write the contract clause; enforcement is the client's.
GV.SC-05Supply-chain cyber risk requirements are integrated into contracts/agreements
GV.SC-05.1
Supply-chain cyber risk requirements and sensitive-info-sharing requirements established, prioritized, integrated into contracts/agreements, applied.
Platform + Services
Programme Design/CISO-as-a-Service build requirements into contract templates. Vendor Management tracks ongoing compliance.
GV.SC-07Supplier/third-party risk is understood, recorded, prioritized, managed, monitored
GV.SC-07.1
Supplier/third-party risk identified, documented, prioritized, mitigated and evaluated at least annually and on relationship change.
Platform
Vendor Management: vendor inventory, review cadence, risk tracking — exactly this requirement.
GV.SC-08Suppliers are included in incident planning, response & recovery
GV.SC-08.1
Key personnel of relevant suppliers/third parties identified & documented for inclusion in incident planning, response, recovery.
Platform + Services
Vendor Management tracks vendor contacts. CISO-as-a-Service's incident leadership coordinates their involvement in planning/response.
Identify87% · 15 platform / 18 combined / 5 client-owned

Asset Management (ID.AM)

ID.AM-01Hardware inventory is maintained
ID.AM-01.1
Inventory of physical & virtual infrastructure assets (hardware, network devices, cloud-hosted environments) documented, reviewed, updated on change.
Platform
Assets module + Discovered Assets (scan-based discovery), reviewed/updated automatically as scans run.
ID.AM-01.2
Enterprise asset inventory reflects organizational context changes and includes all information needed for effective accountability.
Platform
Assets module fields (environment, owner, status) track exactly this.
ID.AM-01.3
Unauthorized hardware quarantined for exception handling, removed, or replaced, and the inventory updated accordingly.
Platform + Services
Discovered Assets flags unrecognized hardware found via scanning for review. Actual quarantine/removal action and policy is the client's; Cloud Security can advise on process.
ID.AM-02Software/services/systems inventory is maintained
ID.AM-02.1
Inventory of software, digital services and work systems used in the organization documented, reviewed, updated on change.
Platform
Assets module (application/service types) + Applications module SCA/SBOM.
ID.AM-02.2
Software/services/systems inventory reflects organizational context changes and includes accountability information.
Platform
Assets/Applications inventories update as scans run and reflect ownership fields.
ID.AM-02.3
People responsible/accountable for managing software platforms and applications formally identified.
Platform
Assets tracks a named owner per asset directly.
ID.AM-02.4
Unauthorized software quarantined for exception handling, removed, or replaced, and the inventory updated accordingly.
Platform + Services
SCA scanning flags unknown/vulnerable dependencies. Actual removal action is the client's; Cloud Security can assist.
ID.AM-03Network communication & data-flow maps are maintained
ID.AM-03-2
Internal network communications and data flows mapped, documented, authorized and updated on change.
Platform + Services
Discovery/Nmap scanning surfaces live hosts & open services. Cloud Security's network exposure mapping completes the picture for cloud environments.
ID.AM-04Vendor-provided service inventory is maintained
ID.AM-04.1
A clear, current list of all external services used, including how they connect, reviewed/approved before use and kept updated.
Platform
Vendor Management's vendor inventory with review/approval workflow.
ID.AM-05Assets are prioritized by classification/criticality
ID.AM-05.1
Assets prioritized based on classification, criticality and business value.
Platform
Assets tracks environment/criticality; risk-based finding prioritization weighs asset criticality directly.
ID.AM-07Data & metadata inventories are maintained
ID.AM-07.1
Data the organization stores and uses must be identified.
Client-owned
No data-classification capability in the platform or service catalog today.
ID.AM-07.2
Inventories of data and associated metadata maintained for designated data types.
Client-owned
Same — a dedicated data-catalog/DLP tool is needed; Security Assessments can review the surrounding policy only.
ID.AM-08Systems/hw/sw/services/data are managed through their lifecycle
ID.AM-08.2K
OS and critical-component security patches and updates must be installed.
Platform
Vulnerability Management detects missing OS/component patches directly; ITSM tracks each to closure.
ID.AM-08.3
Accountability enforced for business-critical assets across their lifecycle, including disposal and transfers.
Platform + Services
Assets tracks lifecycle status (active/retired/disposed). The accountability process itself is the client's; Programme Design can define it.
ID.AM-08.4
Measures taken to address loss, misuse, damage or theft of assets.
Client-owned
Physical/operational asset-protection measures — outside platform and service scope.
ID.AM-08.6
Preventive maintenance and repairs of critical system components planned, performed and documented per approved processes.
Client-owned
Physical hardware maintenance and repairs — outside scope.
ID.AM-08.8
Maintenance tools for critical systems pre-approved, monitored and enforced.
Client-owned
Maintenance-tool approval/enforcement — outside scope.
ID.AM-08.11
Remote maintenance/diagnostic activities on organizational assets pre-approved, performance recorded.
Platform + Services
Cloud Security's remote-access/IAM review covers the authorization process for remote maintenance sessions.
ID.AM-08.12
Non-local maintenance/diagnostic sessions require strong authenticators; connections terminated once maintenance completes.
Platform + Services
Cloud Security reviews remote-access authentication configuration for maintenance sessions.

