GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

NIS2 Cloud Provider (EU)

stable nis2-cloud-provider-eu · v1.0

The saas-ai-provider library read from the seat NIS2 gives it: a cloud computing service provider that is an essential or important entity under Directive (EU) 2022/2555 and a relevant entity under Implementing Regulation (EU) 2024/2690. Nothing here replaces the base profile. The overlay states only what the two instruments add to a control the vendor already runs, which is almost always a clock, a threshold, an audience or a documented reason. The Implementing Regulation is directly applicable, so it binds a provider serving EU customers whether or not the Member State has finished transposing the Directive, and it is written at requirement level rather than as principles: the Annex enumerates the contents of each policy and the review that keeps it current. Three additions carry most of the weight. Incident reporting acquires a statutory sequence to a CSIRT, a 24-hour early warning, a 72-hour notification, an intermediate report on request, a final report within a month and a progress report where the incident is still running. Incident classification acquires external thresholds, 30 minutes of complete unavailability, one hour of limited availability reaching the lower of 5 % of Union users or one million, EUR 500 000 or 5 % of turnover, and exfiltration of a trade secret. Governance acquires a management body that approves the measures, is trained to assess them and is reported to directly. The identification of the entity as essential or important, the national transposing law and the Member State supervisory regime sit outside the overlay: they are establishment questions, not controls. The managed service provider and managed security service provider seat (Implementing Regulation Art. 10) is a second role in this profile's composition rather than a second overlay: a vendor that also operates, administers or monitors a customer's systems holds the managed-service-provider role. The INC-003, INC-005 and MON-010 notes state what Art. 10 adds for it (product owner, S8 overlay profile review, 2026-09-14). No row is conditional on the seat, because the Art. 7 duties stay required for every reader; the first control only that seat triggers will carry the condition.

Roles
ProviderManaged Service Provider
Deployment models
Cloud, multi-tenant SaaSCloud, single tenant
Risk classes
noneminimaltransparencyhigh-risk-annex-iiigpai
Jurisdictions
EU
Frameworks
SOC2ISO-27001NIST-800-53CSA-CCMCSA-AICMISO-42001NIST-AI-RMFNIST-AI-600-1OWASP-LLMOWASP-AGENTICEU-AI-ActGDPRNIS2

Applicability statement

201 controls Download CSV
required 186 controls In scope for this profile. The control has to be in place and evidenced.

GOV · Governance & Risk

Annex point 1.1.1 of Implementing Regulation (EU) 2024/2690 fixes eleven contents for the policy, of which seven are not in the control: the commitment to continual improvement, the commitment to the resources needed for implementation, acknowledgement by relevant interested external parties, the list of documentation kept with its retention duration, the list of the topic-specific policies, indicators and measures of implementation and maturity, and the date of formal approval by the management bodies. Point 1.1.2 fixes the review at at least annually and hands it to the management bodies.

Annex point 1.2.3 requires at least one person to report directly to the management bodies on network and information system security, which is a line rather than a role. Point 1.2.2 extends the duty to apply the security policies to third parties as well as personnel, and point 1.2.6 has the management bodies review the allocation on interval and on significant incidents or changes.

Art. 20(1) of the Directive makes the management body approve the cybersecurity risk-management measures rather than only oversee them, and makes it liable for infringements of Art. 21. Annex point 1.1.1(k) turns the approval into a dated field on the policy, so the evidence is a date and a minute, not a status report.

Annex point 2.1.2 fixes the process: a stated methodology, a risk tolerance level set against the risk appetite, maintained risk criteria, an all-hazards identification that reaches third parties and single points of failure, and cyber threat intelligence as an input to the analysis. Point 2.1.4 sets the review floor at at least annually and adds significant incidents as a trigger.

Annex point 2.1.1 requires a risk treatment plan as a named artefact and requires the risk assessment results and the residual risks to be accepted by the management bodies, or by accountable persons with adequate reporting to them. Point 2.1.2(j) requires the reasons for accepting each residual risk to be documented comprehensibly.

