This table shows the 16 compliance areas where CMMC 2.0 and NIS2 controls overlap. When you mark a control as implemented in either framework, Venvera automatically propagates the status to the equivalent control in the other.

Compliance AreaCMMC 2.0NIS2
Access ControlAC.L2-3.1.1, AC.L2-3.1.2nis2-hr-02
Privileged AccessAC.L2-3.1.5, AC.L2-3.1.6nis2-hr-04
Authentication & MFAIA.L2-3.5.3, IA.L2-3.5.4nis2-mf-01
Security Awareness & TrainingAT.L2-3.2.1, AT.L2-3.2.2nis2-ch-02
Audit LoggingAU.L2-3.3.1, AU.L2-3.3.2nis2-ea-02
Configuration ManagementCM.L2-3.4.1, CM.L2-3.4.2nis2-ss-04
Change ControlCM.L2-3.4.3, CM.L2-3.4.4nis2-ss-04
Incident ResponseIR.L2-3.6.1, IR.L2-3.6.2nis2-ih-01
Incident ReportingIR.L2-3.6.3nis2-ih-02
Vulnerability ManagementRA.L2-3.11.2, RA.L2-3.11.3nis2-ss-02
Risk AssessmentRA.L2-3.11.1nis2-ra-02, nis2-ra-03
Security Assessment & TestingCA.L2-3.12.1, CA.L2-3.12.3nis2-ea-01
EncryptionSC.L2-3.13.8, SC.L2-3.13.11nis2-cr-01
Network SecuritySC.L2-3.13.1, SC.L2-3.13.5nis2-ch-01
Business ContinuitySC.L2-3.13.13nis2-bc-01
Supply Chain SecurityCA.L2-3.12.4, SC.L2-3.13.6nis2-sc-01, nis2-sc-02
ℹ️
For details on how propagation works, thresholds, and the auto-mapped badge, see the Cross-Framework Control Propagation overview article.