With NIS2 being implemented through national law across the EU, organisations that provide essential digital services or support critical infrastructure are under pressure to demonstrate that they manage cybersecurity risk and can remain resilient over time. National authorities may request evidence, conduct inspections, carry out audits or require corrective measures.
NIS2 does not create one standard EU audit process equivalent to an ISO certification audit. The exact approach depends on the entity’s country, sector, classification and competent authority. This article explains how to prepare for a NIS2 audit, inspection or evidence request by focusing on scope, maturity, documentation, simulations, responsibilities and continuous preparation.
For context, NIS2 is the foundation for understanding the scope, obligations and supervisory expectations that apply.
6 Steps to prepare for an NIS2 Audit
1. Define your scope
Before preparing anything, determine whether your organisation is an essential or important entity under the NIS2 transposition applicable to your activities. Those categories influence the supervisory regime, reporting arrangements and measures that apply.
Scope questions to document
Verify and record:
- Sector and service: whether you operate in energy, transport, finance, health, water, digital infrastructure, ICT service management, public administration, space, manufacturing, food, chemicals, waste, postal services, research or another listed area.
- Organisation size: the employee, turnover and balance-sheet thresholds that apply under the EU SME definition and national law.
- Special or direct designation: whether your organisation is covered regardless of size, identified as a critical entity or designated directly by a Member State.
- Role in the supply chain: which services, customers and suppliers depend on your systems, without assuming that serving a critical-sector customer automatically makes you an in-scope entity.
- Systems and services: the networks, information systems, cloud services, operational technology, suppliers and business processes supporting the relevant service.
- Countries: the Member States where you operate, provide services or may need to register or report.
SaaS is not automatically in scope. A SaaS provider should assess whether its service falls within a listed digital or ICT category, whether it meets the applicable size criteria, whether it has been designated under national law and what sector-specific rules apply. A SaaS company should document this assessment rather than rely on its label alone.
Write a scope statement
Once you have clarity, define the scope of the review in writing. List the legal entity, relevant services, locations, systems, suppliers, exclusions and inclusion criteria. Including everything can dilute resources, while excluding a critical system can create a serious gap. The scope statement should explain how decisions were made and who approved them.
2. Assess your security maturity
Supervisory authorities want to see that cybersecurity risk is managed in a structured and consistent way. A gap assessment against NIS2 gives you a realistic picture of what is operating, what is missing and what must be prioritised before an inspection.
Maintain an active risk register
Your risk register should cover relevant cyber threats, affected systems and data, potential service impact, existing measures, residual risk, owners, deadlines and treatment decisions. A static document is not enough. Review it when technology, suppliers, threats, business structure or regulation changes.
Connect policies with operations
Policies should reflect how the organisation actually works. Compare written requirements with access reviews, incident records, supplier assessments, training records, vulnerability remediation, continuity tests and management decisions. If policy says one thing and practice shows another, the inconsistency will be difficult to explain.
Record the improvement plan
Maintain a gap report or equivalent action plan showing the current position, priority, owner, deadline, dependencies and evidence required for each action. Open gaps are not automatically a failure, but unexplained or unmanaged gaps weaken the organisation’s position.
3. Organise documentation and evidence
NIS2 reviews are not only about whether policies exist. Authorities may want to see a clear, traceable story of how the organisation identifies risk, selects measures, assigns responsibility, tests controls and improves over time.
Prepare an evidence index
Organise an evidence index covering at least:
- Scope decision, entity classification and national registration information
- Cybersecurity policy and management approval
- Risk register, treatment plan and residual-risk decisions
- Incident-management procedure and notification contacts
- Business-continuity, disaster-recovery and crisis-management plans
- Access-control, MFA, asset-management and vulnerability records
- Secure-development and change-management procedures
- Supplier assessments, contracts, security clauses and monitoring records
- Training content, attendance, management training and effectiveness checks
- Incident records, tabletop minutes, lessons learned and corrective actions
- Internal reviews, management-review minutes and improvement plans
The evidence should be current, version-controlled and easy to retrieve. A GDPR audit can illustrate the importance of linking documentation to operational records, although NIS2 has its own requirements and supervisory process.
Show how controls operate
For each important control, be able to explain the owner, frequency, system used, approval route, evidence location, exception process and last review. A policy without a completed access review, test record or management decision is unlikely to demonstrate effective operation.
4. Simulate an incident
One of the most scrutinised areas in a NIS2 review is incident response. Article 23 requires an early warning without undue delay and, in any event, within 24 hours of becoming aware of a significant incident. The incident notification generally follows within 72 hours, with intermediate updates where requested and a final report within one month, subject to the Directive’s rules for ongoing incidents. Organisations can also review the practical considerations in NIS2 compliance for SaaS companies when designing an incident process for cloud-based services.
