NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
NIS2 Audit: What to Expect
Learn

NIS2 Audit: What to Expect

·Alexander Sverdlov

A NIS2 audit is not one thing, and the single most useful fact about it is that Directive (EU) 2022/2555 creates two supervisory regimes rather than one. Essential entities can be subjected to the full set of supervisory measures in Article 32(2), including regular security audits and random checks, with no incident and no complaint required to trigger them. Important entities are supervised the other way round: under Article 33(1) the competent authority acts when it is provided with evidence, indication or information of non-compliance, and it does so through ex post measures. Which side of that line you sit on decides whether an auditor can arrive without a reason.

The second thing worth knowing before any letter arrives is who pays. Both articles say the same thing: the costs of a targeted security audit carried out by an independent body are paid by the audited entity, except in duly substantiated cases where the competent authority decides otherwise. A NIS2 audit is not a free inspection. It is an invoice you receive for being inspected, and the results go to the authority whether you like them or not.

FactDetail
Governing lawDirective (EU) 2022/2555. Member States had to adopt implementing measures by 17 October 2024 and apply them from 18 October 2024 (Article 41).
Who audits youYour national competent authority, or an independent body it appoints. Not the European Commission.
Essential entitiesSeven supervisory powers, Article 32(2), points (a) to (g). None of them require an incident first.
Important entitiesSix supervisory powers, Article 33(2), points (a) to (f), applied ex post under Article 33(1).
What gets testedThe Article 21(2) risk-management measures, the Article 23 reporting duties, and the Article 20 governance and training duties.
Who pays for the auditThe audited entity, for a targeted security audit carried out by an independent body.
Where the results goThe results of any targeted security audit are made available to the competent authority.
If it goes badlyThe Article 32(4) enforcement ladder, and administrative fines under Article 34.
The two NIS2 supervisory regimes: seven powers over essential entities under Article 32(2) applied ex ante, and six powers over important entities under Article 33(2) applied ex post

What actually happens in a NIS2 audit?

The Directive does not describe an audit as a single event with an agenda. It gives the competent authority a list of powers and lets national law decide how they are exercised. Reading the two lists side by side is the fastest way to understand what can be done to you.

Supervisory powerEssential entities, Art. 32(2)Important entities, Art. 33(2)
On-site inspections and off-site supervisionYes, including random checks by trained professionalsYes, but the off-site supervision is expressly ex post
Regular and targeted security auditsYes, regular and targetedTargeted only
Ad hoc auditsYes, including on the ground of a significant incident or an infringementNot listed
Security scansYes, on objective and non-discriminatory criteriaYes, on the same criteria
Requests for informationYes, including documented cybersecurity policiesYes, to assess the measures ex post
Requests to access data, documents and informationYesYes
Requests for evidence of implementationYes, such as the results of an audit by a qualified auditorYes, on the same terms

Two words carry most of the difference. Regular and ad hoc appear in Article 32 and not in Article 33. An essential entity can therefore be put on a recurring audit cycle and can be audited immediately after an incident, as a matter of routine supervision rather than as an accusation. An important entity, on the Directive's own wording, gets a targeted audit only once the authority has something that points at non-compliance.

One protection applies to both. Where an authority uses its powers to request information, access or evidence, Article 32(3) and Article 33(3) require it to state the purpose of the request and specify the information requested. A request that does neither is worth querying before you start assembling documents.

The Article 21(2) evidence a NIS2 auditor asks for, including risk analysis policy, incident handling, business continuity, supply chain security, access control policy and training records

Who gets audited, and when?

Classification comes first. If you have not written down whether you are an essential or an important entity, you cannot answer the question this article is about, and our guide to what NIS2 is and who must comply is the place to settle it.

After that, timing is a national matter, and this is where the published guidance goes furthest beyond the text. Article 31(2) lets Member States allow their authorities to prioritise supervisory tasks on a risk-based approach, and to establish supervisory methodologies to do it. So the honest answer to when is: on your authority's risk model, published in your Member State, under national transposing law. The Directive fixes the powers. It does not fix a cycle, a notice period or an agenda, and any article that gives you a fixed number of weeks of warning is describing one country's practice rather than NIS2.

