# Reporting

> Run the built-in NIS2 security compliance and endpoint inventory reports, and export them to CSV or Excel.

Source: https://docs.capaone.com/capaone/reference/reporting/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

CapaOne includes built-in reporting under **Management → Reporting** for two common compliance
and inventory needs: **NIS2** security compliance and **Endpoint** inventory. Both reports can be
exported to CSV or Excel.

## NIS2 report

The NIS2 report summarises your endpoints' security state against the controls relevant to the
EU NIS2 Directive (Network and Information Security Directive). It covers:

- **Missing updates per Windows endpoint** — which devices are missing patches
- **Endpoints per OS version** — fleet breakdown by OS version, useful for identifying devices
  on unsupported or outdated versions
- **System updates for Apple and Android endpoints** — update compliance across mobile devices
- **Windows Antivirus** — antivirus protection status per endpoint
- **Windows Encryption** — disk encryption status per endpoint
- **Firewall** — firewall configuration status per endpoint
- **Detected CVEs on Windows endpoints** — vulnerability exposure from the Security Monitor

This report is intended to support periodic security reviews and provide evidence of control
coverage for NIS2 compliance purposes. Export to Excel for distribution to auditors or management.

## Endpoint inventory report

The Endpoint report is a snapshot of all managed devices, useful for asset inventory audits.
It includes:

- Endpoint type (Desktop, Laptop, or Server)
- Endpoint name
- CapaOne Agent version installed
- Operating system
- Latest OS startup timestamp
- Service startup timestamp
- Available software updates

Export this report to CSV for integration with other asset management or CMDB tooling, or to
Excel for a formatted inventory spreadsheet.

## Archived reports

Previously exported reports are stored under the **Archived** button in each tab. If no reports
have been exported yet, the archive is empty. Archived reports let you compare current state
against a historical snapshot without re-generating the full report.

## Good to know

- **Both reports are cross-platform where applicable** — the NIS2 report includes Apple and
  Android endpoints for update compliance, not just Windows.
- **Export formats** — CSV is better for importing into other systems or scripts. Excel is better
  for sharing with stakeholders.
- **Reports reflect current data** — the report generates based on the latest inventory data from
  enrolled endpoints. Endpoints that have not checked in recently may have stale data.
- **NIS2 is an EU directive** — if your organization is not subject to NIS2, the report still
  provides a useful security posture summary covering the most common endpoint security controls.
