NIS2 readiness

Outside-in exposure monitoring for NIS2 readiness

SurfaceDiff compares your public-facing infrastructure with its previous snapshot and alerts your team when ports, services, DNS records, certificates or observed hosts change.

This additional outside-in evidence can support configuration monitoring, change verification, network security and external asset visibility processes associated with NIS2.

7 days. One verified domain. No credit card.

SurfaceDiff supports selected technical processes. It does not provide legal advice, certification or a guarantee of NIS2 compliance.

Change management records intent. SurfaceDiff shows the externally visible outcome.

A change can be approved, tested and documented, yet its final external result may still differ from what the team expected. A temporary service may remain reachable, a rollback may be incomplete, a certificate may be replaced, or a DNS change may expose a new route to a system.

SurfaceDiff adds a separate outside-in check. It observes the infrastructure from the public Internet, compares the current state with the previous snapshot and draws attention to the difference.

It does not decide that every change is dangerous or non-compliant. It gives the responsible team evidence to confirm whether the change was intentional or whether something needs investigation.

Where outside-in monitoring can support NIS2 processes

Article 21 of the NIS2 Directive requires essential and important entities to apply appropriate and proportionate technical, operational and organisational cybersecurity risk-management measures.

For specified digital sectors, Commission Implementing Regulation (EU) 2024/2690 provides more detailed requirements covering areas such as monitoring, configuration management, change management, network security, assessment of control effectiveness and asset inventory.

SurfaceDiff can contribute evidence and visibility within these processes. It does not satisfy any requirement on its own.

Configuration management - section 6.3

How SurfaceDiff can contribute

Detects changes in externally visible ports, services, DNS, certificates and observed hosts, providing a separate view of public configuration outcomes.

What SurfaceDiff does not replace

It does not define, enforce or validate the complete internal secure configuration baseline.

Change management - section 6.4

How SurfaceDiff can contribute

Before-and-after snapshots can help teams verify the externally visible result of planned, emergency and rollback changes.

What SurfaceDiff does not replace

It does not replace approvals, change tickets, testing, impact assessment or change documentation.

Network security - section 6.7

How SurfaceDiff can contribute

Highlights newly reachable or changed public services and connections that may require review.

What SurfaceDiff does not replace

It does not block traffic, modify firewall rules or decide whether a service is required.

Effectiveness of cybersecurity measures - section 7

How SurfaceDiff can contribute

Outside-in observations can contribute measurement data when a team checks whether a control produced the expected public result.

What SurfaceDiff does not replace

It is not an independent compliance review, penetration test or certification.

Monitoring and logging - section 3.2

How SurfaceDiff can contribute

Provides automated periodic external checks, change history and alerts for the monitored public footprint.

What SurfaceDiff does not replace

It does not replace internal logging, a SIEM, EDR, IDS or incident monitoring across the organisation.

Asset inventory - section 12.4

How SurfaceDiff can contribute

Maintains a history of assets and services observed within the verified external scope.

What SurfaceDiff does not replace

It is not a complete or authoritative inventory and does not replace a CMDB or DNS provider inventory.

The detailed requirements of Commission Implementing Regulation (EU) 2024/2690 apply to specified digital entities, including certain DNS, cloud, data centre, managed service and managed security service providers. Obligations for any organisation depend on its sector, size, jurisdiction, national implementation and individual risk assessment.

A separate check of what the Internet can see

1

Verify your domain

Domain verification confirms that the monitored scope is authorised by the organisation.

2

Establish an external baseline

SurfaceDiff records the public-facing state of observed hosts, DNS, ports, service fingerprints and TLS certificates.

3

Check the exposure daily

Automated scans repeat at daily intervals without requiring an agent inside the monitored environment.

4

Compare snapshots

The current observation is compared with the previous snapshot to identify what appeared, disappeared or changed.

5

Give the change to a human

SurfaceDiff raises an alert and preserves the change history so an administrator can confirm the intended result or investigate an unexpected difference.

