NIS2 Directive Implementing Acts
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Access and Assets
Implement access control per Annex I.12 including identity management + authentication (MFA) + authorisation + role-based access control + privileged access management + session recording + just-in-time access + access reviews. Apply asset management per Annex I.13 covering asset inventory + classification + ownership + handling + return + secure disposal. Implement environmental and physical security per Annex I.14 covering secure areas + perimeter controls + access controls + equipment protection + secure disposal of media.
- IAM deployment
- MFA evidence
- PAM with session recording
- Asset inventory + classification
- Physical security zones
- Access reviews
- No MFA
- No PAM
- Stale asset inventory
- Weak physical security
Governance and Risk
Establish security policy per Annex I.1 covering scope + objectives + risk acceptance + monitoring + review + improvement + management commitment. Implement risk management framework per Annex I.2 including identification + analysis + evaluation + treatment + acceptance + monitoring + review. Define roles + responsibilities + authorities per Annex I.3 with Senior Management responsibility + DPO/CISO coordination + dedicated cybersecurity function + segregation of duties + competence requirements.
- Approved security policy
- Risk assessment register
- RACI matrix
- Senior Management approval
- Annual policy review
- Outdated policy
- Missing risk register
- Unclear RACI
- No annual review
Incident Response and Continuity
Implement incident handling policy per Annex I.4 including incident classification + escalation + handling team + post-incident review. Apply Article 2 significance criteria to determine reportable incidents: significant operational disruption + impact on essential services + material impact on availability/integrity/confidentiality + financial loss + reputational damage. Establish business continuity per Annex I.5 with BIA + RTO/RPO + crisis management procedures + plan testing + supply chain BCP coordination.
- IR policy
- Significance criteria assessment matrix
- BIA
- Crisis management plan
- Annual BCP/DRP test
- Supply chain BCP coordination
- No IR policy
- Missing criteria
- No BIA
- No annual testing
Network and Monitoring
Implement network security per Annex I.15 including segmentation + perimeter defence + IDS/IPS + secure configurations + DDoS protection + zero trust network access. Apply logging and monitoring per Annex I.16 including security event logging + correlation + SIEM + 24x7 SOC + retention + integrity protection. Implement vulnerability handling and disclosure per Annex I.17 including scanning + patch management (Critical 7 days + High 30 days + Medium 90 days) + Coordinated Vulnerability Disclosure (CVD) policy + EUVD coordination.
- Network architecture diagram
- SIEM deployment
- 24x7 SOC roster
- Vulnerability scans + patch SLA
- CVD policy
- EUVD coordination
- Flat network
- No SIEM
- No 24/7 SOC
- Patches exceed SLA
Personnel and Cryptography
Implement basic cyber hygiene and cybersecurity training per Annex I.9 including phishing simulation + password hygiene + secure device use + role-based training + management body training. Apply cryptography per Annex I.10 including cryptographic policy + key management + algorithm selection (post-quantum readiness) + use of certified solutions. Implement human resources security per Annex I.11 covering pre-employment screening + employment terms + termination procedures + insider threat detection.
- Training programme + completion records
- Phishing simulation results
- Cryptographic policy
- Key management evidence
- HR screening records
- Termination procedures
- No phishing simulation
- Weak crypto policy
- No HR screening
- Missing termination process
Regulatory Framework
Comply with Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and further specification of significant incidents per Article 21(5) NIS2. Apply Annex I 17 categories of cybersecurity risk-management measures (policy + risk management + roles + incident handling + business continuity + supply chain + acquisition/development + effectiveness + cyber hygiene + cryptography + HR + access control + asset management + physical/environmental + network + logging + vulnerability handling). Engage ENISA technical guidance + Cooperation Group Reference Documents.
- Annex I 17 measure compliance matrix
- ENISA guidance alignment
- Cooperation Group Reference Document compliance
- Annual review
- Missing Annex I measures
- No ENISA alignment
- No Cooperation Group docs
Sector-Specific
Apply sector-specific requirements for cloud computing service providers per Article 7 covering: virtualisation security + multi-tenancy + customer isolation + data sovereignty + sub-processor management + portability + reversibility + transparency. Apply managed service providers (MSPs) and managed security services providers (MSSPs) requirements per Article 10 including service contract specifications + customer security incident notifications + tooling validation + access logging. Apply tiered approach to DNS providers + TLD registries + IXPs + data centre providers per Article 10(2). Coordinate with EU Cybersecurity Certification Schemes (EUCS for cloud) administered by ENISA.
- Cloud service compliance evidence
- MSP contractual specifications
- Tooling validation
- EUCS certification (where applicable)
- Customer incident notification process
- No cloud-specific controls
- Missing MSP requirements
- No EUCS engagement
- Inadequate customer notification
Supply Chain and Development
Implement supply chain security per Annex I.6 including supplier risk assessment + contractual cybersecurity clauses + monitoring + termination rights + return of data. Apply security in acquisition + development + maintenance per Annex I.7 including secure SDLC + threat modelling + secure coding + dependency scanning + change management + maintenance procedures. Conduct effectiveness assessment of cybersecurity risk management measures per Annex I.8 including testing + measurement + metrics + reporting + continuous improvement.
- Supplier inventory + assessments
- Contractual cyber clauses
- Secure SDLC + SAST/DAST
- Change management evidence
- Effectiveness metrics + reports
- Annual review
- No supplier assessment
- Inadequate SDLC
- Missing effectiveness measurement
- No metrics
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIS2 Directive Implementing Acts framework page.