Design a realistic tabletop exercise
Use a scenario that reflects your services, such as ransomware, a data leak, a cloud outage, a compromised supplier or loss of availability in a critical system. The exercise should test detection, severity assessment, containment, notification and recovery.
Test roles and internal deadlines
Walk through who detects the issue, who assesses whether it is significant, who approves the notification, who submits it to the CSIRT or authority, who informs customers and who coordinates legal and communications work. Set internal deadlines that leave enough time for review before the statutory reporting windows.
Keep exercise evidence
Prepare minutes with the date, participants, scenario, decisions, time taken, communication route, missing information and improvement actions. Record whether contacts were current, criteria were understood and notification templates were usable. A tabletop is valuable evidence only when its findings lead to tracked improvements.
5. Assign responsibilities clearly
NIS2 requires management involvement and traceable responsibility. The management body must approve and oversee cybersecurity risk-management measures, and its members must receive cybersecurity training. A CISO, compliance officer, IT lead or external adviser can coordinate the programme, but management cannot transfer its legal oversight simply by appointing someone else.
Document management involvement
Keep evidence of management approval, resource decisions, risk acceptance, review meetings, training and follow-up of significant findings. The records should show that cybersecurity is treated as a business responsibility rather than only an IT task. Training records should identify the audience, content, date, attendance and any effectiveness review, particularly where management and staff require role-appropriate privacy and cybersecurity training.
Identify operational owners
Assign owners for scope, risk management, incident response, supplier security, training, continuity, vulnerability management and authority contact. Include deputies and escalation routes so the process does not depend on one person.
Make responsibilities traceable
Use an organisational chart, role descriptions, designation records, responsibility matrix and incident call tree. Everyone involved should know what they do and when they must escalate an issue.
6. Prepare for continuous supervision
NIS2 is not a one-off exercise. Authorities can request evidence or conduct further reviews after an incident, material change or identified weakness. An information security management system (ISMS) can help organise recurring risk, control and evidence work, but it does not replace a NIS2 scope assessment. Preparation should therefore operate throughout the year.
Monitor controls continuously
Monitor whether access reviews, incident procedures, training, supplier checks, vulnerability remediation and resilience measures remain active. Record exceptions, overdue actions and management decisions.
Conduct periodic and event-triggered reviews
Review the risk register, policies, procedures and evidence on a practical schedule, and also after incidents, acquisitions, new systems, major supplier changes or regulatory developments. NIS2 does not create one universal annual audit timetable, so the review frequency should reflect risk and national expectations.
Record improvement
Track findings from inspections, internal reviews, incidents and exercises through corrective actions. Document what changed, who approved it, when it was tested and whether the risk was reduced. Continuous improvement is stronger evidence than a one-time compliance folder.
Understand what a NIS2 review involves
Before preparing an evidence pack, distinguish between the different types of review you may face:
- A national authority inspection or supervisory request
- A request for documents, information or corrective-action evidence
- An internal NIS2 readiness assessment
- A customer or supply-chain security assessment
- An ISO 27001 certification or surveillance audit, which is a separate process
NIS2 authorities may assess whether the entity is in scope, whether management has approved and overseen cybersecurity measures, whether Article 21 measures are implemented and whether the organisation can report and manage significant incidents. The authority may also examine suppliers, risk decisions, training and evidence that controls work in practice.
Check the national transposition position, competent authority, reporting channel and applicable sector rules before assuming that an EU-wide checklist is sufficient.
How PrivaLex can help prepare for a NIS2 audit or inspection
At PrivaLex Partners, we help organisations prepare for NIS2 audits, inspections and evidence requests, whether they are completing a first review or building a long-term resilience programme. We start by clarifying the entity’s classification, national requirements, service scope, systems, suppliers and likely supervisory process.
We then assess maturity against the applicable NIS2 requirements and create a prioritised roadmap. This can include risk mapping, policy and procedure design, management-responsibility records, incident-notification playbooks, continuity and recovery processes, supplier controls, training and an evidence index. The roadmap makes clear which actions are urgent, which depend on other work and what evidence will demonstrate completion.
Our preparation process can include an evidence request list, a control-to-evidence map, document review, interviews with management and technical owners, and a readiness assessment against the scope likely to be examined. We can identify missing approvals, outdated procedures, unclear escalation routes and gaps between written policies and operational practice.