Risk Assessment (ID.RA)

ID.RA-01Asset vulnerabilities are identified, validated, recorded
ID.RA-01.1
Threats and vulnerabilities identified across all relevant assets, including software, network/system architectures, and facilities.
Platform + Services
Vulnerability Management covers software/network/system assets directly. Facilities are outside scope.
ID.RA-01.2
A process established for continuous monitoring, identification and documentation of vulnerabilities on business-critical systems.
Platform
Scheduled Scans: a standing process for continuous vulnerability monitoring/identification/documentation.
ID.RA-01.3
A documented process for continuous review, analysis and remediation of vulnerabilities, with information sharing where relevant.
Platform
Findings review/remediation workflow, with CVE enrichment for information sharing.
ID.RA-01.5
Vulnerability scanning must not negatively affect system functions.
Platform
actasec's scanning is designed not to disrupt target systems — a direct product characteristic.
ID.RA-01.6
Vulnerabilities identified and managed across all relevant assets, including software, network/system architectures and facilities.
Platform + Services
Vulnerability Management covers software/network/system assets directly; facilities remain outside scope.
ID.RA-02Cyber threat intel is obtained from forums/sharing sources
ID.RA-02.1
A threat/vulnerability awareness program implemented, including inter-organizational information-sharing capability.
Platform + Services
CVE/NVD enrichment on findings is native. SOC-as-a-Service adds live threat-intel feeds and campaign/IOC mapping.
ID.RA-03Internal/external threats are identified & recorded
ID.RA-03.1
Threats identified and assessed against all relevant assets, including software, network/system architectures and facilities.
Platform + Services
Findings and Risk Register cover IT-asset threats; facilities-related threats stay outside scope.
ID.RA-05Threats/vulnerabilities/likelihood/impact are used to understand inherent risk & prioritize response
ID.RA-05.1
Risk assessments conducted where risk is determined from threats, vulnerabilities and impact on organizational processes/assets.
Platform
Risk Register: risk determined from threats, vulnerabilities and business impact — its core function.
ID.RA-05.2
Risk assessments conducted and documented, incorporating likelihood of occurrence alongside threats/vulnerabilities/impact.
Platform
Risk Register documents likelihood alongside impact, threats and vulnerabilities.
ID.RA-06Risk responses are chosen, prioritized, planned, tracked, communicated
ID.RA-06.1
Risk responses identified, prioritized, planned, tracked and communicated.
Platform
Risk Register treatment plans + Findings remediation tracking + ITSM tickets.
ID.RA-08A process exists for receiving/analyzing/responding to vulnerability disclosures (incl. CVD)
ID.RA-08.1K
A vulnerability management plan established and implemented to identify, analyze, evaluate, mitigate and communicate all vulnerability types, including coordinated vulnerability disclosure (CVD).
Platform + Services
Vulnerability Management runs the internal vulnerability lifecycle. Programme Design formalizes the external coordinated-disclosure (CVD) intake process.

