diff --git a/docs/PAGES.md b/docs/PAGES.md
index c7128f9..edce3c1 100644
--- a/docs/PAGES.md
+++ b/docs/PAGES.md
@@ -13,6 +13,8 @@ structure, and draft copy. Use this as the brief for implementation.
| `/features` | Full feature list | P1 |
| `/drivers` | Supported devices | P1 |
| `/docs/getting-started` | Installation guide | P1 |
+| `/roadmap` | Roadmap — planned + under consideration | P1 |
+| `/nis2` | NIS2 landing page — Art. 21 mapping, evidence, roadmap | P1 |
| `/docs/architecture` | Technical overview | P2 |
| `/plugins` | Plugin system | P2 |
@@ -147,6 +149,33 @@ Each badge uses the `Driver / Integration Badge` component from DESIGN.md.
---
+### Section 5b — NIS2
+
+**Purpose:** Hook for organizations evaluating netOrk in a NIS2 context.
+
+**Layout:** Left column — label + Art. 21 mapping list. Right column — mock compliance overview UI.
+
+**Label (eyebrow):** `NIS2 · Art. 21` (sky-500, uppercase, tracking-widest)
+
+**Heading:** `Evidence, not paperwork.`
+
+**Copy:**
+```
+NIS2 Art. 21 mandates asset inventory, patch management, access control,
+and audit trails as baseline technical measures. netOrk doesn't bolt on a
+compliance layer — these are its day-to-day outputs.
+```
+
+**Art. 21 mapping (4 rows, icon = monospace article ref in sky-500):**
+- Art. 21 (2e) → Patch & vulnerability management — Per-device update status, Wazuh CVE counts by severity
+- Art. 21 (2h) → Asset management & access control — Full device inventory, RBAC with four roles, complete audit log
+- Art. 21 (2a) → Risk analysis baseline — Config drift detection, SNMP health metrics, security agent coverage
+- Art. 21 (2b) → Incident detection — Wazuh alert history, CrowdSec decisions, Graylog syslog per device
+
+**Mock UI (right column):** `MockCompliance` — per-site checklist with ✓/⚠ rows, each showing label + detail stat. Label: `netork.local / compliance / HQ`.
+
+---
+
### Section 6 — Plugin System (brief)
**Purpose:** Signal extensibility without going deep.
@@ -285,6 +314,43 @@ feature items as a clean list with `text-slate-400` body.
---
+## `/roadmap` — Roadmap
+
+**Purpose:** Show what's being built and what's under consideration. Signal NIS2 investment clearly.
+
+**Layout:** Page header + two vertical groups ("Planned" / "Under consideration"), each a list of items.
+
+**NIS2 badge:** `NIS2` monospace tag (sky-500/10 bg, sky-400 text, sky-500/20 border) inline next to item title.
+
+**Intro copy:**
+```
+What's being built and what's being evaluated. Items tagged NIS2 directly
+address NIS2 Art. 21 technical baseline requirements.
+```
+
+**Planned items (NIS2-tagged):**
+- CVE tracking per device — NVD / OSV cross-reference
+- Configuration backup & versioning — git-backed snapshots, change detection
+- Compliance dashboard — per-site Art. 21 checklist view
+- Audit log export — PDF / CSV with filters
+
+**Planned items (general):**
+- Webhook engine — outbound events with HMAC signing
+- Live job log streaming — WebSocket for all long-running tasks
+- NetBox sync — manual trigger + status view
+
+**Under consideration (NIS2-tagged):**
+- Incident workflow — structured record + NIS2 Art. 23 Fristen-Tracker
+- EOL tracking — endoflife.date integration for firmware / OS
+- MFA (TOTP) — second factor for netOrk logins
+
+**Under consideration (general):**
+- mDNS scanner — media device discovery
+- Prometheus + Grafana — metrics and dashboards
+- Kubernetes Helm chart
+
+---
+
## `/docs/architecture` — Technical Overview
**Purpose:** Give engineers the mental model before they look at code.
diff --git a/docs/PRODUCT.md b/docs/PRODUCT.md
index 95428ba..a612fc9 100644
--- a/docs/PRODUCT.md
+++ b/docs/PRODUCT.md
@@ -65,6 +65,11 @@ hardware and want operational visibility beyond what consumer dashboards offer.
8. **Self-hosted, no SaaS** — Runs in Docker Compose. Your data stays on your
infrastructure. No telemetry, no cloud dependency.
+9. **NIS2 evidence foundation** — NIS2 Art. 21 mandates asset inventory, patch
+ management, access control, and audit trails. netOrk produces all of these as
+ day-to-day operational outputs: full device inventory, per-device update status,
+ Wazuh CVE tracking, RBAC, config drift detection, and a complete audit log.
+
---
## Feature List
diff --git a/src/App.tsx b/src/App.tsx
index dba2dd8..416c969 100644
--- a/src/App.tsx
+++ b/src/App.tsx
@@ -5,6 +5,8 @@ import Home from './pages/Home'
import Features from './pages/Features'
import Drivers from './pages/Drivers'
import GettingStarted from './pages/GettingStarted'
+import Roadmap from './pages/Roadmap'
+import Nis2 from './pages/Nis2'
export default function App() {
return (
@@ -17,6 +19,8 @@ export default function App() {
NIS2 · Art. 21
++ NIS2 Art. 21 mandates asset inventory, patch management, access + control, and audit trails as baseline technical measures. netOrk + doesn't bolt on a compliance layer — these are its day-to-day outputs. +
+{m.label}
+{m.detail}
++ NIS2 Art. 21 defines ten categories of technical and organizational + measures. Some of them are directly addressed by what netOrk does + every day. This page maps each requirement to netOrk's current + capabilities — honestly, including what's partial and what's not + applicable. +
+{r.netork}
++ NIS2 audits require demonstrable outputs, not just claimed controls. Here's + what netOrk generates automatically. +
++ {e.trigger} +
+{item.title}
+{item.detail}
++ Asset inventory, continuous polling, drift detection, RBAC, and a full + audit log — deployed in one command. +
+ + Get started → + +
+ What's being built and what's being evaluated. Items tagged{' '}
+
{item.detail}
+