Operational evidence for review and follow-up

A point-in-time scan shows what is exposed now. SurfaceDiff adds the history needed to understand when an observed change appeared and what the previous state looked like.

The resulting snapshots, timestamps, change details and incident history can contribute supporting operational evidence during internal reviews, control assessments and audits. Whether particular evidence is sufficient must be determined by the organisation, its auditor and the relevant authority.

  • Timestamped external snapshots
  • Previous and current observed values
  • Change and incident history
  • Alerts for newly observed differences
  • A consistent outside-in point of view

Relevant to organisations operating critical digital services

SurfaceDiff can be particularly useful to infrastructure teams managing many public services or frequently changing environments, including cloud, data centre, DNS, CDN, managed service and managed security service providers.

NIS2 covers multiple critical sectors across the European Union, but not every organisation is automatically in scope. Classification depends on factors including the service provided, organisation size, jurisdiction and national implementation.

If your organisation may be subject to NIS2, confirm its legal status and obligations with the relevant national authority or a qualified adviser.

A supporting control, not a compliance shortcut

SurfaceDiff does

  • Monitor verified public-facing scope from the outside
  • Run automated checks at daily intervals
  • Compare the current observation with the previous snapshot
  • Detect changes in public ports, services, DNS, certificates and observed hosts
  • Notify administrators and retain change history

SurfaceDiff does not

  • Guarantee or certify NIS2 compliance
  • Provide legal or audit advice
  • Replace a CMDB, SIEM or change management platform
  • Perform comprehensive vulnerability assessment
  • Guarantee discovery of every asset or subdomain
  • Block, remediate or approve infrastructure changes

FAQ

Is SurfaceDiff a NIS2 compliance platform?

No. SurfaceDiff is an external exposure monitoring service that can support selected technical and operational processes associated with NIS2. Compliance depends on the organisation's complete set of legal, technical, operational and organisational measures.

Does NIS2 require organisations to use SurfaceDiff or another EASM product?

No. NIS2 does not require a named product. It requires organisations in scope to implement appropriate and proportionate cybersecurity risk-management measures. The tools selected depend on the organisation's services, risks and applicable national requirements.

Which NIS2 areas can SurfaceDiff support?

SurfaceDiff can contribute outside-in visibility and evidence to configuration monitoring, change verification, network security, assessment of control effectiveness, periodic monitoring and external asset visibility. It does not fulfil any of these areas by itself.

Does SurfaceDiff replace a vulnerability scanner?

No. SurfaceDiff focuses on detecting changes in public exposure over time. It does not perform comprehensive vulnerability assessment or determine that every observed service is secure.

Does SurfaceDiff provide a complete asset inventory?

No. SurfaceDiff records assets and services observed within the verified external scope. Public discovery cannot guarantee a complete or authoritative inventory, especially where assets are not publicly discoverable or DNS wildcard configurations are used.

Is SurfaceDiff a real-time monitoring service?

No. SurfaceDiff performs automated scans at daily intervals. It should be described as periodic external exposure monitoring, not real-time or continuous monitoring.

Is NIS2 limited to one EU country?

No. NIS2 establishes an EU-wide cybersecurity framework. Each Member State implements and enforces it through national law, so detailed obligations, procedures and competent authorities may vary.

Can SurfaceDiff reports be used during an audit?

SurfaceDiff history can contribute supporting operational evidence. The organisation, its auditor and the relevant authority determine whether particular evidence is sufficient for a specific assessment.

Official references

Related

Verify what changed outside the change ticket

Start with one domain and see how SurfaceDiff records changes to the infrastructure visible from the public Internet.

Start a 7-Day Free Scan

One verified domain. No credit card required.

SurfaceDiff is a technical monitoring service. It does not provide legal advice, compliance certification or assurance that an organisation satisfies NIS2 or any national implementing legislation. References to NIS2 describe areas in which external exposure monitoring may provide supporting visibility or evidence. Organisations should assess their obligations with qualified advisers and the relevant national authorities.