Which technical controls Nispo checks on its own, from which systems, and which remain manual.
- The ACN measures have administrative requirements (policies, plans, registers) and technical ones (encryption, updates, MFA). Software can check only some of them automatically, on the systems it is connected to.
- Nispo checks controls automatically on Microsoft 365 / Entra ID (read-only on Microsoft Graph), Google Workspace, AWS and Google Cloud; the rest is handled with uploaded evidence.
- Nispo does not enforce or change configurations: MFA, devices and endpoints remain the job of Entra ID, Intune, Defender or equivalent tools.
What Nispo checks on Microsoft 365
| Area | What Nispo reads | Example result |
|---|---|---|
| Authentication | MFA status of users and admins | “MFA enabled for all admins: passed” |
| Privileged accounts | Assigned admin roles | “3 admin accounts without MFA”, with a remediation task |
| Devices | Devices registered in the tenant | Up-to-date, exportable inventory |
| Users and licences | Tenant users and licences | List for the inventory |
Each result becomes dated evidence linked to the requirement. The connection uses read-only permissions on the Microsoft Graph API and takes about 5 minutes; the first checks take about 10-15 minutes, depending on the tenant.
Available integrations
| System | Scope | How |
|---|---|---|
| Microsoft 365 / Entra ID | Users, roles, MFA, devices, licences | Read-only on the Microsoft Graph API |
| Google Workspace | Identities, access, devices | Provider API |
| AWS | Access and cloud resources | Provider API |
| Google Cloud | Access, groups, compute resources | Provider API |
| CSIRT Italia (ACN) | Public bulletins | Synchronisation |
| Other systems (on-premise servers, network devices, business applications) | — | Uploaded evidence; for specific connectors (e.g. Okta, Jira) ask in the demo |
In the register, the check type column shows for each control whether it is automated or manual.
What stays manual
Without an integration, technical requirements are demonstrated with uploaded evidence: for example backup restore tests, patching of servers and network devices, firewalls and VPN, log collection, encryption of on-premise systems. Nispo keeps the requirement, owner, status, proof and deadlines; a person does the check.
Presence is not effectiveness
NIS2 also requires assessing the effectiveness of the measures: a control being present does not tell you whether it would withstand an attack. That is why Nispo pairs the platform with cybersecurity services such as penetration testing and vulnerability assessment: findings enter the register and the retest documents their closure.
Who does what between Nispo and Microsoft tools: Nispo and Microsoft 365.