# CRO-029 — GAISSF–NIS2 Mapping **Version:** 1.0 **Status:** Publication Candidate **Publisher:** ODA3 Institute **Verified:** 29 June 2026 ## Executive summary This controlled crosswalk maps all **59 GAISSF v1.0 controls** to material provisions of **Directive (EU) 2022/2555 (NIS2)**. It contains **115 control-to-article mapping records** and a reverse register covering all 46 articles. > This mapping is not legal advice and does not establish NIS2 compliance. NIS2 obligations depend on national transposition, entity classification, sector, size, jurisdiction and competent-authority practice. ## Source baseline - Directive (EU) 2022/2555, published 27 December 2022. - Transposition deadline: 17 October 2024. - Commission Implementing Regulation (EU) 2024/2690 is treated as a separate implementation layer for specified digital entities. - GAISSF-NOR-001 and GAISSF-NOR-004 v1.0 are the internal normative baseline. ## Mapping method Mappings compare substantive outcomes rather than labels. Relationship codes are SP (strong partial), P (partial), S (supporting), C (contextual), N (no material mapping), O (outside scope) and U (unable to determine). Mapping does not prove implementation or operating effectiveness. ## Function-level findings - **Article 20 — Governance:** GAISSF governance, assurance, human oversight and evidence controls provide strong partial support. - **Article 21 — Cybersecurity risk-management measures:** GAISSF provides its strongest alignment through technical safeguards, incident readiness, continuity, supply-chain security and access-control-related controls. - **Article 23 — Reporting obligations:** GAISSF supports detection, evidence and escalation, but statutory timing, notification content and authority channels require country-specific implementation. - **Articles 31–36 — Supervision and enforcement:** GAISSF can provide evidence, but does not establish regulator powers, liability, penalties or procedural compliance. ## Notably absent - No automatic NIS2 compliance claim - No determination that an organisation is an essential or important entity - No country-specific transposition analysis - No regulator endorsement - No proof of operating effectiveness - No automatic satisfaction of incident notification deadlines ## Complete mapping register | Record | GAISSF control | NIS2 article | Relationship | Confidence | Rationale | |---|---|---|---|---|---| | CRO-029-MAP-0001 | D1-CTL-01 — Dataset Provenance & Poisoning Prevention | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0002 | D1-CTL-01 — Dataset Provenance & Poisoning Prevention | Art. 24 — Use of European cybersecurity certification schemes | S | Medium | May support use of certification, standards and technical specifications contemplated by NIS2. | | CRO-029-MAP-0003 | D1-CTL-01 — Dataset Provenance & Poisoning Prevention | Art. 25 — Standardisation | S | Medium | May support use of certification, standards and technical specifications contemplated by NIS2. | | CRO-029-MAP-0004 | D1-CTL-02 — Model Extraction Resistance | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0005 | D1-CTL-03 — Behavioral Drift Detection | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0006 | D1-CTL-04 — Federated Learning Poisoning Prevention | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0007 | D1-CTL-04 — Federated Learning Poisoning Prevention | Art. 24 — Use of European cybersecurity certification schemes | S | Medium | May support use of certification, standards and technical specifications contemplated by NIS2. | | CRO-029-MAP-0008 | D1-CTL-04 — Federated Learning Poisoning Prevention | Art. 25 — Standardisation | S | Medium | May support use of certification, standards and technical specifications contemplated by NIS2. | | CRO-029-MAP-0009 | D1-CTL-05 — Embedding Space Robustness | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0010 | D1-CTL-06 — Post-Quantum Model Signing & Crypto Hardening | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0011 | D1-CTL-06 — Post-Quantum Model Signing & Crypto Hardening | Art. 24 — Use of European cybersecurity certification schemes | S | Medium | May support use of certification, standards and technical specifications contemplated by NIS2. | | CRO-029-MAP-0012 | D1-CTL-06 — Post-Quantum Model Signing & Crypto Hardening | Art. 25 — Standardisation | S | Medium | May support use of certification, standards and technical specifications contemplated by NIS2. | | CRO-029-MAP-0013 | D1-CTL-07 — Lora/Adapter Integrity Verification | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0014 | D1-CTL-08 — Model Merge Attack Detection | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0015 | D1-CTL-08 — Model Merge Attack Detection | Art. 29 — Cybersecurity