NIS2 evidence

Supply-chain evidence for NIS2, generated as part of the tested PR review.

Article 21(2)(d) makes supplier relationships auditable. Bivouac records every CVE → fix → test → review state with a deterministic hash, then bundles a signed export per quarter. Your auditor replays the file; the same data hashes to the same root. No end-of-quarter fire-drill. Evidence for your audit, not a Bivouac certification.

Article 21(2)(b) · incident handlingArticle 21(2)(d) · supply-chain securityArticle 21(2)(e) · systems acquisitionArticle 23 · reporting obligations

Article 21 mapped to the review log

What NIS2 asks for, and what Bivouac already records.

The obligations on the left are the law. The matchings on the right are what your auditor replays when they ask for evidence — already captured per review, no end-of-quarter rebuild required. Bivouac supports your NIS2 evidence workflow; Bivouac is itself not certified against the framework.

NIS2 obligation
Bivouac evidence
  1. Article 21(2)(d)

    Supply-chain security, including security-related aspects of supplier relationships

    Every dependency edge — direct and transitive — is enumerated per quarter in the SBOM rollup, with the version that shipped to production tagged. Vendor advisories attach to the exact package and version they affected.

  2. Article 21(2)(e)

    Security in network and information systems acquisition, development and maintenance

    Patch PRs open against the actual project repo and run the actual test suite; green results make them ready for human approval. The full chain — signal, policy-pack decision, test run, review state — is recorded, not just a resulting commit.

  3. Article 21(2)(b)

    Incident handling — prevention, detection, and response

    A new CVE fires a signal within minutes. The policy pack pre-classifies the move (forward fix, downgrade, pin) and a draft PR is in front of you with the test outcome attached as a status check.

  4. Article 21(2)(c)

    Business continuity and crisis management, including backup management

    Tested patch PRs keep the production tree reviewable without waiting for an on-call rotation. The review log shows the decision context and any human approval at every widening.

  5. Article 23

    Reporting obligations — early warning, incident notification, and final report

    Every patch carries its CVE id, the upstream disclosure date, and the review timestamp in the same row. The signed bundle is the report — there is no separate paper trail to keep aligned with the code.

Proof, not a promise

One signed bundle per quarter — replayable, hash-verifiable.

Pick a connected repo and a calendar quarter from /dashboard/attestand download the bundle. Every patch event, test outcome, merge vs human override, CVE id, and SBOM rollup is in the same JSON — and on the cover of the branded PDF. The attestation hash is deterministic, so the same data always hashes to the same root. Your auditor's replay matches yours, byte for byte. Bivouac produces the evidence; the certification is your team's, earned in your audit.

Signed attestation export

Quarter-scoped, deterministic-hashed, downloadable as JSON or PDF. The bundle is the only artifact your auditor needs — coverage, decision provenance, and SBOM provenance all live in the same signed root.

sha256: 9f3a8c…b21e d1c2a7…94f3 5b88e0…1ab6 e2c5d4…7f80
Open the signed export

From signal to evidence

Four steps run end to end — the same trail your auditor replays.

Nothing on this list is reconstructed at the end of the quarter. Every step is a row in the signed bundle, in order, with the policy-pack decision and the SBOM provenance/per-build software-bill-of-materials attached to the last one.

  1. 01

    Signal fires

    New CVE, upstream breaking change, or package-registry disclosure on a watched repo.

  2. 02

    Policy pack decides

    Forward fix, downgrade, or pin chosen locally — license posture, peer usage, and security-sensitive surfaces reviewed before any code is touched.

  3. 03

    Test outcome recorded

    Project test suite runs against the draft PR; the pass/fail trail attaches to the review row, not just a resulting commit.

  4. 04

    Review or human escalation

    Green tests produce a reviewable PR; security-sensitive surfaces stop at a human. SBOM provenance — vendor, version, parent edge — is stamped per review.

NIS2 buyer questions

The questions your auditor and your CISO will ask first.

Bivouac produces the evidence your team hands to the auditor — it isn't itself NIS2 certified.

Generate, sign, ship

Generate your first signed attestation this quarter.

Connect a repo, review a tested patch, and the bundle hashes itself. By the time your auditor opens the export, the file is already self-verifying. Bivouac produces the evidence your team hands to the auditor — it isn't itself NIS2 certified.

Free for the first repo. No card to start.