Improvement (ID.IM)

ID.IM-02Improvements are identified from security tests/exercises, incl. with suppliers
ID.IM-02.1
Security tests and exercises, including with relevant suppliers/third parties, used to identify areas needing improvement.
Platform
Penetration Testing + Vulnerability Scans results feed directly into Findings/remediation for improvement tracking.
ID.IM-03Improvements are identified from operational execution (lessons learned)
ID.IM-03.1
Post-incident reviews performed to analyze lessons learned from response & recovery, improving processes/procedures/technologies.
Platform + Services
ITSM incident history exists. CISO-as-a-Service runs the formal post-incident/lessons-learned review.
ID.IM-03.2
Lessons learned integrated into updated or new incident-management procedures, backed by appropriate training after review/approval/testing.
Platform + Services
CISO-as-a-Service integrates lessons learned into updated procedures; Training Suite delivers the resulting training.
ID.IM-03.3
Improvements from monitoring, metrics, evaluations and lessons learned translated into improved processes/procedures/technologies (continuous improvement).
Platform + Services
CISO-as-a-Service drives continuous improvement from monitoring/metrics/lessons learned.
ID.IM-03.4
Collaboration and information-sharing about security incidents on critical systems and mitigations with designated partners.
Platform + Services
Vendor Management provides the partner context; CISO-as-a-Service coordinates the actual information-sharing.
ID.IM-03.5
Effectiveness of protection technologies communicated to relevant stakeholders.
Platform + Services
VM/Risk Register reporting views supply the data; CISO-as-a-Service packages it for stakeholders.
ID.IM-03.6
Automated mechanisms implemented, where possible, to facilitate information-sharing and collaboration.
Platform + Services
ITSM notifications automate internal sharing; broader cross-org automation is the client's IT.
ID.IM-04Incident response & continuity plans are established, communicated, maintained
ID.IM-04.1
Emergency and continuity plans established, communicated, maintained, tested, validated and improved.
Platform + Services
Documents Library hosts the plan; ITSM Incidents is the execution engine. Programme Design/CISO-as-a-Service write and test it.
Protect66% · 5 platform / 24 combined / 15 client-owned

Identity Management, Authentication & Access Control (PR.AA)

PR.AA-01Identities/credentials of users, services, equipment are managed
PR.AA-01.1K
Identities and credentials of authorized users, services and equipment must be managed.
Platform + Services
actasec's own login (SSO, MFA) manages this directly for platform access. Cloud Security's IAM risk analysis extends it across the client's broader environment.
PR.AA-01.2
Identities and credentials managed through automated mechanisms wherever possible.
Platform + Services
actasec's own identity management is already automated (Keycloak-based). Cloud Security reviews automation client-wide.
PR.AA-02Identities are verified before issuing credentials
PR.AA-02.1
Documented procedures implemented to verify a person's identity before issuing credentials granting access to organizational systems.
Client-owned
An HR/IT process. Programme Design can document the procedure; execution stays with the client.
PR.AA-03Users/services/hardware are authenticated, incl. wireless config & MFA for remote access
PR.AA-03.1
All wireless access points, including guest access, securely configured, managed and monitored to prevent unauthorized access.
Client-owned
Wireless network hardware configuration — outside platform scope; Cloud Security/Penetration Testing can assess wireless security as part of an engagement.
PR.AA-03.2K
Multi-factor authentication (MFA) must be mandatory for remote access to organizational networks.
Platform + Services
MFA/OTP is enforced directly on actasec platform access. Cloud Security validates and extends MFA across the client's remote-access/VPN systems.
PR.AA-03.3K
Usage restrictions, connection requirements and authorization procedures defined, documented and implemented for remote access to critical systems.
Platform + Services
Cloud Security's IAM and network review, documented through Programme Design.
PR.AA-05Access permissions, least privilege & separation of duties
PR.AA-05.1K
Access permissions, rights and authorizations defined, managed, enforced and reviewed.
Platform + Services
actasec's own module-permission system does this for the platform. Cloud Security's IAM analysis covers the client's wider environment.
PR.AA-05.2K
Established who needs access to critical information/technology and by what means they obtain it.
Platform + Services
Cloud Security's IAM risk analysis identifies who needs access to what across the client's environment.
PR.AA-05.3K
Access rights, privileges and authorizations restricted to what's specifically needed for the role (least privilege).
Platform + Services
actasec's own RBAC directly enforces least privilege for the platform. Cloud Security's IAM review covers the client's wider environment.
PR.AA-05.4K
No one should hold administrative privileges for routine, day-to-day tasks.
Platform + Services
Cloud Security's IAM analysis surfaces over-privileged accounts for remediation.
PR.AA-05.5
Automated mechanisms for user-account management on critical ICT/OT systems implemented where technically, operationally and economically feasible.
Client-owned
Automation of account management on critical ICT/OT systems is the client's IT; Cloud Security's IAM review recommends where to automate.
PR.AA-05.6
Separation of duties (SoD) ensured in the management of access rights.
Platform + Services
Cloud Security's IAM review checks for separation-of-duties violations.
PR.AA-05.7
Privileged users managed and monitored.
Platform + Services
SOC-as-a-Service's EDR/monitoring covers privileged-user activity; Cloud Security covers management.
PR.AA-06Physical access to organizational assets is managed
PR.AA-06.1
Physical access to all organizational assets, including critical zones, managed, monitored and enforced by risk.
Client-owned
Physical security (badges, guards, locks) — outside scope. Penetration Testing's physical-access scenarios validate controls.
PR.AA-06.2
Physical access controls include specific emergency procedures, ensuring continued protection of critical/non-critical assets during such events.
Client-owned
Facilities emergency procedures — outside scope.

