NIS2 Compliance

NIS2: map and monitor your web attack surface

The NIS2 directive requires organizations across the EU to inventory their information systems and maintain continuous vulnerability monitoring. Purplemet addresses these specific requirements for your web perimeter — continuously, without intrusion, without configuration.

Zero configuration
Non-intrusive
Continuous monitoring

NIS2 at a glance

What NIS2 changes,
in three points

  1. A massive expansion of scope Organizations from 50 employees or €10M revenue in the covered sectors are in scope across the EU. In France alone, 10,000 to 15,000 organizations are concerned. Essential entities (250+ employees or €50M revenue) face the strictest regime.
  2. Concrete obligations Member states are transposing the directive into national frameworks. In France, ANSSI's ReCyF framework (March 2026) translates NIS2 into 20 concrete security objectives, from asset inventory to security monitoring.
  3. Dissuasive penalties Up to €10M or 2% of worldwide turnover for essential entities; €7M or 1.4% for important entities.

Where Purplemet fits

On your web perimeter, we address specific NIS2 requirements

No tool "makes you NIS2 compliant" on its own — be wary of anyone claiming otherwise. On the specific perimeter of your web attack surface, Purplemet addresses identifiable requirements.

  • Asset inventory (ReCyF objective 1) Continuously discover your exposed web applications — including shadow IT and assets missing from your inventories. Your asset register stops being declarative: it becomes observed, and stays up to date automatically.
  • Security maintenance & vulnerability watch (objective 5) Inventory each application's technology stack and continuously match it against published CVEs. Know the same day whether a component is affected.
  • Audits and configurations (objectives 17 & 18) Prepare and focus your penetration tests by prioritizing at-risk applications. Helps identify configuration weaknesses visible from the web.
  • Security monitoring (objective 20) Complement your internal monitoring (SOC, SIEM) with a continuous external view of your web attack surface — without replacing it.
Faq

Common questions about NIS2 and Web ASM

Does Purplemet make me NIS2 compliant?

No — no tool can, and we don't claim to. Compliance is an organizational project. Purplemet addresses specific objectives of the framework on the web perimeter: the inventory of your exposed assets and the continuous monitoring of their vulnerabilities, in particular.

Am I in scope of NIS2?

Probably, if your organization has at least 50 employees or €10M in revenue in one of the covered sectors. National authorities (ANSSI in France) will formally identify the entities in scope.

Where should I start?

By knowing what you expose. A free web attack surface assessment gives you, from your domain name alone, a map of your exposed applications and their technology inventory — the foundation of the asset register the regulation expects.

Your facility's internet exposure, under control —
for good.

Your facility's internet exposure,under control — for good.