Rapid7 NIS2 Compliance: What Exposure Command, Incident Command, and InsightVM Actually Prove Under Article 21(2)
Rapid7’s own NIS2 page names five products, lists all ten Article 21(2) measures, and says the platform provides broad support for them. It never says which measures. It also never mentions Commission Implementing Regulation (EU) 2024/2690 — the instrument that tells a digital-infrastructure entity what its monitoring, patching and testing evidence actually has to contain.
This guide closes both gaps. It maps each current Rapid7 capability to a specific Article 21(2) sub-paragraph and, where the Implementing Regulation binds you, to a specific Annex point. It names the four measures no Rapid7 product can evidence. And it deals with a problem no vendor page touches: Rapid7 has renamed most of its portfolio since 2024, and your audit evidence spans the rename.
Does the CIR 2024/2690 Annex Actually Bind You? Check This First
Two different rulebooks are in play, and most vendor content collapses them into one. Every essential and important entity owes the ten risk-management measures in Article 21(2) of Directive (EU) 2022/2555. Only eleven categories of organisation additionally owe the detailed technical specification in the Annex to Commission Implementing Regulation (EU) 2024/2690.
| Your organisation | Bound by the CIR Annex? | What governs your technical measures |
|---|---|---|
| DNS service providers, TLD name registries, cloud computing providers, data centre providers, CDN providers, managed service providers, managed security service providers, online marketplaces, online search engines, social networking platforms, trust service providers | Yes, directly | Article 21(2) plus the CIR Annex as a binding, itemised specification |
| Energy, transport, health, water, banking, manufacturing, food, chemicals, waste, postal, space, research, public administration | No | Article 21(2) as transposed into your national law. The Annex is an interpretive benchmark only, never a checklist you are legally held to |
| Mixed — e.g. a hospital group that also sells a public cloud service | Yes, for the in-scope service only | CIR Annex for the cloud service; national Article 21 transposition for everything else |
This matters commercially before it matters legally. If you are a manufacturer, a Rapid7 report that satisfies CIR Annex point 6.10 is useful evidence but not a legal requirement, and buying tooling to close an Annex gap you do not have is wasted budget. If you are an MSSP or a cloud provider, the Annex is the document your supervisor will read. Our guide to CIR 2024/2690 covers the full thirteen-section structure.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
What Rapid7 Actually Sells in 2026 — and Why the Old Names Still Matter
Rapid7 now markets four Command products: Surface Command for attack surface discovery, Exposure Command for hybrid exposure management, Incident Command for detection and response, and Vector Command as a managed continuous red team service. Rapid7’s platform page names none of the Insight products at all. Yet InsightVM and InsightConnect are still live, separately documented products with their own documentation trees, and Incident Command — launched on 29 July 2025 — is described as unifying SIEM, SOAR, attack surface management and threat intelligence into one interface without any published statement about what happens to InsightIDR.
| Current name | What it does | Older name you will find in evidence dated 2023–2025 |
|---|---|---|
| Exposure Command (Essentials / Ultimate) | Vulnerability detection, unified asset and vulnerability inventory, threat-aware risk scoring, policy and compliance checks with drift detection, remediation workflows. Ultimate adds multi-cloud, container and infrastructure-as-code assessment | InsightVM; InsightCloudSec for the cloud capabilities |
| Surface Command | Continuous internal and external attack surface discovery; included with Exposure Command | No direct predecessor |
| Incident Command | SIEM with SOAR, attack surface management and threat intelligence in one interface | InsightIDR |
| Automation (InsightConnect) | Workflow automation across security and IT systems, 300-plus plugins | Still sold and documented under the InsightConnect name |
| Vector Command / Vector Command Advanced | Managed continuous red teaming against the external attack surface; Advanced adds internal penetration testing | No direct predecessor |
Here is the compliance consequence, and it is the reason this section comes before the mapping table. Competent authorities supervising essential entities may run audits and inspections without needing any trigger, and they will ask you to demonstrate that a control has operated continuously. A three-year evidence trail for the same vulnerability-management control will carry scan reports headed InsightVM for 2024 and dashboards headed Exposure Command for 2026. Nothing in the regulation cares what the product is called, but an auditor reading two differently-branded artefacts will ask whether the control changed. Maintain a short control-to-product register: control reference, product name in use, date range, what changed functionally. It takes an afternoon now and is close to unreconstructable in three years.