Awareness & Training (PR.AT)

PR.AT-01General staff receive security awareness & training
PR.AT-01.1
A cybersecurity awareness & training program established and maintained so all staff understand how to perform tasks securely and responsibly.
Platform
Security Awareness Training module: an ongoing program for all staff.
PR.AT-01.2
Cybersecurity training includes insider-threat awareness and reporting, to help staff recognize and respond to potential internal risks.
Platform
Training Suite content covers insider-threat awareness and reporting.
PR.AT-01.3
Staff trained to understand roles, responsibilities and priorities during a cyber/information-security incident, including response steps.
Platform
Training Suite covers incident roles/responsibilities as part of role-based learning paths.
PR.AT-02Specialized roles receive targeted awareness & training
PR.AT-02.1
Governing-body members able to demonstrate cyber/info-security and risk-management training enabling them to evaluate risk and propose mitigations.
Platform
Training Suite's role-based learning paths cover leadership/governing-body training directly.
PR.AT-02.2
Specialized-role personnel receive awareness/training before privileges are granted.
Platform + Services
Training Suite delivers the training itself; gating privilege-grant on completion is a process tied to Cloud Security's IAM review, not a native platform gate.
PR.AT-02.3
Privileged users qualified before privileges are granted and can demonstrate understanding of their roles/responsibilities/authorities.
Platform + Services
Same — Training Suite delivers training, Cloud Security's IAM review can gate privilege issuance on it.

Data Security (PR.DS)

PR.DS-01Confidentiality/integrity/availability of stored data is protected, incl. removable media
PR.DS-01.1
Integrity checks implemented for software/firmware/information to detect unauthorized changes to critical system components.
Platform + Services
Cloud Security's data protection review covers integrity controls for cloud-hosted components. SOC-as-a-Service's EDR provides file-integrity-style monitoring at the endpoint.
PR.DS-01.4
Clear policies and practical protections defined and applied to manage/restrict portable storage media, reducing leak/malware risk.
Client-owned
Removable-media/endpoint controls — outside scope. Programme Design can write the governing policy.
PR.DS-01.5
Removable media use permitted only when strictly necessary, with technical measures blocking autorun execution.
Client-owned
Removable-media technical controls (autorun blocking) — outside scope.
PR.DS-01.9
Organizational assets must be safely disposed of.
Client-owned
Physical asset disposal — outside scope. Programme Design can document the procedure.
PR.DS-11Data backups are created, protected, tested
PR.DS-11.1K
Backups of critical organizational data made and stored on a system different from the device holding the original data.
Client-owned
actasec doesn't operate backup infrastructure. Security Assessments can review backup policy and evidence, but the backup solution itself is the client's.
PR.DS-11.2
Reliability and integrity of backups verified and tested regularly.
Client-owned
Backup testing/verification — same, evidence review only via Security Assessments.
PR.DS-11.3
Secure backup copies of critical data kept in a separate storage location with security controls equivalent to the primary environment.
Client-owned
Offsite backup storage & controls — the client's backup infrastructure.

