NIS2 Supervisory Audits: The Evidence Regulators Actually Ask For

On 6 March 2026, Germany's BSI entered its active supervision phase. Since that date, it can demand evidence of your security measures without waiting for an incident. No breach, no complaint — just a letter asking you to prove your NIS2 compliance posture within a set deadline.
A NIS2 supervisory audit is no longer a theoretical risk. Audit programmes are now running in 14 member states, and the first enforcement actions have been reported in Belgium, Italy and Hungary. For IT consultants, MSPs and vCISOs, the question has changed from "is my client in scope?" to "can my client produce evidence on request?"
This post covers what regulators actually ask for, what happens when the evidence falls short, and how to build a defensible evidence pack before the letter arrives.
Enforcement has moved from registration to evidence
2025 was the year of registration deadlines. 2026 is the year of verification.
Germany's BSI can now request documentation of security measures from registered entities proactively — reports indicate dozens of formal notices have already gone out. France's ANSSI has issued remediation orders under its NIS2 framework. Belgium's CCB opened its audit window for essential entities in April 2026, tied to the CyFun conformity assessment scheme we covered in our Belgium audit deadline guide.
The pattern is consistent across member states. Essential entities face ex-ante supervision: regulators can audit at any time, without suspicion. Important entities face ex-post supervision: audits triggered by incidents, complaints or indications of non-compliance. Either way, the request arrives as a demand for documents, not a site visit.
First financial penalties have been reported in Belgium (€185,000), Italy (€450,000) and Hungary (€78,000). Whether every reported case survives appeal matters less than the direction: authorities have moved past awareness campaigns.
NIS2 Implementation Status by Country (2025–2026)
Fully in force
BelgiumCroatiaHungaryLithuaniaLatviaItaly6 countriesAdopted — late 2025
GermanyCzech RepublicFinland3 countriesIn progress — expected 2026
NetherlandsFranceSpainPolandAustriaSwedenIreland7 countries
The evidence pack maps directly to Article 21
Regulators do not ask "are you secure?" They ask for proof that each of the ten Article 21(2) measures exists, is implemented, and is reviewed.
In practice, evidence requests cluster around five document types per measure.
Policies. A dated, board-approved document for each measure. A risk analysis policy without a management signature fails Article 20 — the board must approve the measures, and auditors check for that approval.
Risk assessments. The current assessment plus at least one previous version. Auditors look for iteration. A single risk assessment from November 2024 that was never updated signals a paper exercise.
Implementation evidence. Screenshots, configurations, contracts. MFA enforcement reports from your identity provider. Backup restore test logs. Supplier security clauses in current contracts — see our supplier contract guide for what those clauses must contain.
Effectiveness reviews. Article 21(2)(f) requires you to assess whether your measures work. Internal audit reports, pentest results, tabletop exercise reports with dated findings and follow-up actions. We broke down this audit loop in a separate post.
Training records. Attendance lists and dates for cyber hygiene training — including management. Article 20(2) makes board training mandatory, and it is one of the easiest gaps for an auditor to find.
One concrete example: in Belgium's CyFun-based audits, entities must show evidence per control, not per theme. "We have backups" is not an answer. A dated restore test report from the last quarter is.
Article 21 — 10 NIS2 Cybersecurity Measures
Article 21
10 Cybersecurity Measures
Governance & Strategy
1Risk analysis & information security policies6Effectiveness assessment of security measuresIncident & Continuity
2Incident handling & notification3Business continuity & disaster recoverySupply Chain & Systems
4Supply chain security5Security in network & information systems developmentTechnical Controls
8Cryptography & encryption10Multi-factor authentication & secure communicationsPeople & Assets
7Cyber hygiene & training9HR security & access control
National regulators ask the same question in different formats
The directive is European; the paperwork is national. Three examples show the spread.
Germany expects structured proof of measures. The BSI's supervision model builds on the established KRITIS practice of formal evidence submissions, and registered entities should expect requests referencing specific measure categories — see our Germany enforcement guide for the timeline.
Belgium runs the most formalised scheme in the EU. CyFun assessments work control-by-control, with assurance levels tied to entity classification. Evidence is graded, not just collected.
Italy's ACN phases obligations by category and deadline, which means the evidence expected from a client depends on when their category's clock started — we mapped those dates in our Italy categorization post.
For consultants serving clients in several member states, the practical answer is to build the evidence pack once, against Article 21, then format it per national scheme on request. The underlying artefacts — signed policies, test reports, training records — are the same everywhere.
What happens when your evidence falls short
A failed evidence request rarely jumps straight to a fine. It starts a sequence — and each step raises the cost.
First comes a binding instruction or remediation order with a deadline, typically one to three months. Miss it, and the authority can order a security audit at your expense, performed by a qualified external party. Still non-compliant, and fines enter the picture: up to €10 million or 2% of global turnover for essential entities, €7 million or 1.4% for important entities.
For essential entities, two sanctions bite harder than any fine. Authorities can suspend certifications or authorisations needed to operate. And they can temporarily ban individual managers from exercising management functions until compliance is restored. We covered why these penalties hurt more than fines — a CEO ban is not a line item you can budget for.
There is a supply chain effect too. An entity under a remediation order becomes a documented supply chain risk for every customer that must assess supplier security under Article 21(2)(d). Lose your evidence pack, and you can lose contracts before any regulator collects a cent.
NIS2 Penalty Escalation — Beyond the Fine
!Trigger event
Non-Compliance Detected or Incident Occurs
A supervisory authority identifies a compliance gap or an organisation fails to meet NIS2 requirements
Authorities can impose▼Non-Monetary Penalties1Compliance orders with binding deadlines
2Mandatory security audits at your expense
3Public disclosure of violations
4Binding instructions on specific security measures
Escalates to▼Operational & Personal Consequences1Suspension of certifications or operating licences
2Temporary ban on management functions for individuals
3Public naming of responsible natural persons
TriggerNon-monetaryOperational / personal
How MSPs and consultants should prepare clients now
You cannot build eighteen months of evidence in the three weeks after a letter arrives. But you can make a client audit-ready in one quarter if you work in the right order.
Weeks 1–2: inventory what exists. Collect every policy, assessment and report the client has. Map each document to an Article 21(2) measure. The gaps you find are your work list — run a structured gap analysis if the client has never done one.
Weeks 3–8: close the documentation gaps. Get undated policies approved and signed by management. Schedule the missing activities that generate evidence: a restore test, a tabletop exercise, a management training session. Each one produces a dated artefact.
Weeks 9–12: build the pack itself. One folder structure, one index, one owner. Per measure: policy, latest assessment, implementation evidence, latest effectiveness review. If the regulator's letter arrives on a Tuesday, the response should be an export, not a project.
For MSPs there is a commercial angle here. Audit-readiness is a recurring service — evidence goes stale, reviews recur, training repeats annually. The MSPs winning NIS2 business in 2026 are not selling firewalls. They are selling the evidence pack and the process that keeps it current.
Not sure where a client stands today? Run a free NIS2 quick scan — it takes minutes and shows which Article 21 measures need evidence first.
The audit letter is a deadline you can beat
Supervisory audits reward preparation and punish improvisation. The regulators' playbook is public: Article 21 lists the measures, Article 20 assigns accountability, and national authorities have shown what evidence they expect.
Treat the evidence pack as the deliverable. A client with signed policies, dated test reports and current training records has little to fear from a BSI notice or a CCB audit window. A client with good intentions and no paperwork is one letter away from a remediation order.
The letter is coming eventually. What it finds is up to you.
Still have a question?
Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.
