NIS2 Audit: Preparation Guide & Checklist
A NIS2 audit verifies that your security measures actually meet the requirements. Whether you face a mandatory external assessment or choose a voluntary one, preparation is key.
What Is a NIS2 Audit?
A NIS2 audit is an external verification by a Conformity Assessment Body (CAB) that your organization's security measures meet the requirements of the NIS2 directive. In Belgium, this means demonstrating compliance with the CyberFundamentals framework developed by the Centre for Cybersecurity Belgium (CCB).
- CAB auditors are accredited by BELAC (Belgian Accreditation Body)
- The audit covers your policies, procedures, technical controls, and evidence of implementation
- It is not a one-time event: ongoing compliance is expected
- The audit confirms you are "audit-ready," not that you are 100% risk-free
Learn more about the NIS2 framework: NIS2 overview.
When Do You Need an Audit?
Essential Entities
Independent verification is required: through an authorised CAB, ISO/IEC 27001, or a conformity assessment by the CCB Inspection Service. If you will not reach Essential-equivalence by 18 April 2027, the Inspection Service requests a remediation plan (CCB Inspection Service letter ref. NCCA/JK/INS/2026-002, 11 August 2026). Two cases need no plan: you are Essential-equivalent by that date, or your own risk analysis under Art. 7 of the NIS2 Royal Decree justifies a lower assurance level and you demonstrate by that date that you meet it (on the CyFun route, through a CAB verification).
Important Entities
No mandatory assessment. They must implement the NIS2 measures, and the CCB can ask for evidence, for example after an incident. A voluntary CyFun assessment is a yearly self-assessment verified by a CAB, at Important level or higher (Royal Decree, Art. 11).
Supply Chain Pressure
Even if you are not legally required to be audited, your clients may demand proof. Large enterprises increasingly require NIS2 compliance evidence from their suppliers. An audit certificate makes this simple.
Not sure which category you fall into? Check who must comply.
What to Have Ready for Each Area
The CCB CyberFundamentals workbook lists each control and its requirement; it does not prescribe the evidence. Below is the evidence we recommend having ready for each major area, with the CyFun controls it supports and the shortfalls to avoid.
Documentation & Policies
Written security policies approved at management level, with a documented review cadence. The CyFun policy controls (GV.PO-01) ask for policies that are documented, approved, reviewed and communicated. A template that has not been adapted to your organisation will not convince an assessor.
Risk Assessment
A structured risk assessment methodology with documented results. The CyFun risk assessment controls (ID.RA-05) cover this. Link each identified risk to one or more mitigating controls.
Incident Response
An incident response plan that has been tested. Keep records of tabletop exercises with named participants, simulation results and lessons learned. The CyFun controls for executing the plan (RS.MA-01) and for testing plans (ID.IM-04) cover this.
Business Continuity
Backup procedures, disaster recovery plans, and evidence of regular restore testing. The CyFun backup controls (PR.DS-11) include testing backups, so keep restore-test records, not just proof that backups exist. Recovery time objectives must be defined and realistic.
Supply Chain Security
Contracts with security clauses, supplier assessments, and a list of critical suppliers with their risk ratings. NIS2 Article 21(2)(d) lists supply chain security among the risk-management measures, and the CyFun supply chain controls (GV.SC) cover it. Rank suppliers by criticality rather than keeping a flat vendor list.
Staff Training Records
Proof that employees received security awareness training. The CyFun awareness control (PR.AT-01.1) does not prescribe the evidence. We recommend completion records per employee: dates, attendance and content covered.
Self-Assessment vs External Audit
Both have their place. The right choice depends on your NIS2 classification.
| Self-Assessment | External Audit | |
|---|---|---|
| Who performs it | Your own team | Accredited CAB auditor |
| When it counts | On its own only for essential entities under CCB inspection (Art. 23); otherwise a CAB verifies it | Essential entities on the CAB or ISO route; important entities that opt in (Art. 11) |
| Cost | Internal time only | Auditor fees (varies) |
| Credibility | Limited: self-reported | High: independently verified |
| Client confidence | Moderate | Strong: certificate as proof |
| Preparation needed | Moderate | Thorough documentation required |
How to Prepare for a NIS2 Audit
Step 1: Gap Analysis Against CyberFundamentals
Start by mapping your current security posture against the CyberFundamentals controls. Identify what you have, what is missing, and what needs improvement.