information-sharing arrangements | S | Medium | Supports structured sharing or voluntary notification of cyber-threat and incident information. | | CRO-029-MAP-0016 | D1-CTL-08 — Model Merge Attack Detection | Art. 30 — Voluntary notification of relevant information | S | Medium | Supports structured sharing or voluntary notification of cyber-threat and incident information. | | CRO-029-MAP-0017 | D1-CTL-09 — Quantization Backdoor Screening | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0018 | D2-CTL-01 — Direct Prompt Injection Prevention | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0019 | D2-CTL-02 — Indirect Prompt Injection Prevention | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0020 | D2-CTL-03 — Jailbreak Resistance Testing | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0021 | D2-CTL-04 — Multi-Modal Injection Defense | Art. 21 — Cybersecurity risk-management measures | P | Medium | The control contributes to an all-hazards cybersecurity risk-management capability, subject to entity and system scope. | | CRO-029-MAP-0022 | D2-CTL-05 — Function Call/Tool Call Injection Prevention | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0023 | D2-CTL-06 — Cross-Context Hijacking Mitigation | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0024 | D3-CTL-01 — Least Agency Enforcement | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0025 | D3-CTL-02 — Inter-Agent Communication Security | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0026 | D3-CTL-03 — Agentic Prompt Chaining Detection | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0027 | D3-CTL-04 — Embodied Ai Safety Controls | Art. 21 — Cybersecurity risk-management measures | P | Medium | The control contributes to an all-hazards cybersecurity risk-management capability, subject to entity and system scope. | | CRO-029-MAP-0028 | D3-CTL-05 — Multi-Agent Trust Chain Attestation | Art. 21 — Cybersecurity risk-management measures | P | Medium | The control contributes to an all-hazards cybersecurity risk-management capability, subject to entity and system scope. | | CRO-029-MAP-0029 | D3-CTL-06 — Persistent Memory Exfiltration Prevention | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0030 | D3-CTL-07 — Secure Memory Lifecycle Management | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0031 | D3-CTL-07 — Secure Memory Lifecycle Management | Art. 22 — Coordinated security risk assessments of critical supply chains | SP | High | Supports supply-chain security, supplier due diligence and risk treatment for ICT products and services. | | CRO-029-MAP-0032 | D3-CTL-07 — Secure Memory Lifecycle Management | Art. 19 — Union-level coordinated security risk assessments of critical supply chains | S | Medium | Provides entity-level evidence relevant to critical supply-chain risk analysis. | | CRO-029-MAP-0033 | D4-CTL-01 — Ai Bill Of Materials (Ai Bom) Maintenance | Art. 21 — Cybersecurity risk-management measures | SP | High | Supports supply-chain security, supplier due diligence and risk treatment for ICT products and services. | | CRO-029-MAP-0034 | D4-CTL-01 — Ai Bill Of Materials (Ai Bom) Maintenance | Art. 22 — Coordinated security risk assessments of critical supply chains | SP | High | Supports supply-chain security, supplier due diligence and risk treatment for ICT products and services. | | CRO-029-MAP-0035 | D4-CTL-01 — Ai Bill Of Materials (Ai Bom) Maintenance | Art. 19 — Union-level coordinated security risk assessments of critical supply chains | S | Medium | Provides entity-level evidence relevant to critical supply-chain risk analysis. | | CRO-029-MAP-0036 | D4-CTL-02 — Model File & Artifact Scanning | Art. 21 — Cybersecurity risk-management measures | P | Medium | The control contributes to an all-hazards cybersecurity risk-management capability, subject to entity and system scope. | | CRO-029-MAP-0037 | D4-CTL-03 — Model Hub & Registry Vetting | Art. 21 — Cybersecurity risk-management measures | SP | High | Supports supply-chain security, supplier due diligence and risk treatment for ICT products and services. | | CRO-029-MAP-0038 | D4-CTL-03 — Model Hub & Registry Vetting | Art. 22 — Coordinated security risk assessments of critical supply chains | SP | High | Supports supply-chain security, supplier due diligence and risk treatment for ICT products and services. | | CRO-029-MAP-0039 | D4-CTL-03 — Model Hub & Registry Vetting | Art. 19 — Union-level coordinated security risk assessments of critical supply chains | S | Medium | Provides entity-level evidence relevant to critical supply-chain risk analysis. | | CRO-029-MAP-0040 | D4-CTL-04 — Mcp Server Behavioral Monitoring | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0041 | D4-CTL-04 — Mcp