Audit and readiness
NIS2 audit: what a supervisor asks for, and how to get there first
A NIS2 audit is not a technical exam but an evidence exam: the supervisor checks whether you can produce a dated artefact with a named owner per measure, and always starts at governance. Organizations that fail usually have the measures. What they lack is the paperwork.
Key takeaway: a supervisor cannot see your controls, only your evidence. The gap between "we do this" and "here is the artefact, dated, owned and reviewed" is where almost every finding sits. An independent audit beforehand closes that gap while there is still time to act.
What can a supervisor actually require?
Article 32 sets out the supervisory measures available against Essential Entities. The list is broader than people expecting a light regime tend to assume.
- On-site inspections and off-site supervision, including random checks, carried out by trained professionals.
- Regular and targeted security audits by an independent body or by the competent authority itself.
- Ad hoc audits, justified by a significant incident or an apparent infringement.
- Security scans based on objective, non-discriminatory, fair and transparent risk assessment criteria.
- Requests for information needed to assess your cybersecurity risk management measures, including documented security policies.
- Requests for access to data, documents and evidence of implementation, such as the results of security audits and the underlying evidence.
Important Entities fall under Article 33 instead. The powers are broadly comparable but exercised ex post: the authority acts once it has evidence, an indication or information suggesting an entity is not meeting its obligations. For planning that means something different. An Essential Entity should assume it may be examined at any point without warning. An Important Entity should assume an incident, a complaint, or a finding at a peer will trigger the visit.
The cost rule people miss
Where an authority orders a targeted security audit by an independent body, Article 32(2) provides that the cost is borne by the audited entity, except in duly justified cases where the competent authority decides otherwise. An unplanned external audit halfway through a financial year is a harder conversation with the board than a planned readiness assessment.
What does an auditor look at, and in what order?
Not Article 21(2)(a) and then downward. A supervisor starts at governance, because governance determines how much trust to extend to everything else. Build the file in the order it gets read.
Governance and accountability
The risk management policy with its date and minuted management body approval, the per-director training register, the scope determination, and who owns the risk. If this layer is weak, everything below it is read sceptically.
Risk and asset foundation
The risk register with named owners, assessment dates, treatment decisions and accepted residual risk, plus a service-linked asset inventory tying each service to the systems and suppliers beneath it.
The ten Article 21 measures
One folder per measure, holding the policy, the operational artefact that shows the policy works, and the most recent review record.
Incidents and exercises
The incident register, the classification test for what counts as significant, copies of any Article 23 notifications with their timestamps, and exercise reports from the past twelve months.
How does the audit day itself run?
The pattern is consistent enough to plan around. An opening session on governance and scope, usually with directors present. A walkthrough of the risk management approach, following one or two real services end to end rather than assessing policy in the abstract. Then sampling: give me the access review for this system, show me the patch record for that server, produce the notification you sent for the incident in March. Finally a closing session summarising the observations.
Three behaviours make the day go better. Answer the question asked, not the question you prepared for. If you do not know something, say so, agree a moment to supply it, and hold to that. And have one person log every request, every document handed over and every commitment made, because that follow-up list becomes the formal findings list. Do not volunteer material beyond the question: every extra artefact is one more thing that has to stay consistent with everything you have already said.
Which findings keep coming back?
- Policy approved by the wrong body. Article 20 requires management body approval. A sign-off by the IT director alone is a governance finding.
- Training that happened but cannot be demonstrated. Without an attendance list, trainer credentials and minutes, the session does not count.
- Risk register with no residual risk. Registers that list risks and controls but never state what residual risk was accepted, and by whom, fail the accountability test.
- MFA with an undocumented exception list. Exceptions are acceptable. Exceptions without a named owner, a compensating control and a review date are not.
- Backups never restored. A backup job completing successfully is not evidence of recoverability. A dated restore test with a measured recovery time is.
- No written classification test. If nobody agreed in advance what triggers the 24 hour early warning, the decision gets made under pressure by whoever is on duty.
- Effectiveness never assessed. Article 21(2)(f) requires policies to assess the effectiveness of measures. Many programs implement controls and never evaluate whether they work.
What happens after a finding?
Article 32(4) gives authorities a graduated set of enforcement powers: warnings, binding instructions, orders to cease conduct that infringes the directive, orders to bring measures into compliance within a set period, orders to implement audit recommendations, orders to inform affected persons, appointment of a monitoring officer, orders to make aspects of an infringement public, and administrative fines.
For Essential Entities, Article 32(5) adds one more step. Where other enforcement measures have proved ineffective, a member state may temporarily suspend a certification or authorisation concerning the services the entity provides, and temporarily prohibit a natural person with management responsibility at chief executive or legal representative level from exercising that function. That is the provision boards need to understand, because it reaches individuals rather than balance sheets.
What does a Grey Clerk NIS2 audit deliver?
An independent gap and readiness audit by a PECB Certified NIS2 Lead Implementer gives you an honest picture of your position against Article 21 and Article 23 in two weeks. Not a marketing report, but a workable list of what has to happen now, this quarter, and this year.
- A gap analysis per Article 21 measure.
- A board briefing with the three biggest risks in plain language.
- An evidence pack your supervisor and your cyber insurer both accept.
- A 90 day action list with a named owner per line.
Three fixed price packages, no open ends. The work covers Essential and Important Entities in all 27 EU member states, and differences in national transposition are taken into account per engagement.
Frequently asked questions
What is a NIS2 audit?
A check on whether your risk management measures and your reporting process are demonstrably in order. That can be an on-site inspection by the competent authority, a targeted security audit by an independent body mandated by that authority, or a readiness assessment you commission yourself before the supervisor arrives.
Does NIS2 require an external audit?
The directive imposes no standing certification requirement. It does give competent authorities the power to require targeted security audits, carried out by an independent body or by the authority itself, and to require ad hoc audits where justified.
Who pays for a targeted security audit?
Article 32(2) provides that the cost of an audit ordered by the authority and carried out by an independent body is borne by the audited entity, except in duly justified cases where the competent authority decides otherwise.
How does supervision differ for Essential and Important Entities?
Essential Entities are under ex ante supervision through Article 32, which allows inspections, random checks, regular and targeted audits, security scans and information requests with no prior indication of a problem. Important Entities are under ex post supervision through Article 33: the authority acts once it has evidence or an indication that obligations are not being met.
What evidence does an auditor ask for first?
Governance artefacts. The approved risk management policy with its date and the record of management body approval, the Article 20 board training register, the risk register with named owners, and the incident register. Technical evidence such as MFA coverage and patch metrics comes after that.
Does a finding lead straight to a fine?
Usually not. Article 32(4) sets out a graduated range of powers: warnings, binding instructions, orders to cease conduct or to bring measures into compliance, appointment of a monitoring officer, public disclosure, and administrative fines. What escalates a case is not the original gap but failing to close it by the stated date.
Get the findings before the supervisor does
Burak runs readiness assessments the way an authority would: governance first, then sampling, then a written findings report with owners and dates. If you are not yet certain NIS2 applies to you, start with the scope check.
Read next: the eight step NIS2 checklist, the methodology, about the auditor.