Step 2: Document Everything
Auditors need evidence. Write down your policies, procedures, and processes. Document who is responsible for what. Keep logs of security activities.
Step 3: Test Your Incident Response
Run a tabletop exercise. Simulate a security incident and walk through your response plan. Document the results and any improvements you make. CyFun asks for plans that are tested, not just written (ID.IM-04).
Step 4: Review Supply Chain Contracts
Check that your supplier contracts include security requirements. Ensure you have assessed your critical suppliers. Document the results and any follow-up actions.
Step 5: Brief Your Team
Everyone should know the basics: your security policy, how to report incidents, and their individual responsibilities. Training records prove your team is prepared.
Use our NIS2 compliance checklist to structure your gap analysis, and follow the implementation steps for a detailed plan.
Want to know whether an audit even applies to your company? Start with our free in-scope checker for an instant on-screen determination in two minutes, no email required. Want that scope decision, CyFun level and prioritized control list signed on the table as the baseline file for your auditor? The written report is €395 flat (ex VAT), delivered in 48 hours.
How MSPs Help Clients Prepare for Audits
Managed Service Providers play a crucial role in NIS2 audit preparation. Most SMEs do not have dedicated security staff. An MSP fills that gap.
Managed Compliance
MSPs handle the ongoing work: monitoring, patching, backup testing, and documentation. This keeps clients audit-ready at all times, not just before the audit.
Evidence Collection
The right tools automatically log security activities: patches applied, backups verified, incidents handled. This evidence is exactly what auditors need.
Easy Cyber Protection gives MSPs the tools to make every client audit-ready. Automated evidence collection, structured compliance tracking, and clear audit reports.
NIS2 Audit Timeline
Key dates for organizations:
See all NIS2 deadlines.
Get Audit-Ready Today
Easy Cyber Protection guides you through every step of NIS2 audit preparation. From gap analysis to evidence collection, we make compliance manageable.
Frequently Asked Questions
What is a NIS2 audit and who performs it?
A NIS2 audit is a formal assessment of your cybersecurity measures against the CyberFundamentals framework. It is performed by a Conformity Assessment Body (CAB) accredited by BELAC. The audit verifies that your policies, procedures, and technical controls meet the requirements of the NIS2 directive.
How do I check if my organization needs a NIS2 audit?
Essential entities need a regular external conformity assessment: by a CAB, through ISO/IEC 27001 certification or through a CCB inspection. Important entities have no mandatory assessment; if they choose one on CyFun, it is a self-assessment verified by a CAB at Important level or higher (Royal Decree, Art. 11). Use the CCB's online tool or check the NIS2 scope criteria to determine your classification.
What is the difference between a NIS2 self-assessment and a full audit?
A self-assessment is an internal review where your organization evaluates its own compliance with CyberFundamentals controls. A full audit involves an independent, accredited CAB auditor who verifies your compliance externally. A self-assessment on its own counts only for essential entities that chose supervision by the CCB inspection service (Royal Decree, Art. 23). An important entity's voluntary CyFun self-assessment is verified by a CAB (Art. 11).
How long does it take to prepare for a NIS2 audit?
For CyFun Basic, 1 to 9 months depending on starting position: well-equipped organisations 1-3 months, with-gaps 4-6 months, greenfield 6-9 months or more. Important contains every Basic control, so an Important audit is often a Year 2 outcome and Essential Year 3 or later; each tier needs its own audit cycle plus 2-3 months of remediation. The Royal Decree does allow an Important verification at the first step (Art. 22 §1). Essential entities cannot wait that long: they need Essential by 18 April 2027, or Important plus a plan to reach it by 18 April 2028. The key is starting early: last-minute preparation creates gaps that auditors will find.
How much does a NIS2 audit cost?
Costs vary based on organization size, complexity, and CyFun tier. Self-assessment costs are mainly internal time. External CAB audits typically range from a few thousand to tens of thousands of euros. The cost of non-compliance (fines up to 10 million euros or 2% of global turnover) far exceeds audit costs.