Platform Security (PR.PS)

PR.PS-01Configuration management practices are established
PR.PS-01.1K
A baseline configuration developed, documented and maintained for business-critical systems.
Platform + Services
Cloud Security's CIS Benchmark hardening and Infrastructure-as-Code review deliver a documented baseline configuration directly.
PR.PS-02Software is maintained/replaced/retired by risk
PR.PS-02.1
Software usage/installation restrictions applied; software maintained, replaced or removed based on associated risk.
Platform + Services
SCA findings flag outdated/vulnerable components. Cloud Security extends this to infrastructure-level configuration.
PR.PS-03Hardware is maintained/replaced/retired by risk
PR.PS-03.1
Hardware used in business-critical environments maintained, replaced or removed based on associated security/operational risk.
Client-owned
Hardware maintenance/replacement decisions are the client's IT operations; Assets tracks status but doesn't drive it.
PR.PS-04Log records are generated & available for monitoring
PR.PS-04.1K
Logs should be maintained, documented and monitored.
Platform + Services
SOC-as-a-Service's SIEM deployment and management delivers this directly.
PR.PS-04.2K
Log records include an authorized time source or internal clock timestamp compared/synchronized against an authorized time source.
Platform + Services
Time-source synchronization is standard configuration within SOC-as-a-Service's SIEM deployment.
PR.PS-04.3
Audit data from critical organizational systems transferred to an alternate system.
Platform + Services
SOC-as-a-Service's log ingestion/SIEM aggregation transfers audit data to an alternate system by design.
PR.PS-05Unauthorized software install/execution is prevented, incl. web/email filtering
PR.PS-05.1
Web and email filters must be installed and used.
Client-owned
Web/email filtering gateway — typically the client's existing email/security stack; SOC-as-a-Service can ingest its logs.
PR.PS-05.2
Installation and execution of unauthorized software must be prevented.
Platform + Services
SOC-as-a-Service's EDR integration prevents/contains unauthorized software execution.
PR.PS-06Secure software development practices are integrated & monitored
PR.PS-06.1
Security considered throughout the lifecycle of systems and applications, whether developed in-house or acquired externally.
Platform
SAST scanning built into the Applications module covers in-house development directly; Cloud Security reviews acquired/cloud systems.
PR.PS-06.2
Changes and exceptions tested and validated before deployment to operational systems.
Platform + Services
SAST/pipeline scanning supports this; the change-management gate itself is the client's process.

Technology Infrastructure Resilience (PR.IR)

PR.IR-01Networks/environments are protected from unauthorized logical access (firewalls, segmentation)
PR.IR-01.1K
Firewalls installed, configured and actively updated across all networks used by the organization to protect against unauthorized access and cyber threats.
Platform + Services
actasec's DAST/port scanning detects exposure from missing firewall controls. Cloud Security and Penetration Testing directly review and harden firewalls.
PR.IR-01.2K
Network segmentation and segregation implemented in line with trust boundaries and asset criticality to limit threat propagation.
Platform + Services
Cloud Security's network security assessment and CIS hardening deliver segmentation review directly.
PR.IR-01.3K
Connections between critical system components identified, documented and controlled, without exception.
Platform + Services
Cloud Security's network exposure mapping and Penetration Testing's infrastructure assessment.
PR.IR-01.4K
Adequate boundary-protection measures implemented to monitor/control communications at key external/internal system boundaries (IT and OT).
Platform + Services
Cloud Security and Penetration Testing review and harden network boundary controls directly.
PR.IR-02Technology assets are protected from environmental threats
PR.IR-02.1
Policies and procedures for emergency/safety systems, fire protection systems and environmental controls defined, implemented and maintained for critical systems.
Client-owned
Physical/environmental controls (fire suppression, HVAC) — the client's facilities management.
PR.IR-04Adequate resource capacity exists to maintain availability
PR.IR-04.1
Adequate resource capacity planning to maintain availability of critical systems (information processing, networks, telecoms, data storage).
Client-owned
Infrastructure/cloud capacity planning; Cloud Security can review cloud-side capacity as part of its assessment.
Detect93% · 3 platform / 10 combined / 1 client-owned

