What NIS2 Auditors Actually Check: Your Preparation Guide for Articles 32 and 33
Your organisation has been notified of a NIS2 supervisory inspection — or perhaps it hasn’t been yet. Either way, the question is the same: what will the authority actually look for, and how do you prepare?
The NIS2 Directive (EU) 2022/2555 established a graduated supervision framework that came into full force following member-state transpositions in October 2024. [1] National competent authorities now hold significant investigative and enforcement powers under Articles 32 and 33. Organisations that understand these powers in advance — and build their evidence base accordingly — face inspections very differently from those that begin preparing only after receiving a notice.
This guide explains the two supervision regimes, the six inspection tools authorities may deploy, and the exact documentation your organisation should have ready before any inspection begins.
Which Supervision Regime Applies to You?
NIS2 divides regulated organisations into two categories, and each faces a different supervision model.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Essential entities — operators of critical infrastructure in energy, transport, banking, health, and digital infrastructure — fall under Article 32. The defining characteristic is that Article 32 supervision is proactive. Authorities may initiate on-site inspections, random checks, and regular security audits at any time, without waiting for an incident or complaint. [2]
Important entities — a broader group in manufacturing, postal services, food, chemicals, and other sectors — fall under Article 33. Article 33 establishes an ex post regime: supervision is triggered by a specific event such as a significant incident, a missed notification deadline, a whistleblower complaint, or evidence of repeated non-compliance across the sector. [3]
| Essential Entities (Art. 32) | Important Entities (Art. 33) | |
|---|---|---|
| Supervision trigger | Proactive — any time | Reactive — event-driven |
| Random checks | Yes — explicitly permitted | Not as standard |
| Regular audits | Scheduled by authority | Only following trigger events |
| Escalated enforcement | Can suspend certifications, prohibit executives (Art. 32(5)) | Art. 32(5) does not apply |
Confirming your classification before preparing is not bureaucratic formality. If your organisation operates in an essential sector but has prepared only for reactive supervision, you may be significantly underprepared for proactive random checks. For guidance on whether your organisation qualifies as essential or important, see our NIS2 scope guide.
Six Supervisory Tools Authorities Can Deploy
Most guidance on NIS2 audits treats “inspection” as a single event. In practice, Articles 32(2) and 33(2) give competent authorities six distinct supervisory tools, each generating different documentation demands. [1, 2, 3]
- On-site inspections — Physical visits by trained authority staff to review systems, observe processes, and interview key personnel. Random unannounced checks are explicitly permitted for essential entities.
- Off-site supervision — Document and evidence reviews conducted without site visits. Frequently used as a precursor to determine whether an on-site inspection is warranted.
- Regular security audits — Structured audits commissioned by the authority or a designated independent auditor, covering compliance with the Article 21 security measures. Audit recommendations are binding under Article 32(4)(e).
- Targeted and ad hoc security audits — Narrower audits triggered by a significant incident or evidence of a material violation. Scope focuses on the incident root cause and remediation steps taken.
- Security scans — Automated technical assessments of exposed systems and known vulnerabilities, conducted using objective, non-discriminatory criteria. No prior notice is required.
- Information and evidence requests — Formal written requests for documentation: cybersecurity policies, risk management records, audit results, and underlying evidence of implementation. This is the most common first contact and the one every organisation can prepare for immediately.
Knowing which tool an authority is using tells you exactly what to have ready. An on-site inspection requires personnel who know their roles; an information request requires organised, accessible documentation; a security scan tests your external attack surface, not your paperwork.
What Auditors Actually Request: The Evidence Checklist
Whether supervision is proactive or reactive, the evidence base that satisfies a NIS2 supervisory review is largely the same. Authorities verify compliance with Article 21 (the ten security measures) and Article 23 (incident notification). [1] The critical distinction auditors draw is between documentation that describes controls and evidence that those controls are followed over time. A policy document alone does not demonstrate compliance. [4]
Governance and Leadership
- Board or senior management approval records for cybersecurity policies — Article 21(1) requires management to approve and oversee risk management measures
- Written accountability assignments identifying who owns each security domain
- Meeting minutes referencing cybersecurity oversight decisions
Risk Management
- A living risk register updated to reflect current threats — not a static annual document
- Threat models and risk treatment plans with decision records and residual risk acceptance
- Evidence of periodic review: version history, update timestamps, meeting records
See our NIS2 risk assessment guide for the documentation structure authorities expect.
