Abstract illustration representing NIS2 audit preparation and evidence review

The 90-Day NIS2 Audit Preparation Plan: Evidence, Gaps, and Interview Readiness

Under Directive (EU) 2022/2555, an NIS2 supervisory contact can start six different ways: a written information request, an off-site document review, an unannounced on-site inspection, an automated security scan, a targeted audit after an incident, or a full ad hoc audit ordered following a compliance failure elsewhere in your sector [1][4][5]. Only one of those six gives you advance notice. The other five expect the evidence to already exist — indexed, dated, and in the hands of the right person — before the request lands.

Most guides at this point walk through what auditors check, line by line. That’s useful once you know a review is coming. It’s less useful if you’re standing 90 days out with a compliance program that’s real but not yet organised around what a supervisory review actually demands. This is the build plan: a phased sequence for the 90 days before contact, a way to decide which gaps to close first, the format differences that separate evidence an auditor accepts from evidence an auditor rejects, and — the part most preparation guides skip — how to get the people in the room, not just the paperwork, ready for the interview powers built into Articles 32(2) and 33(2) [4][5]. Every timeline and format recommendation here traces to the Directive’s own text or ENISA’s June 2025 technical implementation guidance, not generic audit-prep boilerplate [1][7].

The 90-Day Window Starts Before the Letter Arrives

If your organisation is an essential entity — the operators of critical infrastructure across energy, transport, banking, health, and digital infrastructure — the 90-day clock should already be running on a rolling basis, whether or not you’ve had any contact. Article 32 supervision for essential entities is proactive by design: competent authorities may conduct on-site inspections, random off-site checks, and security scans at any time, without waiting for an incident, a complaint, or a tip-off [4]. Important entities work under Article 33’s ex post model instead — supervision triggers on a specific event, typically a significant incident, a missed notification deadline, or evidence of non-compliance surfacing elsewhere [5]. That difference changes when you start, not what you need to have ready: once either regime activates, the supervisory tools and evidence expectations converge. See our guide to what NIS2 auditors actually check for the full tool-by-tool and domain-by-domain breakdown — this guide picks up from there with the build plan.

Ninety days is roughly what it takes a program with real but disorganised measures to move from “we have policies” to “we have policies with dated approvals, tested procedures, and a named owner for every domain in Article 21(2)” without turning remediation into a burnout sprint. Shorter timelines compress the parts that genuinely can’t compress: closing a missing control and rehearsing at least one documented interview. Longer timelines tend to drift.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Your 90 Days in Four Phases

Break the quarter into four phases, each producing one deliverable that unblocks the next.

Phase Days Deliverable Effort
1. Classify and scan 1–14 Confirmed entity classification + honest first-pass gap scan against Article 21(2) Low
2. Remediate by priority 15–55 Highest-exposure gaps closed or actively in progress High
3. Assemble and format evidence 56–80 Indexed repository, named owners, sub-hour retrieval for priority domains Medium
4. Rehearse and hand off 81–90 Documented tabletop exercise plus an interview rehearsal for management and key staff Medium

Phase 1 is deliberately light. Confirm classification against Article 3 — use our NIS2 scope guide or run the scope test if you haven’t formally registered — then run a first-pass scan against the ten Article 21(2) measures using the domain list in our compliance checklist. Don’t fix anything yet. The point of Phase 1 is an honest inventory, not a rushed patch — and the accuracy of everything in Phases 2 through 4 depends on Phase 1 being truthful rather than optimistic.

Prioritising Gaps: A Risk × Effort Framework

Not every gap deserves the same urgency, and treating them as equally important is how remediation stalls in week three. The Directive doesn’t prescribe a sequencing method — this is a practical way to order work under Article 21’s ten measures, using the same risk-times-effort logic gap-analysis programs apply across compliance frameworks generally.

Score exposure by asking two questions. First: does the gap sit in an area the Directive itself treats as central — the risk-management measures in Article 21(2), or the incident notification timelines in Article 23? Gaps there score High exposure by default, independent of remediation effort. Second: would closing it demonstrate the cooperation, mitigation, and prior-compliance factors that Article 32(7) says authorities weigh when setting enforcement severity [4]? A gap you’re actively fixing before contact reads very differently from one nobody noticed.

