NIS2 Gap Audit

Structured mapping of your organisation against NIS2 requirements with a roadmap.

NIS2-01Duration: Indicative 10 business days, depending on scope and accessAssurance

Outcome

A traceable gap matrix per control domain plus a prioritised remediation roadmap, structured for audit review.

Who it is for

Essential/important entities under NIS2 in AT/DE/EU expecting supervisory review.

Deliverables

  • Scope/classification (essential vs. important)
  • Control matrix across NIS2 requirements
  • Evidence check per control point (docs, processes, records)
  • Gap assessment with risk weighting
  • Remediation roadmap (90 days, indicative)
  • 45-min management debrief

In scope

  • 1 organisational entity
  • Document review + interviews up to 6 stakeholders

Out of scope

  • Technical penetration tests
  • Binding legal interpretation of supervisory practice (orientation only)

Prerequisites

  • Access to ISMS/process documentation
  • Named owner

Acceptance

  • Acceptance via gap matrix plus prioritised roadmap with an evidence anchor per control point.

Human approvals

  • Management confirms classifications
  • Owner reviews gap matrix before release

Frequently asked questions

Is this legal advice?

No. It is operational readiness support. Binding legal interpretation requires qualified legal counsel.

Does the result guarantee NIS2 conformity or a successful audit?

No. The gap matrix shows gaps and priorities; conformity and audit outcome cannot be promised.

And after?

Recommended: ISO 27001 readiness or the hardening retainer; the evidence structure stays reusable.