Both instruments belong in the inventory, and so does the Member State whose transposing law and whose coordinated vulnerability disclosure policy apply, because Annex point 6.10.2(e) and Art. 12(1) of the Directive make the disclosure procedure depend on a national designation. Art. 4 of the Directive also records where DORA displaces Arts. 21 and 23 for a financial entity.

Annex point 2.2.2 asks for something a cyclical audit does not provide: a standing compliance reporting system, appropriate to the entity structure, operating environment and threat landscape, capable of giving the management bodies an informed view of the current state of risk management. Point 2.2.3 adds significant incidents and significant changes as triggers for the monitoring.

Annex point 7.2(b) requires the methods for monitoring, measurement, analysis and evaluation to be determined so as to ensure valid results, which is a statement about method validity rather than about cadence or ownership. Point 7.2 also makes the risk assessment results and past significant incidents inputs to the policy.

Art. 2(2) is now stated. The register holds a second kind of entry for a decision that a requirement qualified by 'where appropriate', 'where applicable' or 'to the extent feasible' does not apply: the requirement named, the reasoning written against this environment, the measure implemented in its place or the finding that none is reasonable and appropriate, the approver and a re-assessment trigger rather than an expiry. The control is renamed Exception and Requirement Determination Register.

Annex point 2.3.2 defines independence by line of authority rather than by employment and requires the reviewers to hold appropriate audit competence, with alternative impartiality measures where the entity is too small to separate the line. Point 2.3.3 routes results to the management bodies and resolves each one to corrective action or to a residual risk accepted against the entity risk acceptance criteria.

The provider seat is what brings a customer's supervisor to the organisation: the duty arrives through a customer contract rather than through a law binding the organisation directly. A provider whose customers are unregulated still holds the row, because what is tested is that the route exists, that the access is committed and that no contract term obstructs it. The register may legitimately be empty for a period, in which case the route is tested instead.

IAM · Identity & Access Management

Annex point 11.3.2(b), accounts set up to be used for system administration operations exclusively, is now stated in the control: administration operations run on accounts used for that purpose only, separate from the holder's standard account and carrying no entitlement outside administration. Point 11.3.2(d) moved to IAM-016 with the administration systems it depends on.

Annex point 11.4 of Implementing Regulation (EU) 2024/2690 is the anchor: system administration systems used for administration purposes and nothing else, logically separated from application software not used for administration, with access protected by authentication and encryption. Annex point 11.3.2(d), administration accounts used only to connect to administration systems, and point 6.7.2(e), systems used to administer the security policy implementation not used for anything else, both depend on those systems existing as a class and are stated on this control rather than on IAM-007.

DAT · Data Protection

Annex points 9.2(a) and 9.2(b) are now stated: a maintained list of the protocols, algorithms, cipher strengths, solutions and usage practices approved for use, with the type and strength required per asset class for data at rest and in transit, every production implementation resolving to an entry and a withdrawn entry carrying its migration route, which is what the cryptographic agility approach needs.

Customer-held keys are a commitment of a hosted service.

Location transparency is a commitment of a hosted service to its tenants.

Export and portability are commitments of a hosted service to its tenants.

Exit is executed by the provider on the customer's behalf, because the customer cannot run the transition on infrastructure it does not control.

Retrieval interfaces and the information needed to stand the service up elsewhere are commitments of a hosted service to its tenants, on the same footing as the export capability in DAT-023.

APP · Application Security

Annex point 6.10.2(e) requires the disclosure procedure to be in accordance with the applicable national coordinated vulnerability disclosure policy, which Art. 12(1) of the Directive routes through a CSIRT designated as coordinator in each Member State. The policy content varies, so the programme acquires a per-establishment dependency it did not have.

