
Continuous compliance auditing (NIS2, DORA, CRA, and ISO 27001)

NIS2
NIS2 Directive
Essential and important entities. Applicable since October 2024.
NIS2 requires organizations to implement proportionate cyber risk management measures. Cyberwatch supports you with the following:
Cyber risk management
Asset inventory, continuous vulnerability detection, contextual prioritization, and tracked remediation with SLA monitoring.
- Item 1
- Item 2
- Item 3
Vulnerability management
Continuous agent-based or agentless scanning, integrated patch management, mean time to remediate (MTTR) tracking, and proof of remediation.
- Item 1
- Item 2
- Item 3
Supply chain security
Software Composition Analysis (SCA), EOL component detection, SBOM generation (CycloneDX/SPDX), and compromised package detection
- Item 1
- Item 2
- Item 3
Measure effectiveness
Continuous compliance scoring, real-time dashboards, and audit evidence export.
- Item 1
- Item 2
- Item 3
Network and system security
CIS Benchmark audits and ANSSI guidelines to verify system hardening, active EDR presence, and network equipment configuration
- Item 1
- Item 2
- Item 3
Access Control and Identities
Active Directory and Entra ID auditing: privileged accounts, MFA coverage, conditional access policies, GPOs, and risky delegations.
- Item 1
- Item 2
- Item 3
Dora
Digital Operational Resilience Act (DORA)
Financial sector. Applicable since January 2025.
DORA requires financial institutions to rigorously manage their ICT risks. Cyberwatch supports you with the following:

ICT Risk Management
Comprehensive ICT asset inventory, vulnerability detection and remediation, continuous exposure monitoring, and executive reporting.
- Item 1
- Item 2
- Item 3
Operational resilience testing
Regular vulnerability scans, DAST testing on exposed web applications, and post-patch re-scanning as proof of effective remediation.
- Item 1
- Item 2
- Item 3
ICT third-party risk
SCA and SBOM to track third-party software dependencies integrated into your systems. Detection of obsolete or compromised components.
- Item 1
- Item 2
- Item 3
Context for incident reporting
Cyberwatch provides the vulnerability context needed for reporting: which CVEs, which assets are affected, the severity level, and the remediation deadline.
- Item 1
- Item 2
- Item 3
CRA
Cyber Resilience Act (CRA)
Digital product security. Phased implementation starting in 2026.
The CRA requires digital product manufacturers to manage vulnerabilities and document their components throughout the product lifecycle. Cyberwatch supports you with the following:

Mandatory SBOM
Automated generation of CycloneDX and SPDX component manifests with every build.
Product vulnerability management
Continuous dependency scanning to detect new CVEs after every release. Full traceability from discovery to remediation.
End-of-life components
Detection of EOL libraries and proactive alerts before the end-of-support date.
Post-market surveillance
Continuous analysis of third-party components after deployment: new CVEs, compromised packages, and obsolete dependencies reported in real time.
ISO
ISO 27001:2022
Information Security Management System
ISO 27001 structures information security around technical and organizational controls. Cyberwatch supports you with the following:
Technical vulnerability management
Continuous scanning, contextual prioritization, patch management, and reporting.
- Item 1
- Item 2
- Item 3
Configuration management
CIS Benchmark audits, ANSSI guidelines, and custom rules. Continuous compliance scoring with automatic drift detection.
- Item 1
- Item 2
- Item 3
Asset inventory
Automatic discovery and centralized inventory of all IT assets, updated in real time.
- Item 1
- Item 2
- Item 3

Software installation and monitoring
Patch management, version control, and detection of unauthorized or obsolete components.
- Item 1
- Item 2
- Item 3
Secure coding and supply chain
SCA, SBOM generation, and EOL and compromised package detection for development teams.
- Item 1
- Item 2
- Item 3
Malware protection
Verify that the EDR is properly installed and active across your entire fleet using the compliance module. Cyberwatch audits the presence of your protection without replacing it.
- Item 1
- Item 2
- Item 3
Testimonials
FAQ
From asset mapping to automated remediation.
How does Cyberwatch help companies comply with the NIS2 directive?
Since October 2024, the NIS2 directive has applied to essential and important entities in critical sectors, including energy, healthcare, transport, and digital services. It mandates the implementation of cyber risk management measures, such as asset mapping, vulnerability management, and configuration hardening. Cyberwatch automates the generation of audit evidence.
How does Cyberwatch help companies comply with the DORA regulation?
The Digital Operational Resilience Act (DORA) has applied to financial and insurance institutions since January 2025. It mandates rigorous management of information and communication technology (ICT) risks, including resilience testing and vulnerability management. Cyberwatch continuously audits the areas within its technical visibility to support this compliance.
What obligations does the Cyber Resilience Act impose regarding vulnerability management?
The Cyber Resilience Act requires designers and publishers of digital products to ensure continuous vulnerability management. They must identify flaws, fix them, and provide security updates. Starting September 11, 2026, any actively exploited vulnerability must be reported to ENISA and the relevant authorities via a dedicated platform.
How does Cyberwatch help with ISO 27001:2022 compliance?
ISO 27001 structures information security around technical and organizational controls defined in Annex A. Cyberwatch automates these controls (IT asset inventory, vulnerability and configuration management) and the generation of audit evidence, streamlining certification preparation.
What is the "audit trail" automatically generated by Cyberwatch?
An audit trail is a report demonstrating compliance with a specific regulatory control, such as the status of a vulnerability scan, CIS Benchmark compliance levels, or an up-to-date asset inventory. Cyberwatch generates reports that are ready for auditors to use.
Does Cyberwatch cover all the requirements of NIS2, DORA, or the CRA?
No, Cyberwatch covers the areas where it has expertise: vulnerability management, system configuration auditing, and IT asset inventory. These regulations also include organizational requirements (governance, contracts, training, etc.) that fall outside our scope.



