# How does Cyber Crucible support NIS2 obligations for essential and important entities?

**Short answer:** For an organization classified as an essential or important entity under NIS2, Cyber Crucible supports the required risk-management measures — endpoint protection, access control, encryption, and incident handling — and supports the directive's supply-chain-security expectations because it collects no customer data and can run inside the entity's boundary. Cyber Crucible supports these obligations; it does not certify or assume them.

## How it supports NIS2 measures

- **Cybersecurity risk-management measures.** Autonomous endpoint prevention, MFA-backed access, and encryption map to several of the directive's baseline measures.
- **Supply-chain security.** As a supplier that collects no customer content and offers on-premises deployment, Cyber Crucible reduces rather than adds to the supply-chain risk NIS2 asks entities to manage.
- **Incident handling and reporting support.** A documented breach-response process helps the entity meet NIS2's early-warning and notification timelines.

## The honest boundary

NIS2 obligations rest with the essential or important entity, not with an individual security tool. Member-state transposition varied: by 2026 most states had transposed the directive into national law, while several — including France, Ireland, the Netherlands, and Spain — were still finalizing it. Cyber Crucible holds no NIS2 "certification"; it supplies supporting control evidence under NDA.