Mapping Rapid7 to Article 21(2) and the CIR Annex
One correction before the table, because it circulates widely in vendor and AI-generated content. Rapid7’s SIEM is regularly mapped to a CIR Annex point in Section 6. Section 6 is titled Security in network and information systems acquisition, development and maintenance, it runs from 6.1 to 6.10, and there is no point 6.11. The monitoring and logging specification — the requirement that actually describes a SIEM — sits in Section 3, Incident handling, at point 3.2. If you cite a Section 6 number for your logging control, an auditor reading the Annex will find acquisition and patch management there instead.
| Rapid7 capability | Article 21(2) | CIR Annex point | What it evidences | What you still have to write |
|---|---|---|---|---|
| Exposure Command / InsightVM scanning and risk scoring | (e) vulnerability handling and disclosure | 6.10 | That you obtain vulnerability information, evaluate exposure, and act — the three verbs 6.10 uses | The disclosure procedure. 6.10 covers handling and disclosure; a scanner does neither half of disclosure |
| Remediation workflows and patch-status reporting | (e) | 6.6 | That patches were applied, and when | The definition of a reasonable time. 6.6 requires patches applied within a reasonable time after release; your SLA, not the tool, sets that number |
| Vector Command red team exercises | (f) assessing effectiveness of risk-management measures; (e) via testing | 6.5 and Section 7 | Documented security testing with scope, method, timing and results | The testing policy 6.5 requires, and the effectiveness-assessment methodology Section 7 governs |
| Incident Command SIEM detections and log pipeline | (b) incident handling | 3.2.1–3.2.4 | Automated monitoring, log coverage across authentication, privileged activity and configuration changes, and alarm thresholds | Retention periods. Point 3.2.5 requires predefined retention; the Annex sets no number, so you set and justify it |
| Automation (InsightConnect) playbooks | (b) | 3.1.1 | That detection, analysis, containment, recovery, documentation and reporting follow defined roles and run in a timely manner | The incident handling policy itself, plus the 3.1.3 evidence that procedures are tested periodically |
| Surface Command asset discovery | (i) asset management limb | Supports 3.2.3 log coverage by defining the estate | A current inventory of known and unknown internet-facing assets | Ownership, classification and the access-control policy that (i) also demands |
| Exposure Command policy and compliance checks | (a) risk analysis and information system security policies | Feeds 6.3 configuration management | Configuration drift against a baseline | The risk analysis narrative. A drift report is an input to a risk register, not a risk register |
The pattern across every row is the same, and it is the single most useful thing to understand before a supervisory audit: Rapid7 produces operational evidence that a control ran. The Annex, in almost every point, also requires a documented policy or procedure that says how the control is supposed to run. Scan data without a patch-management policy proves activity, not governance. Our guides on vulnerability and patch management and logging and monitoring requirements set out what those documents need to contain. If you are comparing scanners specifically, the same analysis for Tenable and Qualys reaches the same conclusion from the other direction.
Article 23’s Clock Starts Before Your SIEM Fires
Rapid7 states that it accelerates incident response workflows to help organisations meet the 24-hour and 72-hour reporting timelines required by NIS2. That is a fair claim about detection speed and a misleading one about the obligation, because the two are measured from different starting points.
Article 23(4) requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours of becoming aware, and a final report no later than one month after the notification. The clock is anchored to awareness, not to detection tooling and not to confirmation. Article 23(3) makes an incident significant if it has caused or is capable of causing severe operational disruption or financial loss, or has affected or is capable of affecting others with considerable damage. Read together, the widely held practitioner interpretation is that the 24-hour clock can start while your investigation is still open — a contained incident can still be significant.
