Skip to content

NIS2 evidence

Article 21 of the NIS2 Directive expects organizations in scope to be able to demonstrate, not just assert, how they manage risk in their infrastructure - who did what, when, and to which asset. Sencai’s NIS2 evidence timeline is the part of the product built specifically to answer that: a continuous, read-only, immutable log of inventory activity, scoped to your organization, that you can filter and export.

Find it at Compliance & Audit → NIS2 evidence in the app (/gravity/inventory/evidence).

This page is a read-only window into Sencai’s underlying audit log, filtered to the actions that matter for infrastructure evidence: cloud resource discovery scans, ownership changes (adopting a discovered resource as managed, read-only, or ignored), tagging actions, and drift detection and acknowledgment. For each event you see the timestamp, the actor who performed it (or the system, for automated actions like scans), the action taken, the affected resource, and a before/after comparison where applicable.

This is a read-only view of your organization’s own audit trail - it doesn’t generate new evidence beyond what Sencai already records as you and your team work. Nothing on this page can be edited or deleted. Sencai’s audit log is append-only and cryptographically hash-chained, so tampering with a past entry would be detectable.

The events on this timeline are the kind of record NIS2 Art.21 reviews typically ask for: evidence that your organization tracks its assets, knows who changed them and when, and notices unauthorized changes (drift). What this page does not do is tag each row against a specific NIS2 article or control number for you - it’s a factual activity log, not a pre-built compliance mapping document. Turning this evidence into the specific documentation your NIS2 program or auditor requires is still work your compliance team does, using this as a primary source.

For the broader picture of why a resource is or isn’t compliant against a specific rule (rather than just the activity history), see Policies and the compliance score.

From the NIS2 evidence page:

  1. Filter by action type, resource (a specific asset’s identifier), and a date range if you want a bounded window rather than full history.
  2. Choose CSV or PDF to export the currently filtered result set.

The CSV export is a straightforward data dump suitable for further processing. The PDF export opens a print-formatted view of the same rows (browser print-to-PDF), labeled as a read-only audit-log excerpt with the export timestamp and row count, ready to attach to an audit package as-is.

There’s no separate “collection” step or scheduled report generation here - every qualifying action is written to the timeline as it happens, so the evidence is continuously current. You generate an export whenever you need one (for an ongoing review, an incident follow-up, or a periodic internal audit); there’s no fixed reporting cycle Sencai imposes.

This page gives you the underlying activity record - it doesn’t file anything with a regulator, produce a finished NIS2 compliance report, or make a determination about whether your organization meets its Art.21 obligations. Those are things your organization (with its legal and compliance advisors) is responsible for. Treat this as a primary evidence source you draw on, not a substitute for your own NIS2 program.