Coverage
What Hyground can evidence, measure by measure
NIS2 Article 21 lists ten security measures, and DORA’s pillars converge on the same operational core. Below is which ones Hyground evidences from live system state, which it supports in part, and which belong to other tools.
NIS2 Article 21(2) measure
Hyground Coverage
What you get
Maps to DORA
(a) Risk analysis and security policies
Full
FMEA risk analysis: scored failure-mode matrix, fault tree, report; on-demand asset inventory
Pillar 1: ICT risk management
(b) Incident handling
Full
Automated root-cause analysis; a timestamped, auditable session record per incident
Pillar 2: incident management
(c) Business continuity, backup, disaster recovery
None
Not Hyground: your backup and recovery tooling
Pillar 1: ICT risk management
(d) Supply-chain security
Full
Cross-stack dependency and asset enumeration; which running services use a vulnerable package
Pillar 4: third-party risk
(e) Secure development and vulnerability handling
Partial
Live exposure and configuration checks on running services
Pillars 1 and 3
(f) Assessing whether measures are effective
Full
Scheduled investigations on a cron cadence; downloadable reports that the checks ran
Pillar 3: resilience testing
(g) Basic cyber hygiene and training
None
Not Hyground: your awareness programme
Pillar 1: ICT risk management
(h) Cryptography and encryption
None
Not Hyground: your key management and encryption
Pillar 1: ICT risk management
(i) Access control and asset management
Full
Read-only adapters, short-lived per-environment tokens, full interaction audit trail; on-demand asset inventory
Pillar 1: ICT risk management
(j) Multi-factor authentication and secure communications
None
Not Hyground: your identity provider and communications
Pillar 1: ICT risk management
How it works
The capabilities behind the matrix
Each row above traces back to something that ships today. These are the five capabilities behind it.
Third-party risk
The smallest third-party footprint you can put in a register
Hyground runs inside your environment and reads rather than writes, so you stay the operator of your own data plane. That keeps the third-party-risk paperwork short, and on-premises it nearly disappears.
The honest edges
What Hyground does not do
Being precise about the edges is part of being a supplier you can put in a DORA register without a footnote. Hyground is the operational layer; it does not replace the tools around it, and it is not a certificate.
Deployment
Self-hosted, in the tier your obligation needs
Hyground is self-hosted in every tier, so the one you choose is the compliance argument you get to make.
The rules, in brief
Two regimes, two reporting clocks
Both regimes reach software vendors through their customers: in-scope customers push the requirements down the supply chain (NIS2 Article 21(2)(d), DORA Article 30), so the clock can start with you even when you are not directly in scope.
See it in practice
Proof and related use cases

