Skip to main content
Back to overview

NIS2 Supervisory Audits: The Evidence Regulators Actually Ask For

By NIS2Certify
supervisory-auditenforcementevidence-packmsp
NIS2 Supervisory Audits: The Evidence Regulators Actually Ask For

On 6 March 2026, Germany's BSI entered its active supervision phase. Since that date, it can demand evidence of your security measures without waiting for an incident. No breach, no complaint — just a letter asking you to prove your NIS2 compliance posture within a set deadline.

A NIS2 supervisory audit is no longer a theoretical risk. Audit programmes are now running in 14 member states, and the first enforcement actions have been reported in Belgium, Italy and Hungary. For IT consultants, MSPs and vCISOs, the question has changed from "is my client in scope?" to "can my client produce evidence on request?"

This post covers what regulators actually ask for, what happens when the evidence falls short, and how to build a defensible evidence pack before the letter arrives.

Enforcement has moved from registration to evidence

2025 was the year of registration deadlines. 2026 is the year of verification.

Germany's BSI can now request documentation of security measures from registered entities proactively — reports indicate dozens of formal notices have already gone out. France's ANSSI has issued remediation orders under its NIS2 framework. Belgium's CCB opened its audit window for essential entities in April 2026, tied to the CyFun conformity assessment scheme we covered in our Belgium audit deadline guide.

The pattern is consistent across member states. Essential entities face ex-ante supervision: regulators can audit at any time, without suspicion. Important entities face ex-post supervision: audits triggered by incidents, complaints or indications of non-compliance. Either way, the request arrives as a demand for documents, not a site visit.

First financial penalties have been reported in Belgium (€185,000), Italy (€450,000) and Hungary (€78,000). Whether every reported case survives appeal matters less than the direction: authorities have moved past awareness campaigns.

NIS2 Implementation Status by Country (2025–2026)

Fully in force

Belgium
Croatia
Hungary
Lithuania
Latvia
Italy
6 countries

Adopted — late 2025

Germany
Czech Republic
Finland
3 countries

In progress — expected 2026

Netherlands
France
Spain
Poland
Austria
Sweden
Ireland
7 countries

The evidence pack maps directly to Article 21

Regulators do not ask "are you secure?" They ask for proof that each of the ten Article 21(2) measures exists, is implemented, and is reviewed.

In practice, evidence requests cluster around five document types per measure.

Policies. A dated, board-approved document for each measure. A risk analysis policy without a management signature fails Article 20 — the board must approve the measures, and auditors check for that approval.

Risk assessments. The current assessment plus at least one previous version. Auditors look for iteration. A single risk assessment from November 2024 that was never updated signals a paper exercise.

Implementation evidence. Screenshots, configurations, contracts. MFA enforcement reports from your identity provider. Backup restore test logs. Supplier security clauses in current contracts — see our supplier contract guide for what those clauses must contain.

Effectiveness reviews. Article 21(2)(f) requires you to assess whether your measures work. Internal audit reports, pentest results, tabletop exercise reports with dated findings and follow-up actions. We broke down this audit loop in a separate post.

Training records. Attendance lists and dates for cyber hygiene training — including management. Article 20(2) makes board training mandatory, and it is one of the easiest gaps for an auditor to find.

One concrete example: in Belgium's CyFun-based audits, entities must show evidence per control, not per theme. "We have backups" is not an answer. A dated restore test report from the last quarter is.

Article 21 — 10 NIS2 Cybersecurity Measures

Article 21

10 Cybersecurity Measures

Governance & Strategy

1Risk analysis & information security policies
6Effectiveness assessment of security measures

Incident & Continuity

2Incident handling & notification
3Business continuity & disaster recovery

Supply Chain & Systems

4Supply chain security
5Security in network & information systems development

Technical Controls

8Cryptography & encryption
10Multi-factor authentication & secure communications

People & Assets

7Cyber hygiene & training
9HR security & access control

National regulators ask the same question in different formats

The directive is European; the paperwork is national. Three examples show the spread.

