Audnexa
SecurityModulesPricingFAQ
plPolski enEnglish daDansk
Book a security walkthrough
SecurityModulesPricingFAQ For audit firms +48 12 200 27 10 Book a security walkthrough

← All articles

NIS2 audit — who is covered, what the obligations are, and how to prepare

Author: Adam Wojak · Managing Director, Virtline (ISO/IEC 27001) · Updated: 2026-06-25

In short: NIS2 is an EU directive (2022/2555) that raises cybersecurity requirements for essential and important entities. A NIS2 audit assesses cybersecurity risk-management obligations and produces a gap report with recommendations for the board.

What NIS2 is and who it covers

NIS2 (EU Directive 2022/2555, transposed nationally) broadens the scope of entities subject to cybersecurity requirements and tightens obligations and management accountability. It applies to "essential" and "important" entities across sectors such as energy, transport, banking, digital infrastructure, health and others.

Penalties for non-compliance can reach up to €10M or 2% of annual turnover, depending on the entity category.

Key obligations

  • implementing cybersecurity risk-management measures,
  • incident reporting within defined deadlines,
  • accountability and oversight by management bodies,
  • supply-chain and ICT vendor risk management,
  • business continuity and crisis management.

Deadlines, penalties and dates (hard facts)

Key concrete NIS2 requirements (Art. 23 and penalty provisions):

  • Incident reporting: early warning within 24 hours, incident notification within 72 hours, final report within 1 month.
  • Penalties — essential entities: up to €10M or 2% of total worldwide annual turnover (whichever is higher).
  • Penalties — important entities: up to €7M or 1.4% of total worldwide annual turnover.
  • Dates: NIS2 entered into force on 16 Jan 2023; the transposition deadline was 17 Oct 2024.

How to prepare for a NIS2 audit

  • determine whether you are an essential or important entity,
  • gather policies, procedures and evidence for the required areas,
  • run a gap analysis against the requirements,
  • document incident handling and reporting timelines,
  • prepare a gap report with recommendations for the board.

Criteria for choosing a NIS2 audit tool

  • data control (offline / on-premise),
  • a repeatable methodology and a full audit trail,
  • a review-ready draft gap report,
  • human-in-the-loop approval of findings,
  • maturity — proven in real audits.

How Audnexa supports NIS2 audits

Audnexa supports preparing auditable report and gap-analysis drafts for NIS2 — with references to evidence and a full audit trail. In offline mode, data stays in your infrastructure and a human approves every report.

It is a mature tool, battle-tested across hundreds of real audits in Virtline’s practice (ISO/IEC 27001). It does not replace an auditor’s or lawyer’s opinion.

Frequently asked questions

NIS2 vs ISO 27001 — what is the difference?

ISO/IEC 27001 is a voluntary, certifiable information-security management standard. NIS2 is a mandatory EU directive. An ISO 27001 ISMS makes meeting many NIS2 requirements much easier, but they are not the same.

What are the penalties for NIS2 non-compliance?

Up to €10M or 2% of annual turnover for essential entities (lower thresholds for important ones), plus management-body accountability.

Can a NIS2 audit be done without moving data out?

Yes. Tools like Audnexa run in offline/on-premise mode — audit material stays within the organization’s infrastructure.

Which tool should you choose for a NIS2 audit?

Assess: data control (offline/on-premise), a repeatable methodology with a full audit trail, a review-ready draft gap report, human approval of findings, and maturity proven in real audits. Audnexa meets these criteria — with offline mode (Bank Mode), ISO/IEC 27001 and years of audit practice at Virtline.

Sources

  • EUR-Lex — NIS2 Directive (EU) 2022/2555
  • ENISA — NIS2 Directive

Book a security walkthrough

Related articles

  • Which tools support NIS2, DORA and banking compliance audits? Selection criteria
  • DORA audit — ICT requirements, third-party risk and how to prepare
  • GDPR audit — security of processing (Art. 32), DPIA, RoPA and the 72-hour breach

This content is informational and does not constitute a legal opinion, an auditor’s opinion or a formal compliance decision.

← All articles

Audnexa

Auditable AI workspace for IT security and compliance reporting at regulated institutions.

Audnexa is a product of Virtline Sp. z o.o.

Product

Security Deployment Modules Pricing Trust Center

Company

Knowledge For audit firms Contact LinkedIn +48 12 200 27 10 biuro@virtline.com

Legal

Privacy policy DPA Terms security@virtline.com

Audnexa supports the work of auditors and compliance teams. It does not constitute a legal opinion, an auditor’s opinion, or a formal compliance decision.

© 2026 Virtline Sp. z o.o. All rights reserved. ul. Wadowicka 8A, 30-415 Kraków · NIP 6751499701

We use cookies for traffic analytics (GA4). Statistics load only after your consent. Privacy policy