Skip to content
pioneerdesk.

Category

An RMM built for NIS2: from obligation to evidence

NIS2 requires demonstrable measures for asset management, patching, risk treatment and reporting. An RMM is the tool that fulfils these obligations technically — provided it delivers the evidence along the way.

Dimension OneLog Other RMM
Asset inventoryContinuous, automatic inventory including shadow IT detection; NIS2 evidence exportableInventory available; NIS2 mapping and evidence left to the customer
Patch & vulnerability managementZero-touch patching with a complete history as evidence of measuresPatch automation available; evidence-keeping manual
Risk treatmentAutonomous remediation of defined incidents, documented per caseScripting/alerts; handling and documentation by the operator
Data locationEU-sovereign (STACKIT Sovereign Cloud, headquartered in Germany), no US cloud exposureFrequently US providers with CLOUD Act exposure

As of June 2026. Fair representation based on publicly available information; the feature set of other RMMs varies by plan. This does not replace legal advice on NIS2.

NIS2 requires measures — and evidence of them

NIS2 obliges affected companies to implement a set of technical and organisational measures. Four of them are exactly what an RMM does in daily operations anyway: an up-to-date asset inventory, functioning patch and vulnerability management, the treatment of identified risks and robust documentation.

The difference between “we do that” and “we can demonstrate that” is what decides an audit. An RMM becomes a NIS2 tool when it does not generate the evidence after the fact but records it from ongoing operations.

The four technical obligations — and how an RMM covers them

Asset inventory

NIS2 presupposes that you know what is running in your estate. An RMM maintains the inventory continuously and automatically — including the systems nobody registered. OneLog’s shadow IT detection closes precisely this gap instead of merely mirroring a manually maintained list.

Patch and vulnerability management

Unpatched systems are the most common route of entry. NIS2 expects vulnerabilities to be handled in a governed way. Zero-touch patching closes known gaps automatically and leaves a complete history — when what was closed on which system. This history is at the same time the evidence of measures taken.

Risk treatment

Detecting is half the obligation; treating is the other half. Where conventional RMMs stop at alert and script, OneLog’s AI agents resolve defined incidents autonomously and document every case. That shortens the time between detection and resolution — and provides the trail an audit wants to see.

Evidence-keeping and reporting

NIS2 places the burden of proof on you towards authorities and auditors. An RMM that logs asset changes, patch activities and remediation without gaps turns normal operations into audit-ready documentation — exportable, rather than reconstructed from logs.

Why data location becomes a NIS2 question

An RMM has the deepest reach into your infrastructure. If this tool itself sits under foreign jurisdiction, the compliance solution becomes a compliance risk. US-operated RMMs are potentially subject to the CLOUD Act — a growing procurement issue for KRITIS (German critical infrastructure) operators, public sector buyers and entities subject to NIS2.

OneLog is operated in the STACKIT Sovereign Cloud, is headquartered in Germany and is certified to ISO 27001:2022; the TOMs under Art. 32 GDPR are published. The platform is being validated in operation at a KRITIS hospital.

A fair assessment

NIS2 can be approached with almost any solid RMM — the technical building blocks are widespread. The effort simply shifts: with generic tools, you carry the mapping, the evidence-keeping and the sovereignty question yourself. OneLog takes these three points off your hands. An RMM does not replace legal advice and does not cover the organisational NIS2 obligations — it fulfils the technical core and makes it demonstrable.

NIS2 Art. 21 — covered by OneLog: eight building blocks from risk management through vulnerability handling and asset management to supply chain/hosting, each marked as fulfilled
The NIS2 Art. 21 obligations, mapped to OneLog functions.

Frequently asked questions

Does an RMM on its own satisfy NIS2 for my company?
An RMM alone does not — NIS2 also covers organisation, governance and reporting. It is, however, the central tool for the technical obligations: asset management, patching, vulnerability treatment and the associated evidence-keeping.
Which NIS2 obligations does an RMM cover technically?
Above all the up-to-date asset inventory, patch and vulnerability management, the treatment of identified risks and reporting. OneLog maps these functions directly to the NIS2 requirements and delivers exportable evidence.
Why is evidence-keeping so important under NIS2?
NIS2 requires not only measures but also the ability to demonstrate them to authorities and auditors. An RMM that logs patches, asset changes and remediation activities without gaps turns ongoing operations into audit-ready documentation.
Must a NIS2 RMM be operated in the EU?
It is strongly advisable. An RMM has full access to the IT estate; a US-operated tool is potentially subject to the CLOUD Act and thus itself becomes a procurement and compliance risk. OneLog is operated exclusively EU-sovereign.

See OneLog in your environment

Monitors and maintains your IT remotely and fixes many incidents automatically — hosted in the EU, with no dependency on US cloud providers. NIS2 requirements are built in from the start.