We can facilitate incident-tabletop exercises, test internal reporting deadlines, review supplier arrangements and help teams close the gaps identified during the assessment. We document the exercise results, assign corrective actions and help verify that changes have been implemented. For ongoing maintenance, our approach can also support the principles described in staying compliant with NIS2.
Our support complements internal security, legal and technology teams. We can help prepare documentation and evidence, but the organisation and its management remain responsible for decisions, resources and compliance. We also keep the distinction clear between NIS2 readiness support and an ISO 27001 certification audit.
Where an organisation already has ISO 27001 certification, GDPR, DORA or sector-specific controls, we map shared evidence without assuming that one framework automatically satisfies NIS2. The result is a practical inspection-readiness programme that helps management explain the organisation’s scope, risks, controls, incidents, suppliers and improvement decisions.
5 NIS2 audit-preparation mistakes to avoid
1. Preparing for an undefined review
Treating every review as an ISO-style certification audit creates confusion. Identify the authority, legal basis, review scope, evidence request, reporting channel and response deadline first. An internal readiness review should be planned differently from a formal authority inspection.
2. Failing to decide whether the entity is in scope
Trying to prepare documents without resolving the sector, size, service and national-law position wastes resources. Start with a written scope decision that records the entity classification, countries, relevant services, systems, suppliers and exclusions.
3. Focusing only on policies
Policies need operational evidence: logs, approvals, completed reviews, training records, test results, supplier monitoring and corrective actions. For each major control, identify the owner, frequency, evidence location and process for handling exceptions.
4. Preparing only for the first 24-hour deadline
The 24-hour window is the early warning, not the complete reporting process. Teams must also prepare for the 72-hour notification, intermediate updates and final report. Internal deadlines should leave enough time for severity assessment, management approval and submission to the correct authority.
5. Treating accountability as an outsourced task
An adviser can support implementation and coordination, but management must approve, oversee and resource cybersecurity measures. Keep evidence of management decisions, training, risk acceptance, resource allocation and follow-up of significant findings.
Conclusion
Preparing for a NIS2 audit or inspection starts with a documented scope decision and continues through risk management, management oversight, operational controls, incident exercises, supplier reviews and evidence maintenance.
The strongest preparation is continuous. Keep the evidence current, test the 24-hour, 72-hour and final-report process, review changes in national implementation and make sure management can demonstrate that cybersecurity measures are approved, funded, monitored and improved.
Schedule a strategic session with PrivaLex to prepare your organisation for a NIS2 inspection or evidence request.
Frequently Asked Questions (FAQs)
In six steps: (1) define your scope by verifying sector, size, business volume, clients in critical sectors and systems/services/equipment in scope; (2) assess your maturity with a gap analysis (active risk register, assigned responsibilities, policies aligned with operations); (3) organise the documentation typically requested (incident management, access and privileges, training, third-party risk, evidence such as minutes, records and logs); (4) simulate an incident (tabletop) with scenario, steps with the team and documentation produced, including roles and notification deadlines; (5) assign clear responsibilities (senior management involvement, one identifiable person to coordinate compliance, traceability); (6) prepare for continuous audits with monitoring, periodic internal reviews, documentation updates and evidence of improvement.
No. NIS2 does not define a single certification process like ISO 27001. National authorities have powers to supervise and audit covered entities; they can request evidence, carry out inspections and require remedial measures. Being ready for those reviews is key to demonstrating compliance.
Documentation on incident management (procedures, roles, notification deadlines); access and privilege control; staff training on cybersecurity; assessment and management of third-party risk; an up-to-date risk register; and evidence that policies are applied (minutes, records, logs). Organise it for quick access.
Authorities can request evidence (policies, procedures, simulation minutes, training records), visit on site or in writing and, in case of non-compliance, impose sanctions (up to €10 million or 2% of global turnover for essential entities) and require remedial measures. Preparing in advance —defined scope, gap analysis, organised documentation, documented simulations and assigned lead— reduces risk and demonstrates good faith and maturity to the regulator.
NIS2 does not set a single frequency. Authorities can carry out reviews or request evidence when they see fit. So preparation must be continuous: monitoring, periodic internal reviews and up-to-date documentation, not just for a fixed date.
Yes. PrivaLex offers NIS2 gap assessments, risk mapping, policy and procedure design, incident simulations and preparation of documentation and evidence for inspections. We support you so you know how to prepare for a NIS2 audit and can respond clearly when the authority asks.
Next step
Knowing how to prepare for a NIS2 audit is the first step; the next is to define your scope and close gaps before the authority knocks. Schedule a strategic session with PrivaLex and turn preparation into advantage.