Server Behavioral Monitoring | Art. 22 — Coordinated security risk assessments of critical supply chains | SP | High | Supports supply-chain security, supplier due diligence and risk treatment for ICT products and services. | | CRO-029-MAP-0042 | D4-CTL-05 — Third-Party Ai Api Security Assessment | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0043 | D4-CTL-05 — Third-Party Ai Api Security Assessment | Art. 22 — Coordinated security risk assessments of critical supply chains | SP | High | Supports supply-chain security, supplier due diligence and risk treatment for ICT products and services. | | CRO-029-MAP-0044 | D4-CTL-05 — Third-Party Ai Api Security Assessment | Art. 31 — General aspects concerning supervision and enforcement | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0045 | D4-CTL-05 — Third-Party Ai Api Security Assessment | Art. 32 — Supervisory and enforcement measures in relation to essential entities | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0046 | D4-CTL-06 — Shadow Ai Discovery & Governance | Art. 20 — Governance | SP | High | Supports management oversight, accountability and documented approval of cybersecurity measures. | | CRO-029-MAP-0047 | D4-CTL-06 — Shadow Ai Discovery & Governance | Art. 31 — General aspects concerning supervision and enforcement | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0048 | D4-CTL-06 — Shadow Ai Discovery & Governance | Art. 32 — Supervisory and enforcement measures in relation to essential entities | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0049 | D4-CTL-06 — Shadow Ai Discovery & Governance | Art. 33 — Supervisory and enforcement measures in relation to important entities | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0050 | D4-CTL-07 — Ai Software Composition Analysis (Sca) | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0051 | D4-CTL-07 — Ai Software Composition Analysis (Sca) | Art. 22 — Coordinated security risk assessments of critical supply chains | SP | High | Supports supply-chain security, supplier due diligence and risk treatment for ICT products and services. | | CRO-029-MAP-0052 | D5-CTL-01 — Harmful Content Blocking | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0053 | D5-CTL-02 — Pii Leakage Prevention | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0054 | D5-CTL-03 — Copyright Detection | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0055 | D5-CTL-04 — Ai Watermarking Robustness | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0056 | D5-CTL-05 — Privacy-By-Design Verification | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0057 | D5-CTL-06 — Privacy-Preserving Ml Validation | Art. 20 — Governance | SP | High | Supports management oversight, accountability and documented approval of cybersecurity measures. | | CRO-029-MAP-0058 | D5-CTL-06 — Privacy-Preserving Ml Validation | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0059 | D5-CTL-06 — Privacy-Preserving Ml Validation | Art. 31 — General aspects concerning supervision and enforcement | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0060 | D5-CTL-06 — Privacy-Preserving Ml Validation | Art. 32 — Supervisory and enforcement measures in relation to essential entities | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0061 | D6-CTL-01 — Human-In-The-Loop For High-Risk Actions | Art. 20 — Governance | SP | High | Supports management oversight, accountability and documented approval of cybersecurity measures. | | CRO-029-MAP-0062 | D6-CTL-02 — Audit Trail Completeness | Art. 20 — Governance | SP | High | Supports management oversight, accountability and documented approval of cybersecurity measures. | | CRO-029-MAP-0063 | D6-CTL-02 — Audit Trail Completeness | Art. 23 — Reporting obligations | P | High | Supports incident detection, evidence capture, escalation and reporting workflows, but does not by itself satisfy statutory notification timing and content. | | CRO-029-MAP-0064 | D6-CTL-02 — Audit Trail Completeness | Art. 31 — General aspects concerning supervision and enforcement | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0065 | D6-CTL-02 — Audit Trail Completeness | Art. 32 — Supervisory and enforcement measures in relation to essential entities | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0066 | D6-CTL-03 — Ai Model Card Completeness | Art. 20 — Governance | SP | High | Supports management oversight, accountability and documented approval of cybersecurity measures. | | CRO-029-MAP-0067 | D6-CTL-03 — Ai Model Card Completeness | Art. 31 — General aspects concerning supervision and enforcement | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0068 | D6-CTL-03 — Ai Model Card Completeness | Art. 32 — Supervisory and enforcement measures