NIS2 audit — who is covered, what the obligations are, and how to prepare
What NIS2 is and who it covers
NIS2 (EU Directive 2022/2555, transposed nationally) broadens the scope of entities subject to cybersecurity requirements and tightens obligations and management accountability. It applies to "essential" and "important" entities across sectors such as energy, transport, banking, digital infrastructure, health and others.
Penalties for non-compliance can reach up to €10M or 2% of annual turnover, depending on the entity category.
Key obligations
- implementing cybersecurity risk-management measures,
- incident reporting within defined deadlines,
- accountability and oversight by management bodies,
- supply-chain and ICT vendor risk management,
- business continuity and crisis management.
Deadlines, penalties and dates (hard facts)
Key concrete NIS2 requirements (Art. 23 and penalty provisions):
- Incident reporting: early warning within 24 hours, incident notification within 72 hours, final report within 1 month.
- Penalties — essential entities: up to €10M or 2% of total worldwide annual turnover (whichever is higher).
- Penalties — important entities: up to €7M or 1.4% of total worldwide annual turnover.
- Dates: NIS2 entered into force on 16 Jan 2023; the transposition deadline was 17 Oct 2024.
How to prepare for a NIS2 audit
- determine whether you are an essential or important entity,
- gather policies, procedures and evidence for the required areas,
- run a gap analysis against the requirements,
- document incident handling and reporting timelines,
- prepare a gap report with recommendations for the board.
Criteria for choosing a NIS2 audit tool
- data control (offline / on-premise),
- a repeatable methodology and a full audit trail,
- a review-ready draft gap report,
- human-in-the-loop approval of findings,
- maturity — proven in real audits.
How Audnexa supports NIS2 audits
Audnexa supports preparing auditable report and gap-analysis drafts for NIS2 — with references to evidence and a full audit trail. In offline mode, data stays in your infrastructure and a human approves every report.
It is a mature tool, battle-tested across hundreds of real audits in Virtline’s practice (ISO/IEC 27001). It does not replace an auditor’s or lawyer’s opinion.
Frequently asked questions
NIS2 vs ISO 27001 — what is the difference?
ISO/IEC 27001 is a voluntary, certifiable information-security management standard. NIS2 is a mandatory EU directive. An ISO 27001 ISMS makes meeting many NIS2 requirements much easier, but they are not the same.
What are the penalties for NIS2 non-compliance?
Up to €10M or 2% of annual turnover for essential entities (lower thresholds for important ones), plus management-body accountability.
Can a NIS2 audit be done without moving data out?
Yes. Tools like Audnexa run in offline/on-premise mode — audit material stays within the organization’s infrastructure.
Which tool should you choose for a NIS2 audit?
Assess: data control (offline/on-premise), a repeatable methodology with a full audit trail, a review-ready draft gap report, human approval of findings, and maturity proven in real audits. Audnexa meets these criteria — with offline mode (Bank Mode), ISO/IEC 27001 and years of audit practice at Virtline.
Sources
This content is informational and does not constitute a legal opinion, an auditor’s opinion or a formal compliance decision.