· Kai Roer

What evidence does a NIS2 auditor actually want to see?

A NIS2 policy is only the container. Article 21(2)(f) auditors want what is inside it: evidence your controls work. Here is what strong effectiveness evidence looks like.

What evidence does a NIS2 auditor actually want to see?

NIS2 Article 21(2)(f) requires organisations to maintain “policies and procedures to assess the effectiveness of cybersecurity risk-management measures.” Most organisations read that sentence and hear “we need a policy.” They draft one. It says something about annual effectiveness assessments. It gets approved, filed, and forgotten.

That misreads the obligation. A policy is the container. An auditor wants what is inside it.

What the auditor is actually looking for

An auditor working under a NIS2 framework is not looking for a document that says the word “effectiveness.” They are looking for documented evidence that the effectiveness assessment process exists, runs on a defined schedule, produces output, and feeds back into decisions. Those are four separate things, and all four need to be demonstrable.

The distinction is between a policy and a process. A policy is a statement of intent — “we will assess effectiveness quarterly.” A process is the machinery that makes the policy real — the schedule, the data, the analysis, the findings, the decisions made as a result. The policy is the promise. The process is the proof.

An auditor who finds a well-written policy and no evidence that the assessment described in that policy was ever conducted has found a compliance gap. The policy makes the gap worse, not better, because it documents an obligation the organisation imposed on itself and then failed to meet.

What constitutes weak evidence

Three patterns appear repeatedly in organisations that believe they are compliant but would struggle under audit.

The first is a policy that describes an annual assessment cycle with no record that the assessment ever ran. This is the most common gap. The policy exists. The calendar entry may even exist. But there is no output — no report, no data, no findings document, no record of what was assessed and what was concluded.

The second is training completion reports presented as effectiveness evidence. A training completion report documents that an activity occurred — that a certain number of employees completed a certain module by a certain date. It says nothing about what those employees learned, whether their behaviour changed, or whether the organisation is now more secure. Training completion is process evidence, not effectiveness evidence. The two are not interchangeable.

The third is a point-in-time audit report from eighteen months ago. An audit captures a snapshot. It tells you what was true when the auditor looked. It cannot tell you what has been true in the months since. It cannot tell you whether controls that were in place at audit time are still functioning. And it cannot demonstrate that the measures assessed in the audit had a measurable effect — only that they existed at the time.

What constitutes strong evidence

Three patterns indicate an organisation with a live effectiveness assessment process.

The first is before-and-after data tied to a specific intervention. A training was conducted, a policy was changed, a technical configuration was updated — and there is documented data showing what the relevant indicators looked like before the intervention and what they looked like after. This is the core of effectiveness evidence. It connects an action to a measurable outcome.

The second is a documented record that the assessment process ran on the dates it was supposed to run. Not that a policy says it runs quarterly, but that there is a dated output — a report, a dataset, a findings summary — for Q1, Q2, Q3, and Q4. The cadence is as important as the content. Regulators are looking for evidence of regularity, not just evidence of existence.

The third is evidence that findings from the assessment fed back into decisions. A control was assessed, a gap was identified, and something changed as a result — a revised policy, an updated configuration, a board-level discussion documented in minutes. This is where the loop closes. Assessment without follow-through is observation. Assessment that drives decision-making is governance.

The proportionality trap

Article 21(1) of NIS2 establishes a proportionality standard. Measures must be “appropriate and proportionate” to the risks. This creates an additional audit exposure that most organisations have not considered.

An auditor operating under the proportionality standard can ask not just “do you assess effectiveness?” but “can you demonstrate that the measures you have in place are proportionate to your risk profile?” That is a comparative claim. It requires you to show what your risk looks like, what measures you have deployed against that risk, and what evidence you have that those measures are producing an effect commensurate with the risk. You cannot answer that question without measurement data. A policy alone does not get you there.

What auditors are not looking for

An auditor is not looking for perfection. They are not expecting every control to show a positive trend. They are not expecting zero incidents or flawless compliance.

What they are looking for is evidence that a process exists, that it runs, that it produces output, and that the output is used. The gap most organisations have is not in their controls. It is in the paper trail that shows those controls were assessed, the assessment produced findings, and the findings informed decisions.

That paper trail is the difference between an organisation that has controls and an organisation that can demonstrate those controls are working. Under NIS2, only the second position is compliant.

For the full regulatory argument and enforcement precedents, read the white paper: Measuring Security Control Effectiveness: From Attestation to Evidence

Ready to see your employees' security behaviors?

Connect your Microsoft 365 and see months of behavioral data in 15 minutes. Free 30-day trial — no credit card, no sales call.

Start Free Trial