in relation to essential entities | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0069 | D6-CTL-03 — Ai Model Card Completeness | Art. 33 — Supervisory and enforcement measures in relation to important entities | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0070 | D6-CTL-04 — Ai Incident Response Readiness | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0071 | D6-CTL-04 — Ai Incident Response Readiness | Art. 23 — Reporting obligations | P | High | Supports incident detection, evidence capture, escalation and reporting workflows, but does not by itself satisfy statutory notification timing and content. | | CRO-029-MAP-0072 | D6-CTL-04 — Ai Incident Response Readiness | Art. 29 — Cybersecurity information-sharing arrangements | S | Medium | Supports structured sharing or voluntary notification of cyber-threat and incident information. | | CRO-029-MAP-0073 | D6-CTL-04 — Ai Incident Response Readiness | Art. 30 — Voluntary notification of relevant information | S | Medium | Supports structured sharing or voluntary notification of cyber-threat and incident information. | | CRO-029-MAP-0074 | D6-CTL-05 — Model Deprecation & Decommissioning | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0075 | D6-CTL-06 — Third-Party Ai Vendor Governance | Art. 20 — Governance | SP | High | Supports management oversight, accountability and documented approval of cybersecurity measures. | | CRO-029-MAP-0076 | D6-CTL-06 — Third-Party Ai Vendor Governance | Art. 21 — Cybersecurity risk-management measures | SP | High | Supports supply-chain security, supplier due diligence and risk treatment for ICT products and services. | | CRO-029-MAP-0077 | D6-CTL-06 — Third-Party Ai Vendor Governance | Art. 22 — Coordinated security risk assessments of critical supply chains | SP | High | Supports supply-chain security, supplier due diligence and risk treatment for ICT products and services. | | CRO-029-MAP-0078 | D6-CTL-06 — Third-Party Ai Vendor Governance | Art. 31 — General aspects concerning supervision and enforcement | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0079 | D6-CTL-07 — Ai Resilience & Business Continuity | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0080 | D7-CTL-H01 — Ai-Generated Phishing Simulation | Art. 29 — Cybersecurity information-sharing arrangements | S | Medium | Supports structured sharing or voluntary notification of cyber-threat and incident information. | | CRO-029-MAP-0081 | D7-CTL-H01 — Ai-Generated Phishing Simulation | Art. 30 — Voluntary notification of relevant information | S | Medium | Supports structured sharing or voluntary notification of cyber-threat and incident information. | | CRO-029-MAP-0082 | D7-CTL-H02 — Deepfake Detection Training | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0083 | D7-CTL-H03 — Out-Of-Band Authentication | Art. 21 — Cybersecurity risk-management measures | P | Medium | The control contributes to an all-hazards cybersecurity risk-management capability, subject to entity and system scope. | | CRO-029-MAP-0084 | D7-CTL-H04 — Ai Social Engineering Ir | Art. 23 — Reporting obligations | P | High | Supports incident detection, evidence capture, escalation and reporting workflows, but does not by itself satisfy statutory notification timing and content. | | CRO-029-MAP-0085 | D7-CTL-H05 — Ai-Enhanced External Attack Defense | Art. 20 — Governance | SP | High | Supports management oversight, accountability and documented approval of cybersecurity measures. | | CRO-029-MAP-0086 | D7-CTL-H05 — Ai-Enhanced External Attack Defense | Art. 24 — Use of European cybersecurity certification schemes | S | Medium | May support use of certification, standards and technical specifications contemplated by NIS2. | | CRO-029-MAP-0087 | D7-CTL-H05 — Ai-Enhanced External Attack Defense | Art. 25 — Standardisation | S | Medium | May support use of certification, standards and technical specifications contemplated by NIS2. | | CRO-029-MAP-0088 | D7-CTL-H05 — Ai-Enhanced External Attack Defense | Art. 29 — Cybersecurity information-sharing arrangements | S | Medium | Supports structured sharing or voluntary notification of cyber-threat and incident information. | | CRO-029-MAP-0089 | D8-CTL-01 — Eu Ai Act Risk Tier Mapping | Art. 20 — Governance | SP | High | Supports management oversight, accountability and documented approval of cybersecurity measures. | | CRO-029-MAP-0090 | D8-CTL-01 — Eu Ai Act Risk Tier Mapping | Art. 7 — National cybersecurity strategy | C | Low | Can inform organisational alignment with national cybersecurity strategies but does not implement Member State duties. | | CRO-029-MAP-0091 | D8-CTL-02 — Iso 42001 Gap Analysis | Art. 20 — Governance | SP | High | Supports management oversight, accountability