INF · Infrastructure & Cloud Security

Annex points 6.7.2(j), (k) and (l) require three forward-looking artefacts the control does not name: an implementation plan for the transition to latest generation network layer communication protocols, an implementation plan for the deployment of modern e-mail communications standards, and best practice for DNS security and for Internet routing security and routing hygiene. Recital 32 of the Regulation records that the standards themselves are not yet settled, so the duty is to hold a plan rather than to have arrived.

Tenant isolation exists because the product is cloud-hosted and shared.

Annex point 6.7.2(l) is now stated in both halves. The inventory records, for each address range and routing origin the service is announced from or depends on, the routing security measure in force and who applies it, with origin registration and authorisation where the organisation announces its own space and the operator's published statement where it announces none. The control is renamed Domain, DNS and Routing Security.

Annex points 13.1 and 13.2 add supporting utilities and environmental thresholds: electricity, telecommunications, water, gas, sewage, ventilation and air conditioning protected and monitored, redundancy considered, emergency supply contracts concluded, minimum and maximum control thresholds determined and events outside them reported. For a provider running on a third party facility the substance is inherited, and the control's attestation route is what evidences it, so the delta is that the attestation has to be read against this list rather than against a generic physical security expectation.

MON · Monitoring & Logging

Annex point 3.2.3 lists twelve log sources and six are outside the usual security-event scope: relevant outbound and inbound network traffic, access or changes to critical configuration and backup files, use of system resources and their performance, physical access to facilities, access to and use of network equipment and devices, and the activation, stopping and pausing of the logs themselves. The list of assets to be logged is derived from the risk assessment rather than set directly.

Annex point 3.2.6 is now stated: the log management platform and the monitoring systems are redundant and their availability is monitored from outside the platform they run in, so the outage that takes the platform down does not take the check with it.

Art. 7 of Implementing Regulation (EU) 2024/2690 turns availability measurement into a reporting trigger: complete unavailability for more than 30 minutes, and limited availability for more than one hour affecting the lower of 5 % of the service users in the Union or one million of them. Art. 3(3) fixes the denominator as the contracting customers plus the natural and legal persons associated with business customers, which is not the same as monthly active users and has to be derivable. For an organisation that also holds the managed-service-provider role, Art. 10 measures the managed service rather than the cloud service, with the users of the customer's systems as the denominator, so availability of what is operated on a customer's behalf has to be measurable on its own.

VND · Vendor & Third-Party Risk

Annex point 5.1.1 requires a supply chain security policy as a named artefact in which the entity identifies its own role in the supply chain and communicates it to its direct suppliers. Point 5.1.2 adds the supplier secure development procedures and the ability to diversify sources and limit vendor lock-in as selection criteria. Point 5.2 adds two fields to the register, a contact point per supplier and the list of ICT products, services and processes each provides. Point 5.1.3 and Art. 21(3) require the results of an Art. 22 coordinated assessment to be taken into account once one is published.

Annex point 5.1.4 fixes eight contract terms and three are not in the control: requirements on the awareness, skills, training and where appropriate certifications of the supplier employees, verification of the background of those employees, and an obligation on the supplier to handle vulnerabilities that present a risk to the entity network and information systems, which is distinct from notifying an incident. Point 6.1.2(b) adds terms on security updates through the lifetime of an acquired product or replacement after end of support.

The shared responsibility matrix exists because the customer's workload runs on the provider's service.

Requests for customer data reach the provider because it hosts the tenant's data.

A hosted service has customers whose data it holds, so the terms on which a customer leaves and the terms a regulation makes compulsory for that data are commitments of the service rather than internal practice.

A customer scoping its own controls over a workload it does not run needs a stated route to inspect the provider. VND-011 publishes the boundary; this states the access across it.

