Dir. (EU) 2022/2555Evidence pack
NIS2
NIS2 applies to essential and important entities across 11 sectors (in Italy via D.Lgs. 138/2024, ACN as the competent authority). Nyx covers the AI-specific slice of the Art. 21 security measures that traditional tooling misses, and exports a NIS2 evidence pack.
| Reference | Requirement | Nyx capability |
|---|---|---|
| Art. 21(2)(a) | Risk analysis & security policies | Automated risk scoring across registered AI systems, governed by signed enforcement policy |
| Art. 21(2)(b) | Incident handling | Automated detection and severity triage on AI pipelines with webhook escalation |
| Art. 21(2)(d) | Supply-chain security | Monitoring and scoring of AI model providers across jurisdictions |
| Art. 21(2)(e) | Acquisition & development security | AI traffic interception with policy-based blocking and PII redaction |
| Art. 21(2)(i) | Cryptography & access control | Argon2id, signed policies, TLS, RBAC with five roles and API-key agent auth |
| Art. 23 | Incident reporting (24h / 72h / 1 month) | Severity-classified incidents with on-demand reports in PDF / CSV / JSON |
Nyx addresses the AI attack surface — prompt injection, data exfiltration via LLM, model-provider dependency — and produces the records an auditor needs to verify the Art. 21 measures are in place.
The information on this page is for informational purposes and does not constitute legal advice. For an assessment specific to your organization, consult a qualified professional. Nyx reports are evidence packs — control, requirement, metrics and reasoning — not a compliance verdict.