Germany expects structured proof of measures. The BSI's supervision model builds on the established KRITIS practice of formal evidence submissions, and registered entities should expect requests referencing specific measure categories — see our Germany enforcement guide for the timeline.

Belgium runs the most formalised scheme in the EU. CyFun assessments work control-by-control, with assurance levels tied to entity classification. Evidence is graded, not just collected.

Italy's ACN phases obligations by category and deadline, which means the evidence expected from a client depends on when their category's clock started — we mapped those dates in our Italy categorization post.

For consultants serving clients in several member states, the practical answer is to build the evidence pack once, against Article 21, then format it per national scheme on request. The underlying artefacts — signed policies, test reports, training records — are the same everywhere.

What happens when your evidence falls short

A failed evidence request rarely jumps straight to a fine. It starts a sequence — and each step raises the cost.

First comes a binding instruction or remediation order with a deadline, typically one to three months. Miss it, and the authority can order a security audit at your expense, performed by a qualified external party. Still non-compliant, and fines enter the picture: up to €10 million or 2% of global turnover for essential entities, €7 million or 1.4% for important entities.

For essential entities, two sanctions bite harder than any fine. Authorities can suspend certifications or authorisations needed to operate. And they can temporarily ban individual managers from exercising management functions until compliance is restored. We covered why these penalties hurt more than fines — a CEO ban is not a line item you can budget for.

There is a supply chain effect too. An entity under a remediation order becomes a documented supply chain risk for every customer that must assess supplier security under Article 21(2)(d). Lose your evidence pack, and you can lose contracts before any regulator collects a cent.

NIS2 Penalty Escalation — Beyond the Fine

!

Trigger event

Non-Compliance Detected or Incident Occurs

A supervisory authority identifies a compliance gap or an organisation fails to meet NIS2 requirements

Authorities can impose
Non-Monetary Penalties
1

Compliance orders with binding deadlines

2

Mandatory security audits at your expense

3

Public disclosure of violations

4

Binding instructions on specific security measures

Escalates to
Operational & Personal Consequences
1

Suspension of certifications or operating licences

2

Temporary ban on management functions for individuals

3

Public naming of responsible natural persons

Trigger
Non-monetary
Operational / personal

How MSPs and consultants should prepare clients now

You cannot build eighteen months of evidence in the three weeks after a letter arrives. But you can make a client audit-ready in one quarter if you work in the right order.

Weeks 1–2: inventory what exists. Collect every policy, assessment and report the client has. Map each document to an Article 21(2) measure. The gaps you find are your work list — run a structured gap analysis if the client has never done one.

Weeks 3–8: close the documentation gaps. Get undated policies approved and signed by management. Schedule the missing activities that generate evidence: a restore test, a tabletop exercise, a management training session. Each one produces a dated artefact.

Weeks 9–12: build the pack itself. One folder structure, one index, one owner. Per measure: policy, latest assessment, implementation evidence, latest effectiveness review. If the regulator's letter arrives on a Tuesday, the response should be an export, not a project.

For MSPs there is a commercial angle here. Audit-readiness is a recurring service — evidence goes stale, reviews recur, training repeats annually. The MSPs winning NIS2 business in 2026 are not selling firewalls. They are selling the evidence pack and the process that keeps it current.

Not sure where a client stands today? Run a free NIS2 quick scan — it takes minutes and shows which Article 21 measures need evidence first.

The audit letter is a deadline you can beat

Supervisory audits reward preparation and punish improvisation. The regulators' playbook is public: Article 21 lists the measures, Article 20 assigns accountability, and national authorities have shown what evidence they expect.

Treat the evidence pack as the deliverable. A client with signed policies, dated test reports and current training records has little to fear from a BSI notice or a CCB audit window. A client with good intentions and no paperwork is one letter away from a remediation order.

The letter is coming eventually. What it finds is up to you.

Still have a question?

Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.

    NIS2 Supervisory Audits: The Evidence Regulators Actually Ask For — NIS2Certify