Audnexa module · NIS2

NIS2 audit tool — gap analysis and report

Audnexa supports your NIS2 compliance audit (Directive (EU) 2022/2555): gap analysis of the technical and organisational risk-management measures and a board-ready report — offline, with human sign-off. Deadlines and thresholds follow each country’s transposition.

NIS2 audit tool

NIS2 scope and what an audit checks

Who NIS2 applies to

NIS2 (Directive (EU) 2022/2555) replaced the original NIS directive and significantly widened its scope. Member States were to transpose it into national law by 17 October 2024; exact thresholds and registration deadlines follow each country’s implementing act.

  • Essential and important entities in the sectors listed in the directive
  • As a rule, medium and large enterprises meeting the size thresholds
  • Selected entities regardless of size

What a NIS2 audit covers

An audit verifies the technical and organisational risk-management measures, incident handling and reporting, business continuity and supply-chain security. A full preparation guide is in the knowledge base — this module focuses on a faster, repeatable report.

audnexa

How Audnexa supports a NIS2 audit

NIS2 gap analysis

Maps the risk-management measures to the directive’s requirements and produces a gap report for the board.

Documentation and ISMS

Organises policies, procedures and evidence in one controlled workspace — support for building an ISMS.

Board-ready report

An auditable report with recommendations — support in view of management’s accountability under NIS2.

Offline mode

Data and audit material stay within the entity’s infrastructure — no outbound traffic to the cloud.

faq

Frequently asked questions — NIS2 audit

When does NIS2 apply?
Directive (EU) 2022/2555 had to be transposed into national law by 17 October 2024. Obligations, registration deadlines and size thresholds follow each Member State’s implementing legislation, so the exact dates depend on your country.
Who is subject to NIS2?
Essential and important entities in the sectors named in the directive that meet the size thresholds (as a rule medium and large enterprises), plus selected entities regardless of size.
What is the incident-reporting timeline?
In stages: an early warning (as a rule within 24 hours), an incident notification (72 hours) and a final report (usually within one month). National rules set the details.
Is management personally accountable under NIS2?
NIS2 makes management bodies responsible for approving and overseeing the risk-management measures. National transpositions provide for supervision and sanctions.
Does Audnexa replace the auditor?
No. Audnexa prepares an auditable draft with references to evidence, which a person reviews and signs off.

Book a security presentation

We cover technical details, deployment modes and licence terms in a security presentation (30 min, online).

+48 12 200 27 10 Book a security presentation

Contact

Audnexa supports your NIS2 compliance audit (Directive (EU) 2022/2555): gap analysis of the technical and organisational risk-management measures and a board-ready report — offline, with human sign-off. Deadlines and thresholds follow each country’s transposition.

Virtline Sp. z o.o. · biuro@virtline.com · +48 12 200 27 10