Annex point 5.2 adds two fields to every register entry, a contact point for the party and the list of ICT products, ICT services and ICT processes it provides, kept up to date rather than reviewed on a cycle. Point 5.1.4 adds four contract terms to the subcontract for a customer-facing service: competence, skills, training and where appropriate certification of the party's employees at point (b), verification of their background at point (c), an obligation to handle vulnerabilities presenting a risk to the entity's systems at point (f) and the requirements applying where that party subcontracts further at point (g). Point 6.1.2(b) adds security updates through the life of the product or replacement after support ends. VND-001 keeps the register of direct suppliers as a whole and VND-002 the general contract terms.

INC · Incident Response

Annex point 3.1.2(a) requires a categorisation system inside the policy that is consistent with the event assessment and classification under point 3.4.1, and point 3.1.3 requires the roles, responsibilities and procedures to be tested as well as reviewed. Point 3.5.3 adds a communication plan with the CSIRT or competent authority alongside the internal and stakeholder one.

The taxonomy now carries the external notification thresholds and criteria that bind the service, with the population each proportional threshold is measured against, and aggregates closed sub-threshold incidents by apparent root cause. The figures this instrument supplies are the entries: Art. 3 fixes seven criteria, among them direct financial loss above the lower of EUR 500 000 or 5 % of turnover, trade secret exfiltration, death or considerable damage to health and a successful suspectedly malicious access capable of severe disruption; Art. 7 adds 30 minutes of complete unavailability, one hour of limited availability reaching the lower of 5 % of Union users or one million and the two data-compromise limbs; Art. 3(3) fixes the denominator by counting the natural and legal persons associated with business customers and not only the contracting ones; Art. 4 aggregates incidents recurring at least twice in six months with the same apparent root cause, tested quarterly under Annex point 3.4.2(b). For an organisation that also holds the managed-service-provider role, Art. 10 repeats the four Art. 7 criteria with the managed service or managed security service as the unit measured, applied to the systems it operates, administers or monitors on a customer's behalf. The NIS2-CIR-Art.10 disposition closes with the mapping this wave writes.

The control now holds a register of every statutory reporting obligation an incident can trigger, with the trigger, the recipient, the clock and the content of each, and records every submission against its deadline. This instrument supplies five entries running in parallel with the GDPR clock: an early warning within 24 hours of awareness, an incident notification within 72 hours, an intermediate report on request, a final report within one month of the notification with four fixed contents, and a progress report where the incident is still running at that point with the final report a month after handling ends. For an organisation that also holds the managed-service-provider role, an incident crossing an Art. 10 threshold on a managed service runs the same sequence, so the classification decision in INC-003 says which service tripped it.

Both outbound messages are now stated. Art. 23(1) requires recipients to be notified without undue delay of a significant incident likely to adversely affect the provision of the service, whether or not personal data is involved, which the control carries as a trigger and a period named per regulation that binds the service. Art. 23(2) is the second message on a different trigger, a significant cyber threat with the measures or remedies the recipient can take, and the control now holds the advisory and the recorded decision on whether the threat itself was disclosed.

Annex point 3.6.3 is now stated: at planned intervals the incidents closed in the period are checked against the reviews held, and one that met the trigger and produced no review carries a reason and a corrective action.

The contact list acquires named entries: the CSIRT and the competent authority of the Member State in which the provider is regarded as established, and the CSIRT designated as coordinator for coordinated vulnerability disclosure under Art. 12(1). Annex point 4.3.2(b) requires the communication means to carry non-obligatory communications too, so the list is a working channel rather than an emergency one.

BCM · Business Continuity

Annex point 4.3 adds a crisis management process with two outward limbs the plan does not carry: communication means with the competent authorities covering both obligatory communications such as incident reports and their timelines and non-obligatory ones, and a process for managing and using information received from the CSIRTs or competent authorities about incidents, vulnerabilities, threats or mitigations. Point 4.3.2(a) extends the role allocation to suppliers and service providers.

AIG · AI Governance

Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.

Art.5 binds every provider, whatever the risk class of its other systems.

Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).

The provider is also a user of AI systems, including the models beneath its product. The use register covers both.

The statement on customer data in training and the opt-out are the provider's to give.

