Which technical controls Nispo checks on its own, from which systems, and which remain manual.

Key facts
  • The ACN measures have administrative requirements (policies, plans, registers) and technical ones (encryption, updates, MFA). Software can check only some of them automatically, on the systems it is connected to.
  • Nispo checks controls automatically on Microsoft 365 / Entra ID (read-only on Microsoft Graph), Google Workspace, AWS and Google Cloud; the rest is handled with uploaded evidence.
  • Nispo does not enforce or change configurations: MFA, devices and endpoints remain the job of Entra ID, Intune, Defender or equivalent tools.

What Nispo checks on Microsoft 365

AreaWhat Nispo readsExample result
AuthenticationMFA status of users and admins“MFA enabled for all admins: passed”
Privileged accountsAssigned admin roles“3 admin accounts without MFA”, with a remediation task
DevicesDevices registered in the tenantUp-to-date, exportable inventory
Users and licencesTenant users and licencesList for the inventory

Each result becomes dated evidence linked to the requirement. The connection uses read-only permissions on the Microsoft Graph API and takes about 5 minutes; the first checks take about 10-15 minutes, depending on the tenant.

Available integrations

SystemScopeHow
Microsoft 365 / Entra IDUsers, roles, MFA, devices, licencesRead-only on the Microsoft Graph API
Google WorkspaceIdentities, access, devicesProvider API
AWSAccess and cloud resourcesProvider API
Google CloudAccess, groups, compute resourcesProvider API
CSIRT Italia (ACN)Public bulletinsSynchronisation
Other systems (on-premise servers, network devices, business applications)—Uploaded evidence; for specific connectors (e.g. Okta, Jira) ask in the demo

In the register, the check type column shows for each control whether it is automated or manual.

What stays manual

Without an integration, technical requirements are demonstrated with uploaded evidence: for example backup restore tests, patching of servers and network devices, firewalls and VPN, log collection, encryption of on-premise systems. Nispo keeps the requirement, owner, status, proof and deadlines; a person does the check.

Presence is not effectiveness

NIS2 also requires assessing the effectiveness of the measures: a control being present does not tell you whether it would withstand an attack. That is why Nispo pairs the platform with cybersecurity services such as penetration testing and vulnerability assessment: findings enter the register and the retest documents their closure.

Who does what between Nispo and Microsoft tools: Nispo and Microsoft 365.

A 30-minute demo: we connect your systems (Microsoft 365, Google Workspace, AWS or Google Cloud) and show you your real controls, evidence and gaps.