Supply-chain evidence for NIS2, generated as part of the tested PR review.
Article 21(2)(d) makes supplier relationships auditable. Bivouac records every CVE → fix → test → review state with a deterministic hash, then bundles a signed export per quarter. Your auditor replays the file; the same data hashes to the same root. No end-of-quarter fire-drill. Evidence for your audit, not a Bivouac certification.
Article 21 mapped to the review log
What NIS2 asks for, and what Bivouac already records.
The obligations on the left are the law. The matchings on the right are what your auditor replays when they ask for evidence — already captured per review, no end-of-quarter rebuild required. Bivouac supports your NIS2 evidence workflow; Bivouac is itself not certified against the framework.
- Article 21(2)(d)
Supply-chain security, including security-related aspects of supplier relationships
Every dependency edge — direct and transitive — is enumerated per quarter in the SBOM rollup, with the version that shipped to production tagged. Vendor advisories attach to the exact package and version they affected.
- Article 21(2)(e)
Security in network and information systems acquisition, development and maintenance
Patch PRs open against the actual project repo and run the actual test suite; green results make them ready for human approval. The full chain — signal, policy-pack decision, test run, review state — is recorded, not just a resulting commit.
- Article 21(2)(b)
Incident handling — prevention, detection, and response
A new CVE fires a signal within minutes. The policy pack pre-classifies the move (forward fix, downgrade, pin) and a draft PR is in front of you with the test outcome attached as a status check.
- Article 21(2)(c)
Business continuity and crisis management, including backup management
Tested patch PRs keep the production tree reviewable without waiting for an on-call rotation. The review log shows the decision context and any human approval at every widening.
- Article 23
Reporting obligations — early warning, incident notification, and final report
Every patch carries its CVE id, the upstream disclosure date, and the review timestamp in the same row. The signed bundle is the report — there is no separate paper trail to keep aligned with the code.
Proof, not a promise
One signed bundle per quarter — replayable, hash-verifiable.
Pick a connected repo and a calendar quarter from /dashboard/attestand download the bundle. Every patch event, test outcome, merge vs human override, CVE id, and SBOM rollup is in the same JSON — and on the cover of the branded PDF. The attestation hash is deterministic, so the same data always hashes to the same root. Your auditor's replay matches yours, byte for byte. Bivouac produces the evidence; the certification is your team's, earned in your audit.
Quarter-scoped, deterministic-hashed, downloadable as JSON or PDF. The bundle is the only artifact your auditor needs — coverage, decision provenance, and SBOM provenance all live in the same signed root.
From signal to evidence
Four steps run end to end — the same trail your auditor replays.
Nothing on this list is reconstructed at the end of the quarter. Every step is a row in the signed bundle, in order, with the policy-pack decision and the SBOM provenance/per-build software-bill-of-materials attached to the last one.
- 01
Signal fires
New CVE, upstream breaking change, or package-registry disclosure on a watched repo.
- 02
Policy pack decides
Forward fix, downgrade, or pin chosen locally — license posture, peer usage, and security-sensitive surfaces reviewed before any code is touched.
- 03
Test outcome recorded
Project test suite runs against the draft PR; the pass/fail trail attaches to the review row, not just a resulting commit.
- 04
Review or human escalation
Green tests produce a reviewable PR; security-sensitive surfaces stop at a human. SBOM provenance — vendor, version, parent edge — is stamped per review.
NIS2 buyer questions
The questions your auditor and your CISO will ask first.
Bivouac produces the evidence your team hands to the auditor — it isn't itself NIS2 certified.
Generate, sign, ship
Generate your first signed attestation this quarter.
Connect a repo, review a tested patch, and the bundle hashes itself. By the time your auditor opens the export, the file is already self-verifying. Bivouac produces the evidence your team hands to the auditor — it isn't itself NIS2 certified.
Free for the first repo. No card to start.