No Rapid7 product submits a notification. The filing goes from your entity to your national CSIRT or competent authority, usually through a national portal, and it stays your legal duty even under a fully managed service. What Rapid7 can do is give you the three timestamps a supervisor will ask for: when the first alarm fired, when a human triaged it, and when someone decided it met the significance threshold. Instrument those explicitly in your playbooks. They are more defensible evidence than a mean-time-to-detect dashboard, which answers a question nobody in a regulatory conversation asked. Our incident reporting guide covers the notification content requirements at each stage.
The Four Measures Rapid7 Cannot Evidence
No vendor page states this, so state it in your own gap analysis. Of the ten Article 21(2) measures, four have no Rapid7 product behind them and one is only partially covered.
| Measure | Rapid7 coverage | Effort to close |
|---|---|---|
| (c) business continuity, backup management, disaster recovery, crisis management | None | Medium — policy set plus tested restore evidence |
| (g) basic cyber hygiene practices and cybersecurity training | None | Low — training records, plus Article 20(2) management-body training |
| (h) policies and procedures on the use of cryptography and, where appropriate, encryption | None — this is a policy obligation, not a tooling one | Low to medium |
| (j) multi-factor authentication, continuous authentication, secured voice, video and text communications | None — Rapid7 consumes authentication telemetry, it does not provide the factor | Medium — identity platform plus documented policy |
| (d) supply chain security | Partial — Exposure Command surfaces exposure in third-party software you run | Medium — supplier classification, contractual clauses, audit rights |
The stakes on the documentation half are not abstract. Article 20(1) requires management bodies to approve the risk-management measures taken to comply with Article 21, to oversee implementation, and provides that they can be held liable for infringements of that Article. Article 34(4) sets administrative fines for essential entities at a maximum of at least EUR 10 000 000 or 2 % of total worldwide annual turnover, whichever is higher, and Article 34(5) sets EUR 7 000 000 or 1,4 % for important entities on the same higher-of basis. A board signs off on the measure, not on the dashboard — which means someone has to hand the board a document describing the measure.
Rapid7 Becomes Your Supplier the Day You Sign
This is the reflexive obligation almost every vendor-selection process misses. Article 21(2)(d) covers security in the relationships between the entity and its direct suppliers, and Article 21(3) requires you to take into account the vulnerabilities specific to each direct supplier and the overall quality of its products and cybersecurity practices. Rapid7 is a direct supplier. Buying Rapid7 to close a NIS2 gap opens a smaller one.
Recital 83 indicates that the obligations apply regardless of whether entities maintain their systems internally or outsource their maintenance, and Recital 86 signals that managed security service providers have themselves been targets of cyberattacks and, because of their close integration into the operations of entities, pose a particular risk. Both are recitals — non-binding interpretive aids that explain intent rather than create obligations — but they are the clearest statement available of why a Rapid7 MDR contract does not transfer your duty anywhere.
There is a neat structural wrinkle worth knowing. Managed security service providers are one of the eleven categories the CIR Annex binds directly. So if you are a manufacturer, the Annex does not bind you — but it does bind your MSSP. That is a legitimate lever in a procurement conversation.
Concretely, ask Rapid7 for four artefacts and file them against 21(2)(d): the ISO 27001 certificate for its ISMS, the current SOC 2 Type II report, the BSI C5:2020 Type 2 examination report, which Rapid7 states covers the Command Platform and Threat Command, and written confirmation of your selected data region. Rapid7 states that customers of certain Insight platform solutions can select from five cloud regions including Europe, and that except as set out in its privacy policy or the applicable agreement it will not move data from the region you select. Our supply chain security guide and MSSP compliance guide cover the contractual side.
