The night before the audit, someone is still taking screenshots.
Screenshots go stale the moment they are taken, and an auditor knows it. Assembling that evidence by hand usually falls to whoever is least busy that week, not whoever understands the requirement. Module sigil builds the report from what module scry actually monitored and what module ward actually fixed, so the document reflects a running record instead of a scramble the night before the audit.
compliance reporting
NIS2 evidence built from what we actually watched.
Every report is generated from the surface we monitored and the fixes we confirmed, mapped to the NIS2 measures, so your audit rests on a continuous record, not screenshots gathered the night before.
capabilities
Built from real data
Generated from the surface we monitored and the fixes we confirmed, not screenshots gathered the night before.
Mapped to NIS2
Every finding is tied to the technical measures in the NIS2 implementing regulation, so an auditor can follow it.
Your entity details
The registration details a NIS2 authority asks for, filled in from your account.
White-label ready
Providers can put their own logo and colours on the report and hand it to a client as their own.
PDF and CSV export
A clean PDF for the auditor and a CSV of the findings for your own tracking.
A continuous record
Each report rests on the running history of what we watched, so an auditor sees a timeline, not one afternoon.
How module sigil works
- 01
Built from a running record, not a fire drill
Module scry keeps watching your exposed assets and module ward keeps tracking the fixes that landed. Module sigil reads from that record continuously, so the report is never a one-time snapshot someone had to go build. It reflects what happened this month, not a single night.
- 02
Every finding traces to a requirement
Each finding is mapped to the specific technical measure in the NIS2 implementing regulation it satisfies. An auditor can follow a line from requirement to evidence, instead of taking your word for it.
- 03
Export it, brand it, and hand it over
The entity registration details a NIS2 authority asks for are filled in from your account. Export a clean PDF for the auditor and a CSV for your own tracking, whenever you need it, not just once a year. A managed provider can put its own logo and colours on the report and hand it to a client as their own work.
Where it fits
- scrysee what you are exposing
- hexprove it can’t be broken into
- wardfix it, and confirm it’s gone
- sigilyou are hereturn it into compliance evidence
Common questions about module sigil
Is module sigil an official NIS2 certification?
No. NIS2 does not define a single certificate an authority stamps and signs, so no vendor can sell you one honestly. What module sigil gives you is the evidence and posture document an authority and an auditor actually expect to see: findings mapped to the technical measures in the implementing regulation, backed by a running monitoring record. That document is what you walk into the audit with. The legal judgment of compliance stays with the authority.
What does module sigil pull its data from?
Module scry runs the continuous monitoring and finds the exposures. Module ward tracks and confirms the fixes. Module sigil turns that record into the document: it reads what module scry monitored and what module ward closed, maps each item to the relevant technical measure, and writes the report. Without module scry and module ward running, module sigil has nothing current to report on.
Can our managed provider put its own branding on the report?
Yes. The report is white-label ready: a managed provider can apply its own logo and colours before handing it to a client as their own work. The underlying evidence and mappings do not change, only the presentation.
The NIS2 deadline isn't moving. Your setup can start today.
See what your company exposes to the internet, free and EU-hosted, with no security team required.
*Passive scan only. We never touch your systems. Free, no credit card, EU-hosted.