Nr. 2 — Handling security incidents
The 24-hour clock in § 32 is only meetable if you can see the incident. Live sessions with the reason for each verdict, intrusion detection and prevention, and a CEF/LEEF/syslog-TLS feed into the SIEM you already run.
Nr. 4 — Supply-chain security
A German manufacturer, a CycloneDX SBOM with every release, and a published vulnerability-disclosure path. § 41 BSIG makes manufacturer trustworthiness a criterion; this is the paperwork that answers it.
Nr. 5 — Security in acquisition, development and maintenance
An Annex III Class II product under the EU Cyber Resilience Act, built to Annex I, with a published support period of at least five years and free security updates. The procurement file writes itself.
Nr. 8 — Cryptography and encryption
Selective TLS inspection with a policy that says where, encrypted overlays between sites in the engine, and DNS over TLS and HTTPS handled rather than blinded.
Nr. 9 — Access control
Devices recognised, users and groups from your directory, policy by zone and schedule, quarantine that isolates without cutting off. The records show who reached what, and why it was allowed.
Nr. 10 — Secured communication
Site-to-site overlays with automatic failover and per-application routing across uplinks. The § 30(2) Nr. 10 wording also covers multi-factor authentication; that is a directory and endpoint matter, and we do not claim it for a firewall.
Not covered by any firewall: Nr. 1, 3, 6, 7
Risk analysis, business continuity and backup, effectiveness assessment, cyber-hygiene training. These are organisational duties of the entity. NIS2 binds the operator, not the product; there is no NIS2 product certification, and we do not claim one.