What is NIS2 audit?
A NIS2 audit is a review of whether an organisation meets the cybersecurity requirements of the NIS2 Directive. It can be an internal gap assessment, an independent security audit, or a supervisory audit ordered by the national competent authority. There is no single official NIS2 certificate; the audit checks compliance with the national law that transposes NIS2.
Under NIS2, essential entities are subject to proactive supervision, including regular and targeted security audits carried out by an independent body or the competent authority. Important entities are supervised ex post, typically after an incident or evidence of non-compliance.
A NIS2 audit usually covers:
- Scope: whether the organisation is an essential or important entity.
- Governance: management approval, oversight and training.
- Risk management measures required by Article 21.
- Incident detection, handling and reporting processes.
- Supply chain and third-party ICT risk.
- Evidence: policies, logs, access records and documented decisions.
Auditors look for proof, not intentions. Keeping security tasks, owners, deadlines and change history in one traceable system, such as Easy8, makes it faster to show auditors what was done, by whom and when.
Related content
What is NIS2 and DORA?
NIS2 and DORA are two EU regulations that raise cybersecurity and digital resilience requirements. NIS2 (Directive (EU) 2022/2555) sets cybersecurity obligations for essential and important entities across 18 critical sectors. DORA (Regulation (EU) 2022/2554, the Digital Operational Resilience Act) applies specifically to the financial sector and has been in force since 17 January 2025.
What is NIS2 and DORA?
NIS2 and DORA are two EU regulations that raise cybersecurity and digital resilience requirements. NIS2 (Directive (EU) 2022/2555) sets cybersecurity obligations for essential and important entities across 18 critical sectors. DORA (Regulation (EU) 2022/2554, the Digital Operational Resilience Act) applies specifically to the financial sector and has been in force since 17 January 2025.
