Skip to content

Evidence request lists

NIS2 Directive Implementing Acts

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Access and Assets

NIS2I-6
Access Control, Asset Management, and Physical Security

Implement access control per Annex I.12 including identity management + authentication (MFA) + authorisation + role-based access control + privileged access management + session recording + just-in-time access + access reviews. Apply asset management per Annex I.13 covering asset inventory + classification + ownership + handling + return + secure disposal. Implement environmental and physical security per Annex I.14 covering secure areas + perimeter controls + access controls + equipment protection + secure disposal of media.

Artefacts an auditor will ask for
  • IAM deployment
  • MFA evidence
  • PAM with session recording
  • Asset inventory + classification
  • Physical security zones
  • Access reviews
Where this commonly fails
  • No MFA
  • No PAM
  • Stale asset inventory
  • Weak physical security

Governance and Risk

NIS2I-2
Policy, Risk Management, and Roles + Responsibilities

Establish security policy per Annex I.1 covering scope + objectives + risk acceptance + monitoring + review + improvement + management commitment. Implement risk management framework per Annex I.2 including identification + analysis + evaluation + treatment + acceptance + monitoring + review. Define roles + responsibilities + authorities per Annex I.3 with Senior Management responsibility + DPO/CISO coordination + dedicated cybersecurity function + segregation of duties + competence requirements.

Artefacts an auditor will ask for
  • Approved security policy
  • Risk assessment register
  • RACI matrix
  • Senior Management approval
  • Annual policy review
Where this commonly fails
  • Outdated policy
  • Missing risk register
  • Unclear RACI
  • No annual review

Incident Response and Continuity

NIS2I-3
Incident Handling Policy, Reporting Significance Criteria, and Business Continuity

Implement incident handling policy per Annex I.4 including incident classification + escalation + handling team + post-incident review. Apply Article 2 significance criteria to determine reportable incidents: significant operational disruption + impact on essential services + material impact on availability/integrity/confidentiality + financial loss + reputational damage. Establish business continuity per Annex I.5 with BIA + RTO/RPO + crisis management procedures + plan testing + supply chain BCP coordination.

Artefacts an auditor will ask for
  • IR policy
  • Significance criteria assessment matrix
  • BIA
  • Crisis management plan
  • Annual BCP/DRP test
  • Supply chain BCP coordination
Where this commonly fails
  • No IR policy
  • Missing criteria
  • No BIA
  • No annual testing

Network and Monitoring

NIS2I-7
Network Security, Logging, Monitoring, and Vulnerability Handling

Implement network security per Annex I.15 including segmentation + perimeter defence + IDS/IPS + secure configurations + DDoS protection + zero trust network access. Apply logging and monitoring per Annex I.16 including security event logging + correlation + SIEM + 24x7 SOC + retention + integrity protection. Implement vulnerability handling and disclosure per Annex I.17 including scanning + patch management (Critical 7 days + High 30 days + Medium 90 days) + Coordinated Vulnerability Disclosure (CVD) policy + EUVD coordination.

Artefacts an auditor will ask for
  • Network architecture diagram
  • SIEM deployment
  • 24x7 SOC roster
  • Vulnerability scans + patch SLA
  • CVD policy
  • EUVD coordination
Where this commonly fails
  • Flat network
  • No SIEM
  • No 24/7 SOC
  • Patches exceed SLA

Personnel and Cryptography

NIS2I-5
Cyber Hygiene, Training, Cryptography, and Human Resources Security

Implement basic cyber hygiene and cybersecurity training per Annex I.9 including phishing simulation + password hygiene + secure device use + role-based training + management body training. Apply cryptography per Annex I.10 including cryptographic policy + key management + algorithm selection (post-quantum readiness) + use of certified solutions. Implement human resources security per Annex I.11 covering pre-employment screening + employment terms + termination procedures + insider threat detection.

Artefacts an auditor will ask for
  • Training programme + completion records
  • Phishing simulation results
  • Cryptographic policy
  • Key management evidence
  • HR screening records
  • Termination procedures
Where this commonly fails
  • No phishing simulation
  • Weak crypto policy
  • No HR screening
  • Missing termination process

Regulatory Framework

NIS2I-1
Implementing Regulation 2024/2690 Scope, Annex I Measures, and ENISA Technical Guidance

Comply with Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and further specification of significant incidents per Article 21(5) NIS2. Apply Annex I 17 categories of cybersecurity risk-management measures (policy + risk management + roles + incident handling + business continuity + supply chain + acquisition/development + effectiveness + cyber hygiene + cryptography + HR + access control + asset management + physical/environmental + network + logging + vulnerability handling). Engage ENISA technical guidance + Cooperation Group Reference Documents.

Artefacts an auditor will ask for
  • Annex I 17 measure compliance matrix
  • ENISA guidance alignment
  • Cooperation Group Reference Document compliance
  • Annual review
Where this commonly fails
  • Missing Annex I measures
  • No ENISA alignment
  • No Cooperation Group docs

Sector-Specific

NIS2I-8
Sector-Specific Requirements - Cloud Providers and Managed Service Providers (Articles 7, 10)

Apply sector-specific requirements for cloud computing service providers per Article 7 covering: virtualisation security + multi-tenancy + customer isolation + data sovereignty + sub-processor management + portability + reversibility + transparency. Apply managed service providers (MSPs) and managed security services providers (MSSPs) requirements per Article 10 including service contract specifications + customer security incident notifications + tooling validation + access logging. Apply tiered approach to DNS providers + TLD registries + IXPs + data centre providers per Article 10(2). Coordinate with EU Cybersecurity Certification Schemes (EUCS for cloud) administered by ENISA.

Artefacts an auditor will ask for
  • Cloud service compliance evidence
  • MSP contractual specifications
  • Tooling validation
  • EUCS certification (where applicable)
  • Customer incident notification process
Where this commonly fails
  • No cloud-specific controls
  • Missing MSP requirements
  • No EUCS engagement
  • Inadequate customer notification

Supply Chain and Development

NIS2I-4
Supply Chain Security, Acquisition Development, and Effectiveness Assessment

Implement supply chain security per Annex I.6 including supplier risk assessment + contractual cybersecurity clauses + monitoring + termination rights + return of data. Apply security in acquisition + development + maintenance per Annex I.7 including secure SDLC + threat modelling + secure coding + dependency scanning + change management + maintenance procedures. Conduct effectiveness assessment of cybersecurity risk management measures per Annex I.8 including testing + measurement + metrics + reporting + continuous improvement.

Artefacts an auditor will ask for
  • Supplier inventory + assessments
  • Contractual cyber clauses
  • Secure SDLC + SAST/DAST
  • Change management evidence
  • Effectiveness metrics + reports
  • Annual review
Where this commonly fails
  • No supplier assessment
  • Inadequate SDLC
  • Missing effectiveness measurement
  • No metrics
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIS2 Directive Implementing Acts framework page.