NIS2 Gap Audit
Structured mapping of your organisation against NIS2 requirements with a roadmap.
NIS2-01Duration: Indicative 10 business days, depending on scope and accessAssurance
Outcome
A traceable gap matrix per control domain plus a prioritised remediation roadmap, structured for audit review.
Who it is for
Essential/important entities under NIS2 in AT/DE/EU expecting supervisory review.
Deliverables
- Scope/classification (essential vs. important)
- Control matrix across NIS2 requirements
- Evidence check per control point (docs, processes, records)
- Gap assessment with risk weighting
- Remediation roadmap (90 days, indicative)
- 45-min management debrief
In scope
- 1 organisational entity
- Document review + interviews up to 6 stakeholders
Out of scope
- Technical penetration tests
- Binding legal interpretation of supervisory practice (orientation only)
Prerequisites
- Access to ISMS/process documentation
- Named owner
Acceptance
- Acceptance via gap matrix plus prioritised roadmap with an evidence anchor per control point.
Human approvals
- Management confirms classifications
- Owner reviews gap matrix before release
Frequently asked questions
Is this legal advice?
No. It is operational readiness support. Binding legal interpretation requires qualified legal counsel.
Does the result guarantee NIS2 conformity or a successful audit?
No. The gap matrix shows gaps and priorities; conformity and audit outcome cannot be promised.
And after?
Recommended: ISO 27001 readiness or the hardening retainer; the evidence structure stays reusable.