Because NIS2 is a directive rather than a regulation, a group operating in several Member States can face several authorities applying the same substance through different procedures. That fragmentation is real and it is the part of NIS2 worth planning for explicitly, in the same way our comparison of DORA and NIS2 treats overlapping supervision as a design problem rather than a surprise.

How a NIS2 supervisory audit runs, from the authority opening supervision through information requests and inspection to a targeted security audit and enforcement

What evidence will an auditor ask for?

The substance being tested is Article 21(2), which lists ten measures every essential and important entity must have, based on an all-hazards approach. The list is short enough to quote, and it is the only defensible index for an evidence pack.

Article 21(2)The measureWhat proves it
(a)Policies on risk analysis and information system securityThe approved policy, plus a current risk assessment with dates and owners
(b)Incident handlingThe procedure, and records of real incidents run through it
(c)Business continuity, backup management, disaster recovery and crisis managementPlans, plus evidence of a restoration test rather than a plan alone
(d)Supply chain security, including relationships with direct suppliersSupplier assessments, and Article 21(3) requires you to weigh each supplier's own secure development practices
(e)Security in acquisition, development and maintenance, including vulnerability handling and disclosureYour secure development standard and vulnerability records
(f)Policies and procedures to assess the effectiveness of the measuresAssessment output, not the policy that promises assessment
(g)Basic cyber hygiene practices and cybersecurity trainingAttendance and completion records by role
(h)Policies and procedures on cryptography and, where appropriate, encryptionThe standard, plus evidence of where it is applied
(i)Human resources security, access control policies and asset managementAccess reviews with dates, and an asset inventory that reconciles
(j)Multi-factor authentication or continuous authentication, secured communications and secured emergency communications, where appropriateConfiguration evidence and the coverage gaps you accepted

Two duties sit outside that list and get missed. Article 20(1) makes the management body approve the risk-management measures and oversee their implementation, and allows them to be held liable for infringements. Article 20(2) requires members of the management body to follow training. Board approval minutes and board training records are therefore audit evidence, not governance housekeeping. Article 23 adds the reporting clocks: an early warning within 24 hours, an incident notification within 72 hours, an intermediate report on request, and a final report no later than one month after the notification. Our NIS2 compliance checklist lays those out as rows you can assign.

Who pays for a NIS2 audit?

You do, in the case that costs the most. Article 32(2) and Article 33(2) both provide that the costs of a targeted security audit carried out by an independent body are paid by the audited entity, except in duly substantiated cases where the competent authority decides otherwise. Both articles also require that the results of any targeted security audit are made available to the competent authority, and that the audit is based on risk assessments conducted by the authority or by the audited entity, or on other risk-related available information.

That combination is worth planning around. You may be required to commission an audit, pay for it, and have its findings sent to your regulator, on the basis of a risk assessment you did not write. The practical consequence is that the quality of your own evidence is the only variable you control.

What happens if the audit finds gaps?

A fine is the end of the sequence, not the opening move. Article 32(4) gives authorities a graduated set of enforcement powers over essential entities: warnings, binding instructions including deadlines, orders to cease infringing conduct, orders to bring the Article 21 measures or the Article 23 reporting into compliance, orders to inform affected customers of a significant cyber threat, orders to implement an audit's recommendations, the designation of a monitoring officer to oversee compliance with Articles 21 and 23, orders to make aspects of the infringement public, and administrative fines on top of any of those.

Article 32(5) goes further for essential entities where the softer measures fail: temporary suspension of a certification or authorisation, and a temporary ban on a person discharging managerial responsibilities at chief executive or legal representative level from exercising managerial functions in that entity. Article 33(4) gives a similar but shorter list for important entities, and does not carry that suspension power.

Article 32(8) is the clause to remember on the day: authorities must set out detailed reasoning, notify you of their preliminary findings before adopting measures, and allow reasonable time for you to submit observations, except where immediate action is needed. Fines themselves reach EUR 10 million or 2 percent of total worldwide annual turnover for essential entities, and EUR 7 million or 1.4 percent for important entities, whichever is higher in each case. We cover the detail in NIS2 fines and penalties.

