Find the gap before the auditor does. Eight minutes against NIS2 21(2)(f).
Twenty questions across the five components of NIS2 21(2)(f). Returns a gap assessment, the controls your current program already produces, and the evidence Moxso would add. No demo gate. Carry the report into your next board meeting.
How is your workforce currently being measured? And reported on?
NIS2 21(2)(f) requires evidence of basic cyber hygiene practice. The compliance floor expects measurement, not just delivery.
Do you currently capture click rate by user, not just by campaign cohort?
Do you produce reporting rate by user as evidence of phishing recognition?
Can you produce a quarterly report mapping awareness coverage to job role?