and documented approval of cybersecurity measures. | | CRO-029-MAP-0092 | D8-CTL-02 — Iso 42001 Gap Analysis | Art. 24 — Use of European cybersecurity certification schemes | S | Medium | May support use of certification, standards and technical specifications contemplated by NIS2. | | CRO-029-MAP-0093 | D8-CTL-02 — Iso 42001 Gap Analysis | Art. 25 — Standardisation | S | Medium | May support use of certification, standards and technical specifications contemplated by NIS2. | | CRO-029-MAP-0094 | D8-CTL-02 — Iso 42001 Gap Analysis | Art. 7 — National cybersecurity strategy | C | Low | Can inform organisational alignment with national cybersecurity strategies but does not implement Member State duties. | | CRO-029-MAP-0095 | D8-CTL-03 — Gpai Technical Documentation Verification | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0096 | D8-CTL-03 — Gpai Technical Documentation Verification | Art. 31 — General aspects concerning supervision and enforcement | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0097 | D8-CTL-03 — Gpai Technical Documentation Verification | Art. 32 — Supervisory and enforcement measures in relation to essential entities | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0098 | D8-CTL-03 — Gpai Technical Documentation Verification | Art. 33 — Supervisory and enforcement measures in relation to important entities | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0099 | D8-CTL-04 — Dora Ict Incident Reporting (Financial Sector) | Art. 23 — Reporting obligations | P | High | Supports incident detection, evidence capture, escalation and reporting workflows, but does not by itself satisfy statutory notification timing and content. | | CRO-029-MAP-0100 | D8-CTL-05 — Nist Sp 800-218A Compliance Check | Art. 20 — Governance | SP | High | Supports management oversight, accountability and documented approval of cybersecurity measures. | | CRO-029-MAP-0101 | D8-CTL-05 — Nist Sp 800-218A Compliance Check | Art. 24 — Use of European cybersecurity certification schemes | S | Medium | May support use of certification, standards and technical specifications contemplated by NIS2. | | CRO-029-MAP-0102 | D8-CTL-05 — Nist Sp 800-218A Compliance Check | Art. 25 — Standardisation | S | Medium | May support use of certification, standards and technical specifications contemplated by NIS2. | | CRO-029-MAP-0103 | D8-CTL-05 — Nist Sp 800-218A Compliance Check | Art. 31 — General aspects concerning supervision and enforcement | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0104 | D9-CTL-01 — Physical Harm Boundary Enforcement | Art. 21 — Cybersecurity risk-management measures | P | Medium | The control contributes to an all-hazards cybersecurity risk-management capability, subject to entity and system scope. | | CRO-029-MAP-0105 | D9-CTL-02 — Safe State And Graceful Degradation | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0106 | D9-CTL-03 — Human Override And Emergency Stop | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0107 | D9-CTL-04 — Cyber-Physical Attack Detection | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0108 | D9-CTL-04 — Cyber-Physical Attack Detection | Art. 29 — Cybersecurity information-sharing arrangements | S | Medium | Supports structured sharing or voluntary notification of cyber-threat and incident information. | | CRO-029-MAP-0109 | D9-CTL-04 — Cyber-Physical Attack Detection | Art. 30 — Voluntary notification of relevant information | S | Medium | Supports structured sharing or voluntary notification of cyber-threat and incident information. | | CRO-029-MAP-0110 | D9-CTL-05 — Physical Environment Integrity Monitoring | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0111 | D9-CTL-06 — Actuator Command Verification | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | | CRO-029-MAP-0112 | D9-CTL-07 — Physical Incident Evidence Preservation | Art. 23 — Reporting obligations | P | High | Supports incident detection, evidence capture, escalation and reporting workflows, but does not by itself satisfy statutory notification timing and content. | | CRO-029-MAP-0113 | D9-CTL-07 — Physical Incident Evidence Preservation | Art. 31 — General aspects concerning supervision and enforcement | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0114 | D9-CTL-07 — Physical Incident Evidence Preservation | Art. 32 — Supervisory and enforcement measures in relation to essential entities | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. | | CRO-029-MAP-0115 | D9-CTL-07 — Physical Incident Evidence Preservation | Art. 33 — Supervisory and enforcement measures in relation to important entities | P | Medium | Produces evidence that may support supervisory review, inspection or remediation, subject to national law. |