Continuous Monitoring (DE.CM)

DE.CM-01Networks/network services are monitored, incl. firewalls & anti-malware
DE.CM-01.1
Firewalls installed and operated at network boundaries, including endpoint-level firewalls.
Platform + Services
Cloud Security and Penetration Testing review/configure boundary firewalls; SOC-as-a-Service monitors them ongoing.
DE.CM-01.2K
Antivirus, anti-spyware and other anti-malware programs must be installed and kept updated.
Platform + Services
SOC-as-a-Service's EDR integration is the modern superset of traditional antivirus/anti-malware.
DE.CM-01.3K
Unauthorized use of business-critical systems monitored and identified, through detection of unauthorized local, network, and remote connections.
Platform + Services
SOC-as-a-Service's 24/7 monitoring and EDR detect unauthorized local/network/remote system use.
DE.CM-02The physical environment is monitored
DE.CM-02.1
The physical environment must be monitored to identify potentially adverse events.
Client-owned
Physical security systems — outside platform and service scope.
DE.CM-03Personnel activity & technology use are monitored
DE.CM-03-1
Endpoint and network protection tools implemented to monitor end-user behavior for risky activity.
Platform + Services
SOC-as-a-Service's EDR integration monitors end-user behavior for risky activity.
DE.CM-03.2
Endpoint and network protection tools that monitor end-user behavior for risky activity must be managed.
Platform + Services
SOC-as-a-Service manages the endpoint/network protection tooling on an ongoing basis.
DE.CM-06External service-provider activities are monitored
DE.CM-06.1
External service-provider activities and services secured and monitored to identify potentially adverse events.
Platform + Services
Vendor Management provides the review cadence; SOC-as-a-Service extends monitoring to vendor-connected systems.
DE.CM-06.2
External service-provider compliance with personnel security policies/procedures and contractual security requirements monitored against their cyber risk.
Platform + Services
Vendor Management tracks contractual compliance; CISO-as-a-Service provides ongoing oversight.
DE.CM-09Computing hardware/software, runtimes & data are monitored for adverse events
DE.CM-09.1
Computing hardware/software, runtime environments and their data monitored to detect potentially adverse events.
Platform + Services
Scheduled Scans re-check assets recurrently; SOC-as-a-Service and Cloud Security's CSPM add continuous runtime monitoring.

Adverse Event Analysis (DE.AE)

DE.AE-02Adverse events are analyzed to understand associated activities
DE.AE-02.1
Cyber/information-security events reviewed and analyzed to identify potential targets and attack methods, per applicable laws/standards/policies.
Platform + Services
Findings triage/review workflow is native; SOC-as-a-Service analysts triage security events 24/7.
DE.AE-03Information is correlated from multiple sources
DE.AE-03.1K
Logging functionality of protection/detection tools enabled; logs saved, retained for a predefined period and periodically reviewed for unusual/harmful activity.
Platform + Services
SOC-as-a-Service's SIEM/log management enables and retains logging; platform activity logs cover the vulnerability-management side.
DE.AE-03.2
Event data from critical systems collected and correlated using information from multiple relevant sources.
Platform
Vulnerability Management consolidates results across all scanner inputs into one source of truth — its core design.
DE.AE-06Adverse-event information is delivered to authorized personnel/tools
DE.AE-06.1
Adverse-event information transmitted promptly to authorized personnel/systems, enabling timely detection, investigation and response.
Platform
Create-Incident-from-Finding integration + assignee notifications deliver this directly.
DE.AE-08Incidents are declared when adverse events meet defined criteria
DE.AE-08.1
Incidents reported when adverse events meet defined, documented incident criteria.
Platform
ITSM Incidents module: incidents are declared against defined, documented criteria.
Respond100% · 3 platform / 6 combined / 0 client-owned

Incident Management (RS.MA)

