This table shows the 29 compliance areas where NIST CSF and NIS2 controls overlap. When you mark a control as implemented in either framework, Venvera automatically propagates the status to the equivalent control in the other.

Compliance AreaNIST CSFNIS2
EncryptionPR.DS-01, PR.DS-02nis2-cr-01
Key ManagementPR.DS-01nis2-cr-02
Access ControlPR.AA-01nis2-hr-02
Identity ManagementPR.AA-01, PR.AA-03nis2-hr-02
Authentication & MFAPR.AA-03nis2-mf-01
Access Rights ReviewPR.AA-05nis2-hr-04
Privileged Access ManagementPR.AA-05nis2-hr-04
Network SecurityPR.IR-01nis2-ch-01
Vulnerability ManagementID.RA-01, PR.PS-01nis2-ss-02
Logging & MonitoringDE.CM-01, DE.AE-02nis2-ea-02
Incident ManagementRS.MA-01, RS.AN-03nis2-ih-01
Incident ClassificationDE.AE-04nis2-ih-03
Incident ReportingRS.CO-02nis2-ih-02
Incident Response TeamRS.MA-02nis2-ih-01
Post-Incident ReviewRS.AN-08nis2-ih-04
Business ContinuityRC.RP-01, RC.RP-03nis2-bc-01
Backup & RestorationRC.RP-03nis2-bc-02
Crisis ManagementRS.CO-03nis2-bc-03
Third-Party Risk ManagementGV.SC-03nis2-sc-01
Supplier Due DiligenceGV.SC-06nis2-sc-02
Supplier ContractsGV.SC-05nis2-sc-03
Supplier MonitoringGV.SC-09nis2-sc-04
Risk AssessmentID.RA-03, ID.RA-05nis2-ra-02, nis2-ra-03
Information Security PolicyGV.PO-01nis2-ra-01
Security Awareness & TrainingPR.AT-01nis2-ch-02
Change ManagementPR.PS-01nis2-ss-04
Secure DevelopmentPR.PS-06nis2-ss-03
Security TestingID.IM-02nis2-ea-01
Penetration TestingID.RA-01nis2-ea-01
ℹ️
For details on how propagation works, thresholds, and the auto-mapped badge, see the Cross-Framework Control Propagation overview article.