Any organisation that trains, fine-tunes or evaluates a production model runs the pipeline this control secures. A provider that only calls a third-party model records that no pipeline exists against the inventory entry.

Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16).

HRS · Human Resources Security

Annex point 8.1.1 widens the audience beyond personnel to members of management bodies as a named group and to direct suppliers and service providers where appropriate under point 5.1.4. Point 8.1.3 requires the effectiveness of the programme to be tested, which is a measurement of the training rather than of completion.

Art. 20(2) and Annex points 8.2.2 to 8.2.4 are now stated: named role groups with the criteria by which a role enters the programme, a competence standard per group, the members of the management body as one of those groups with the Art. 20(2) standard of enough knowledge and skill to identify risks and assess risk-management practices and their effect on the services, training on transfer into a named role, and effectiveness assessed rather than completion counted. Annex point 8.1, the awareness programme reaching direct suppliers and service providers, stays a note on HRS-004.

Annex points 3.3.1 and 3.3.2 are now stated: the mechanism is reachable by suppliers and customers as well as employees, is communicated to them, and an external report is acknowledged and tracked on the terms the channel states. The control is renamed Security Event Reporting Channel, because it is no longer a personnel-only route.

conditional 4 controls In scope when the stated condition holds. Read the condition before deciding.

AIG · AI Governance

Condition: ai_risk_class in high-risk-annex-iii

Art.17 quality management system binds providers of high-risk systems.

Condition: ai_risk_class in high-risk-annex-iii

Conformity assessment, the declaration and the CE marking (Art.43, 47, 48) bind providers of high-risk systems.

Condition: ai_risk_class in high-risk-annex-iii and the organisation is established outside the Union

Art.22 binds providers of high-risk systems established outside the Union. The Art.54 arm for general-purpose model providers belongs to the gpai-model-provider profile.

Condition: ai_risk_class in high-risk-annex-iii

Art.20 and Art.21 bind providers of high-risk systems. The Art.53.5 cooperation duty on general-purpose model providers belongs to the gpai-model-provider profile.

not-applicable 11 controls Out of scope for this profile. It is stated rather than omitted so the exclusion is auditable.

AIG · AI Governance

Worker notification before a system is put into use at a workplace is an employer's duty under Art.26(7). A provider placing the system on the market owes it for its own workforce only where it is also the deployer, which is the enterprise-ai-deployer seat.

Registration by the organisation using the system is a deployer duty under Art.49(3). The provider registration of Art.49(1) and (2) sits on AIG-003 and is required of this profile there.

The fundamental rights impact assessment of Art.27 is owed by the deployer about the use it makes of the system. A provider's duty is to supply the information the assessment draws on, which AIG-034 carries.

Documentation of a general-purpose model as such is the gpai-provider seat (gpai-model-provider, ADR-046). A SaaS provider documents its product under AIG-015 and, where it also trains and offers a general-purpose model, holds the gpai-provider role and that profile alongside this one.

The public training content summary is the gpai-provider seat (ADR-046). A provider that fine-tunes a third-party model for its product records provenance under AIG-013 and is not the models provider.

The copyright policy and crawler conduct of a general-purpose model provider are the gpai-provider seat (ADR-046). A SaaS providers own licensed assets and training data licences are GOV-015 and AIG-013.

Systemic risk at Union level attaches to a designated general-purpose model and its provider (ADR-046). Risk from the systems a SaaS provider builds is AIG-005.

Evaluation under standardised protocols attaches to a designated general-purpose model (ADR-046). A SaaS provider evaluates the systems it operates under AIG-026 and AIG-008.

Protection of a designated models weights to a stated security goal is the gpai-provider seat (ADR-046). A SaaS providers development assets and training pipeline are IAM-014 and AIG-055.

Reporting to the AI Office about a designated model is the gpai-provider seat (ADR-046). A SaaS provider reports a systems serious incident to the competent authority under AIG-021.

The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.

Published 2026-09-14