The entry into force of the NIS2 Directive across several EU Member States, along with the national transpositions currently underway, introduces a significant shift for all hosting, cloud and security service providers. One of the most critical points — and one that will directly affect the security tools we rely on — is the obligation to maintain complete, tamper-resistant and long-term logs, often for periods ranging from six to twenty-four months.
This is not simply an operational preference; it is a legal requirement. Service providers must be able to demonstrate, in a clear and verifiable way, that they can reconstruct security incidents, identify actions and prove that appropriate protection measures were in place. Without comprehensive and long-lasting logs, this becomes technically impossible.
This is precisely where cPFence plays an essential role.
Most small and medium-sized hosting providers do not have advanced security teams or large SIEM infrastructures. We rely heavily on the tools we deploy on our servers — and cPFence is a central component of that defence layer.
For this reason, I would like to make the following suggestion to both the community and the development team:
It would be extremely valuable for cPFence to evolve in the following areas:
– Providing more detailed, audit-oriented logs
– Allowing long-term, configurable log retention that meets legal requirements
– Implementing integrity mechanisms (log hashing/signatures)
– Enabling seamless integration with dedicated logging servers
– Supporting export of logs in formats suitable for NIS2 audits
This is not only about technical convenience.
In many EU countries, these requirements will become mandatory within the next few months.
I also want to address a point raised in the Enhance community: someone commented that “the European Union talks a lot but does very little.” And while this may feel true for certain regulations, with NIS2 the legal and financial responsibility falls directly on service providers. Even if enforcement takes longer in some regions, it is far safer to be prepared now than to scramble at the last minute — especially when compliance depends on something as essential as log retention.
Furthermore, through discussions with government contacts in several African countries, it is clear that many of them are planning to introduce legislation aligned with the European framework. This means the expectation for long-term, structured and reliable logs will become an international norm, not just a European one.
If cPFence adapts to these new requirements, it will not only strengthen the security posture of the ecosystem but also position itself as a crucial tool for hosting providers needing to comply with NIS2 without investing in expensive external systems.