RS.MA-01The incident response plan is executed in coordination with relevant third parties
RS.MA-01.1
An incident response plan, with defined roles/responsibilities/authorities, put into action during or after a cyber event affecting critical systems.
Platform
ITSM Incidents is the execution engine, with roles assigned via Resolver Groups.
RS.MA-01.2
Response actions to information/cyber-security incidents coordinated with all predefined stakeholders.
Platform + Services
ITSM comments/notifications coordinate internal stakeholders; CISO-as-a-Service coordinates complex/executive-level incidents.
RS.MA-02Incident reports are triaged & validated
RS.MA-02.1
Incident reports triaged and validated in line with the organization's incident-response procedures.
Platform
ITSM Incidents triage workflow.
RS.MA-03Incidents are classified & prioritized
RS.MA-03.1
Incidents classified, prioritized and escalated per the incident response plan.
Platform
Impact/urgency/priority fields with automatic priority derivation and escalation via resolver groups.
RS.MA-05Criteria are applied to initiate incident recovery
RS.MA-05.1
Clear criteria defined and applied to determine when incident-recovery processes should be initiated.
Platform + Services
ITSM status workflow supports the transition to recovery; explicit criteria are documented via Programme Design.

Incident Response Reporting & Communication (RS.CO)

RS.CO-02Internal/external stakeholders are informed of incidents
RS.CO-02.1
Cybersecurity incident information communicated to employees clearly and understandably.
Platform + Services
ITSM notifies assignees directly; broader all-employee communication is a CISO-as-a-Service-led process.
RS.CO-02.2K
Cybersecurity incidents communicated to relevant external stakeholders within IR-plan-defined timelines, including reporting significant incidents to authorities per legal requirements.
Platform + Services
ITSM tracks the incident timeline; CISO-as-a-Service provides direct regulatory notification guidance (e.g. DNSC/NIS2 reporting).

Incident Mitigation (RS.MI)

RS.MI-01Incidents are contained & eradicated
RS.MI-01.1
Cybersecurity incidents limited and eliminated; any decision to accept/retain certain cyber risks formally documented.
Platform + Services
ITSM status tracking + Risk Register record formal risk-acceptance decisions; SOC-as-a-Service/CISO-as-a-Service lead actual containment.
RS.MI-01.2K
Unauthorized access or data leaks detected and appropriately mitigated, including monitoring of critical systems at external boundaries and key internal points.
Platform + Services
SOC-as-a-Service's EDR/SIEM monitoring plus analyst containment action.
Recover60% · 0 platform / 3 combined / 2 client-owned

Incident Recovery Plan Execution (RC.RP)

RC.RP-01The recovery portion of the incident response plan is executed
RC.RP-01.1
A disaster and information/cyber-security-incident recovery process developed and executed.
Platform + Services
An ITSM ticket tracks recovery tasks; Programme Design/CISO-as-a-Service design the DR/recovery process itself.
RC.RP-05Restored asset integrity is verified, normal operation confirmed
RC.RP-05.1
Integrity of restored systems/assets verified before returning to service; systems/services fully restored and normal operation confirmed.
Client-owned
Real-time restoration verification is the client's DR operation; Security Assessments can validate after the fact.
RC.RP-06Incident recovery completion is declared & documentation completed
RC.RP-06.1
Incident-recovery completion formally declared based on predefined criteria; all incident-related documentation completed and reviewed.
Platform + Services
ITSM incident closure and documentation cover most of this directly; Programme Design defines the completion criteria upfront.

Incident Recovery Communication (RC.CO)

RC.CO-03Recovery activities & progress are communicated to stakeholders
RC.CO-03.1
Recovery activities and progress restoring operational capabilities communicated to designated internal/external stakeholders per established communication procedures.
Platform + Services
ITSM comments/notifications; CISO-as-a-Service coordinates external stakeholder communication.
RC.CO-04Public updates on incident recovery are communicated
RC.CO-04.1
Public updates on incident recovery communicated using approved communication methods and messages, per established procedures.
Client-owned
CISO-as-a-Service covers the regulatory-notification slice; broader public/PR messaging is the client's communications function.

This is actasec’s own technical mapping against our shipped features and live service offerings — it is not a certified CyFun or NIS2 compliance audit, and coverage of a requirement does not by itself make an organization compliant. Most requirements also need organizational policy, procedure, and evidence that we can help produce but that the client must still own.

Get started

Talk to us about NIS2 readiness

We’ll walk through where your organization stands today and what combination of platform and services gets you to a defensible CyFun®2025 assessment.

Request a Consultation →