The NIS2 enforcement ladder under Article 32(4), running from a warning through binding instructions and orders to comply with Article 21 to a monitoring officer and an administrative fine

What the other results get wrong

Three errors recur across the pages ranking for this query.

The first is describing a NIS2 audit as a certification. There is no NIS2 certificate and no NIS2 auditor qualification in the Directive. Article 24 lets Member States require the use of ICT products, services and processes certified under European schemes adopted pursuant to Regulation (EU) 2019/881, which certifies technology rather than your organisation. Anyone offering to certify your entity against NIS2 is selling something the Directive does not define. Where certification does help is indirectly, and our comparison of NIS2 and ISO 27001 sets out how far an existing management system carries you.

The second is quoting a fixed notice period. Several results state that you will get a set number of weeks of written warning. The Directive contains no such period. Notice is a creature of national transposing law, and an entity operating across borders should expect the answer to differ by country.

The third is reducing the essential and important distinction to the size of the fine. The ceilings do differ, but the operationally important difference is the trigger. An important entity that never attracts evidence of non-compliance may never see a targeted audit. An essential entity can be audited on a schedule, which changes how continuously you need your evidence to be current.

A NIS2 audit readiness view tracking Article 21 measures evidenced, supplier assessments in date, days to assemble an evidence pack and outstanding board training records

Could you pass one next month?

Fill this in for your own entity. Any row you cannot complete is the row an auditor will find first.

QuestionYour answerWhy it matters
Are you an essential or an important entity, in writing?It decides whether you can be audited without a trigger at all.
Which Member States supervise you?Procedure, notice and registration are national, even though the substance is not.
How many of the ten Article 21(2) measures can you evidence today?Evidence, not assertion. This is the body of the audit.
Can you show board approval of the measures and board training records?Article 20(1) and 20(2). Commonly missing, and directly in scope.
Could you file a 24 hour early warning tonight, without waking a manager?Article 23(4)(a). A named filer with a named fallback, or you do not have a process.
Have you budgeted for an audit you may be ordered to pay for?Article 32(2) and 33(2) put the cost of an independent audit on you.

If most rows are blank, the useful next step is a baseline rather than a project plan. A free compliance check will tell you which of the ten measures you can actually evidence, and our NIS2 compliance software keeps that evidence current between supervisory contacts instead of rebuilding it each time.

The bottom line on NIS2 audits: the audit tests the evidence you kept rather than the answers you give on the day

Frequently asked questions

How often will we be audited under NIS2?

The Directive sets no frequency. It allows regular security audits of essential entities and lets Member States prioritise supervision on a risk-based approach under Article 31(2), so the cycle is set by your national authority rather than by NIS2 itself.

Do important entities get audited at all?

Yes, but only ex post. Article 33(1) applies where the authority is provided with evidence, indication or information of alleged non-compliance. Article 33(2) then makes six supervisory powers available, including a targeted security audit.

Is there a NIS2 certification we can obtain?

No. Article 24 concerns European cybersecurity certification schemes for ICT products, services and processes under Regulation (EU) 2019/881. There is no entity level NIS2 certificate in the Directive.

Does ISO 27001 mean we pass?

It helps and it does not settle it. A certified management system produces much of the Article 21(2) evidence, but the reporting duties in Article 23 and the management body duties in Article 20 are NIS2 specific and are assessed on their own terms.

Can our directors be personally sanctioned?

Yes, in defined circumstances. Article 20(1) allows management bodies to be held liable for infringements of Article 21, and Article 32(5)(b) allows a temporary ban on a person at chief executive or legal representative level from exercising managerial functions in an essential entity where earlier enforcement measures have proved ineffective.

Primary sources

Every article reference above is taken from the consolidated text of Directive (EU) 2022/2555 on EUR-Lex, specifically Articles 20, 21, 23, 24, 31, 32, 33, 34 and 41. Because NIS2 is a directive, the procedure that applies to you is in your Member State's transposing law, which can add detail the Directive does not contain. Confirm the current national text before relying on a procedural point.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING