NIS2 Compliance Proof

NIS2 compliance is proven, not declared.

Under the NIS2 directive, an auditor no longer asks "are you compliant?" but "show me". Proof of compliance: a continuously sealed journal, eIDAS-timestamped and anchored on a public ledger — verifiable by a third party, without taking your word for it.

DIRECT ANSWER

NIS2 compliance proof is the continuous demonstration — not a one-off declaration — that Article 21 measures are met. Every event is sealed (SHA-256 hash), eIDAS-timestamped and anchored on a public ledger: an auditor, insurer or business partner can verify it without trusting your word or the vendor's.

THE THREE DELIVERABLES
01

Sealed journal (SPINA)

Every event is chained to the previous one (Merkle SHA-256). Any past alteration breaks the chain and becomes detectable.

02

eIDAS timestamping

A stamp from a qualified trust provider, with a legal presumption of date accuracy and integrity (Art. 41 eIDAS).

03

Public anchoring

The SHA-256 hash is published on a public ledger (Hedera). Integrity is verifiable by anyone, without an account.

04

Signed monthly dossier

Inventory + journal + anchoring, assembled into a signed dossier you can hand to any auditor.

FAQ
How do I prove my NIS2 compliance?
By presenting continuous, timestamped proof rather than a one-off declaration: a sealed event journal (Merkle SHA-256), eIDAS-timestamped and anchored on a public ledger, assembled into a monthly signed dossier. This is 0DATA's OT Diligence Dossier.
What is NIS2 compliance proof?
The continuous demonstration that Article 21 measures are met: every event is sealed, timestamped and anchored, making integrity and anteriority verifiable by a third party, independently of the vendor.
What should I give an auditor to prove NIS2 compliance?
Three deliverables: the equipment inventory, the continuously sealed event journal, and the qualified timestamp anchoring (eIDAS/QTSP). Together, in a monthly signed dossier, they answer Article 21 for the industrial perimeter.
What is the difference between proving and declaring NIS2 compliance?
Declaring states compliance at a point in time (checklist, report, GRC). Proving demonstrates it continuously: every measurement is sealed and anchored, and any later alteration becomes detectable by a third party.
How much does NIS2 compliance proof cost?
At 0DATA: €15–25k setup, then €2–4k per month per site. Generic sealing costs €0.20 per hash, eIDAS timestamping included.