NIS2 & UK NCSC CAF Compliance

NIS2 and the NCSC CAF both require identity and access control. Your Linux estate is where it is proven.

Energy, water, telecoms, and transport run essential functions on Linux — where operator accounts, integrator access, and shared credentials drift out of view. Our pilot maps every privilege path and delivers evidence aligned to NIS2 Article 21 and NCSC CAF Principle B2.

Why Critical National Infrastructure Makes Linux Identity Visible

  • OT/IT convergence puts long-lived operator and engineering accounts, and shared credentials, on Linux systems supporting essential functions — precisely the identity and access controls NIS2 Article 21(2)(i) and NCSC CAF Principle B2 require you to demonstrate.
  • Supply-chain and integrator access is a named concern under NIS2 Article 21(2)(e) and CAF B2: third parties with sudo on essential-function hosts, often provisioned once and never reviewed. The pilot surfaces every such account and the privileges it holds.
  • NIS2 Article 20 introduces personal liability for board members and senior management — leadership needs defensible evidence of IAM control effectiveness, not a policy PDF. Unmanaged Linux privilege is a documented, reportable control failure.
  • Supervisory authorities and the CAF assessment model both expect continuous control effectiveness, not point-in-time attestation. LinuxGuard detects privilege and configuration drift on a 60-second interval, closing the gap between annual assessment and everyday reality.
  • LinuxGuard uses read-only, lightweight collectors designed not to disrupt sensitive estates — it covers Linux hosts, giving you identity evidence without touching the industrial control protocols themselves.

How the Founding Pilot Addresses NIS2 & UK NCSC CAF Requirements

Every pilot finding is mapped to specific NIS2 & UK NCSC CAF controls, providing direct compliance evidence for your regulatory submissions.

Scroll horizontally to see all columns →

Article / RequirementWhat It MandatesHow the Founding Pilot Covers It
NIS2 Article 21(2)(i)Identity and access managementFull inventory of users, groups, sudo rules, SSH keys, and service accounts on essential-function Linux hosts with privilege path mapping
NIS2 Article 21(2)(a)Risk analysis and information system security policiesRisk-scored findings mapped to exploit patterns and prioritized by impact on the continuity of essential services
NIS2 Article 21(2)(e)Supply chain securityAssessment of integrator and third-party privileges, identifying vendor accounts with excessive or unreviewed access
NCSC CAF Principle B2Identity and access control (verify, authenticate, authorise, least privilege, review)Evidence of privileged-access governance on Linux hosts supporting essential functions, aligned to the B2 outcomes assessed under GovAssure
NIST SP 800-53 (AC)Access control family (secondary, for US-facing CNI)Mapping of Linux access-control findings to the AC control family where NIST baselines apply

What You Get

  • Identity & Privilege Inventory — Every user, group, sudo rule, SSH key, and service account across your Linux estate, showing who can do what
  • Risk-Scored Findings Report — Prioritized findings based on real exploit patterns, highlighting the privilege paths attackers would use first
  • Compliance Evidence Package — Identity governance gaps mapped to NIS2 Article 21 and NCSC CAF Principle B2 controls with remediation guidance
  • Prioritized Remediation Plan — Phased plan to reduce privilege drift and move toward least-privilege, with a zero trust alignment overlay where applicable
  • Board-Ready Executive Summary — Executive summary for boards and a technical deep-dive for your security team

How the Founding Pilot Works

The Founding Pilot runs in four phases over 60 days — discovery and scoping, identity and privilege mapping with lightweight read-only collectors, a security and compliance assessment that maps findings to NIS2 Article 21 and NCSC CAF Principle B2 outcomes, and reporting with a prioritised least-privilege remediation roadmap. See the Founding Pilot for the full four-phase process, timeline, and deliverables.

Frequently Asked Questions

Does NIS2 or the NCSC CAF apply to our Linux systems?
If you operate an essential or important service, the identity and access requirements apply to the systems supporting that service regardless of operating system — and much of that estate is Linux. In the EU, NIS2 Article 21(2)(i) mandates identity and access management; in the UK, NCSC CAF Principle B2 sets the equivalent outcomes assessed via GovAssure. Both require you to demonstrate control, not just assert it.
Is NIS2 in force everywhere?
NIS2 (Directive (EU) 2022/2555) had to be transposed into national law by 17 October 2024, but transposition has been staggered — most member states have enacted implementing laws and enforcement is live, while a few remain in procedure. Because status varies by market, we confirm the applicable national law and supervisory authority for your jurisdiction as part of pilot scoping rather than assuming a single EU-wide position.
Do you monitor our OT, SCADA, or industrial control systems?
No. LinuxGuard assesses identity and access on Linux hosts — it does not monitor industrial control protocols, PLCs, or SCADA systems, and we do not claim to. What we cover is the Linux layer of your converged OT/IT estate: the operator, engineering, integrator, and service accounts that hold privilege on those hosts, which is exactly where NIS2 B2-style identity requirements bite.
What does the board get for its Article 20 accountability?
A board-ready executive summary that states, in plain terms, the current effectiveness of identity and access control across your essential-function Linux estate, the material gaps, and the remediation plan. NIS2 Article 20 makes senior management accountable for cybersecurity measures; this gives leadership defensible, evidence-based documentation rather than a policy statement.
How long does the CNI pilot take?
The pilot is a fixed-scope engagement covering scoping and data collection, analysis mapping findings to NIS2 Article 21 and NCSC CAF B2 outcomes, and delivery of the evidence package, executive summary, and remediation roadmap with a readout for your team. See the Founding Pilot page for the full timeline.

Ready to demonstrate CNI compliance?

Request your CNI-focused Linux identity pilot and receive evidence aligned to NIS2 Article 21 and NCSC CAF Principle B2.