Incident Response
- Documented procedures covering detection, assessment, escalation, and the 24-hour early warning and 72-hour formal notification deadlines
- Historical incident logs showing actual events handled — even minor events demonstrate an active monitoring capability
- Tabletop exercise records: the written minutes documenting what was tested and what gaps were identified are the regulatory evidence, not the exercise itself [5]
See our NIS2 incident reporting guide for full notification timeline requirements.
Technical Controls
- Access control policies with MFA implementation records for privileged accounts
- Patch management logs demonstrating timely vulnerability remediation
- Encryption policies with records confirming application to critical data systems
Supply Chain
- Supplier security assessments for third parties with access to your systems or data
- Contracts with explicit cybersecurity obligations and evidence of ongoing monitoring
Suppliers that access your network or handle critical data are treated as extensions of your security perimeter under NIS2. Auditors look for evidence that security obligations are contractually embedded — not just internally aspired to.
Training Records
- Attendance records for cybersecurity training with dates confirming regularity
- Training content descriptions and evaluation results
| Evidence Category | Primary Owner | Backup |
|---|---|---|
| Governance records | Legal / Compliance | CISO |
| Risk register | CISO | Risk Manager |
| Incident logs | SOC / IT Security | CISO |
| Supplier contracts | Procurement | Legal |
| Training records | HR | Compliance |
| Technical controls proof | IT / DevOps | CISO |
Your 5-Step Preparation Plan
Audit readiness is not a project with an end date, but these five steps create a defensible baseline before any supervisory contact occurs.
Step 1 — Confirm your entity classification. Before preparing any documentation, verify whether your organisation is essential or important under Article 3 of the directive. Misclassification in either direction carries risk: essential entities that prepare only for ex post supervision are exposed to proactive random checks; important entities that invest in proactive-regime compliance structures divert resources unnecessarily. Confirm sector membership, size thresholds, and registration status with your national competent authority. (Effort: Low)
Step 2 — Run a gap analysis against the evidence checklist above. Identify what exists, what is outdated or inaccessible, and what is genuinely missing. Prioritise by exposure: missing incident notification procedures and an absent or static risk register represent the highest penalty risk under Article 21. Our NIS2 compliance checklist provides a structured reference across all ten Article 21 measures. (Effort: Medium)
Step 3 — Organise existing documentation for rapid retrieval. Most organisations have more compliance documentation than they realise, but it is scattered across systems and individuals. Create a single indexed evidence repository so any information request can be answered within the authority’s specified deadline. Focus on accessibility, not volume. (Effort: Low)
Step 4 — Conduct and formally document tabletop exercises. Run at least one incident response simulation per year. Document the scenario tested, participants, gaps identified, and remediation actions agreed. The written minutes produce regulatory evidence that your incident response capability is actively tested and improving — not just described in a policy document. [5] (Effort: Medium)
Step 5 — Assign a preparation lead and define presentation roles. When an authority contacts your organisation, someone must own the response: correspondence management, documentation production, and spokesperson coordination. Define these roles before any inspection begins. For essential entities facing proactive supervision, this should be a permanent assignment, not activated only in response to contact. (Effort: Low)
If you need ready-to-use policy documents and evidence templates mapped to the Article 21 requirements, explore our NIS2 documentation templates.
Key Takeaways
NIS2 supervisory activity is accelerating as national authorities across the EU operationalise their enforcement powers. In 2025 and 2026, organisations in Annex I and Annex II sectors should expect authority contact — whether through information requests, security scans, or formal inspection notices.
Essential entities face proactive scrutiny that may begin at any time. Important entities face reactive investigation triggered by incidents or non-compliance signals — but when triggered, the evidence requirements are identical.
Under Article 34, infringements of Articles 21 or 23 carry administrative fines of up to €10 million or 2% of global annual turnover for essential entities, and up to €7 million or 1.4% for important entities. [1, 6] Member-state authorities may additionally impose personal liability on senior management where gross negligence is established.
Start with your entity classification. Run the gap analysis. Build your evidence repository before the authority contacts you — not after.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources
- Directive (EU) 2022/2555 (NIS2 Directive) — EUR-Lex. eur-lex.europa.eu
- NIS2 Directive, Article 32 — Supervisory and enforcement measures for essential entities. nis-2-directive.com
- NIS2 Directive, Article 33 — Supervisory and enforcement measures for important entities. nis-2-directive.com
- NIS2 Documentation: What Auditors Expect to See — House of Control. houseofcontrol.com
- Prepare for a NIS2 Audit Step by Step — Privalex. privalex.es
- NIS2 Directive, Article 34 — General conditions for imposing administrative fines. nis-2-directive.com
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