Which Configuration Matches Your Role and Your Gap
| Role | The question to answer first | What to take from Rapid7 | What you must produce elsewhere |
|---|---|---|---|
| CISO / IT security manager | Which Article 21(2) letters does my current licence already evidence? | Exposure Command for (e); Incident Command for (b); Surface Command for the (i) asset limb | The (c), (g), (h) and (j) control set — none of it is a tooling purchase |
| Compliance officer | Can I produce a dated artefact for each measure, signed by a named owner? | Exported scan, log and remediation records with timestamps and asset scope | Every policy document, plus the control-to-product-name register across the Insight-to-Command rename |
| SME owner without a security team | Am I even in scope, and is the Annex binding on me? | Start with Surface Command asset discovery — you cannot scope what you cannot see | A scope determination and a documented risk assessment before any tooling spend |
| Board member | What am I approving under Article 20(1), and what is my exposure? | Nothing directly — dashboards are not approval artefacts | A written statement of the risk-management measures, and the Article 20(2) training record |
If you are running the mapping exercise for the first time, our complete Article 21 breakdown lists all ten measures with the CIR sub-requirements underneath each, and the audit preparation guide covers what supervisors ask for.
Frequently Asked Questions
Does buying Rapid7 make my organisation NIS2 compliant?
No, and no tooling purchase can. Rapid7 produces operational evidence for roughly five of the ten Article 21(2) measures. The remaining measures, and the documented policies that sit behind every measure Rapid7 does support, are governance work.
Is InsightVM being discontinued in favour of Exposure Command?
We found no published end-of-life statement at the time of writing. InsightVM remains a separately documented product while the platform marketing names only the Command products. Treat this as an open question with your account team and record the answer — it affects how you describe control continuity in an audit.
Which CIR Annex point covers SIEM and logging?
Section 3.2, Monitoring and logging, inside Section 3 on incident handling. Point 3.2.2 requires monitoring to be automated and carried out continuously or at periodic intervals, subject to business capabilities. Section 6 is a different subject and ends at 6.10.
Does Rapid7 MDR satisfy the 24-hour reporting obligation?
No. MDR can compress the time from alarm to a defensible significance decision, but the notification is filed by your entity with your CSIRT or competent authority, and the duty is unaffected by outsourcing.
Does Vector Command count as the penetration testing NIS2 requires?
NIS2 does not mandate penetration testing by name. CIR point 6.5 requires a policy and procedures for security testing, and continuous red teaming can be documented as one method under that policy. Vector Command Advanced additionally includes an annual internal penetration test, which is the part most testing policies are written around.
The Practical Sequence
Work in this order. Determine whether the CIR Annex binds you at all, because it changes what the evidence has to look like. Map your existing Rapid7 licence to Article 21(2) letters before renewing or expanding it, since three of the four Command products address only two of the ten measures. Write the control-to-product register while the rename is still recent. Then spend the remaining budget on (c), (g), (h) and (j), where you currently have nothing — not on a further exposure-management tier, where you already have the best-evidenced controls in your programme.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Article 21 — Cybersecurity risk-management measures, Directive (EU) 2022/2555
- Article 23 — Reporting obligations, Directive (EU) 2022/2555
- Article 20 — Governance, Directive (EU) 2022/2555
- Article 34 — General conditions for imposing administrative fines, Directive (EU) 2022/2555
- Recitals 81 to 90, Directive (EU) 2022/2555
- Commission Implementing Regulation (EU) 2024/2690, EUR-Lex
- CIR 2024/2690 Annex — Technical and methodological requirements, Advisera full-text mirror
- NIS2 Compliance Solutions, Rapid7
- Does Your Security Programme Align With NIS2 Requirements?, Rapid7, 15 June 2026
- Exposure Command: Hybrid Exposure Management, Rapid7
- The Command Cybersecurity Platform, Rapid7
- Rapid7 Launches Incident Command, Rapid7 press release, 29 July 2025
- Vector Command — Continuous Red Teaming, Rapid7
- Vulnerability Management (InsightVM) documentation, Rapid7
- Automation (InsightConnect) documentation, Rapid7
- Compliance, Rapid7 Trust Center
- Transparency, Rapid7 Trust Center
- Rapid7 Launches the Command Platform, Rapid7 press release, 5 August 2024
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