Gap example Exposure Effort Action
No documented 24h/72h incident notification procedure High Low Fix now
Risk register exists but hasn’t been updated in 12+ months High Low Fix now
No MFA on privileged accounts High High Schedule, with a documented interim compensating control
Supplier contracts lack explicit cybersecurity clauses Medium–High High Schedule
Training records incomplete for recent hires Low Low Quick win
Centralised logging / SIEM build-out Medium High Schedule across two quarters

The “Schedule” quadrant is the one teams get wrong — they leave it silent instead of documenting it. A high-effort gap you can’t close in 90 days should still produce two artefacts inside the window: a written risk acceptance naming who accepted it and why, and an interim compensating control. That pairing is what our Article 21 complete guide covers domain-by-domain; this framework assumes you already know which measure a gap sits in and helps decide what to fix first.

Evidence Format: What Makes Documentation “Audit-Ready” Instead of Just “On File”

A risk register that exists is not the same as a risk register an auditor will accept. The gap between the two is format, and it’s where compliance programs with genuinely good substance still stumble in a supervisory review.

ENISA’s June 2025 Technical Implementation Guidance — a 170-page companion to Commission Implementing Regulation (EU) 2024/2690 — makes the same point across all 13 thematic areas it covers: each maps to concrete evidence examples and recognised frameworks (ISO/IEC 27001, NIST CSF 2.0, CEN/TS 18026) rather than a single prescribed template [7]. Format matters more than any specific document type. Four things separate evidence that survives a review from a folder that merely exists:

Format failure Why it fails a review Fix
Undated document Can’t prove currency or an actual review cadence Add a version and approval date to every document
Single “current” file, no history Can’t prove review happened repeatedly over time, only that it happened once Retain prior versions with a change log
Evidence stored across four tools and three people’s inboxes Can’t meet the deadline stated in an information request One indexed repository, one accountable owner
Generic policy text with no control mapping Auditor can’t verify it addresses the specific Article 21(2) measure Map each policy section to the exact sub-point it satisfies

The first row matters because Article 20(1) requires the management body to approve the Article 21 measures and oversee their implementation [2] — a policy without an approval date can’t demonstrate that oversight happened, only that a document exists. The third row matters because Article 32(3) and 33(3) require authorities to state the purpose of an information request and specify exactly what they’re requesting [4][5]; those requests typically arrive with a practical response deadline, and if it takes three days to locate the current MFA rollout log, the format has already failed even though the control itself is sound.

Who Owns What: Building the Evidence Repository

Assign ownership by evidence domain, not by department chart, and set a retrieval target for each.

Evidence domain Primary owner Backup Retrieval target
Governance approvals (Art. 20) Legal / Compliance CISO Under 4 hours
Risk register (Art. 21(2)(a)) CISO Risk Manager Under 4 hours
Incident logs & notification records (Art. 23) SOC / IT Security CISO Under 4 hours
Business continuity / test records Operations CISO Same business day
Supplier contracts & assessments Procurement Legal Same business day
Training records HR Compliance Same business day
Technical control evidence (MFA, patching, encryption) IT / DevOps CISO Under 4 hours

If you’re a smaller organisation without a dedicated CISO or compliance function, this table collapses to two or three people wearing multiple hats — that’s fine. What matters isn’t the org chart, it’s that every domain has exactly one accountable person and the retrieval target is real. A distributed “everyone owns their own piece” model adds hours or days spent finding the right person before anyone starts finding the document. Our guide written for internal auditors covers how to structure this repository if you’re building the program from the audit function outward rather than from IT or legal.

Preparing People, Not Just Paperwork: What Auditors Ask in Interviews

On-site inspections under Article 32(2) and 33(2) explicitly authorise trained authority staff to interview key personnel, not just review documents [4][5]. Most preparation stops at the paperwork and treats the interview as an afterthought — hand someone a folder and hope they can talk about it. That’s backwards. An auditor who gets a confident, accurate answer from staff about a control with thin paperwork will generally read that more favourably than a beautifully formatted policy nobody in the room can explain.

Different roles face genuinely different questions. Based on the interview provisions in Articles 32(2) and 33(2), and the documented experience of organisations that have already been through a review, here’s roughly how that splits — treat it as a rehearsal guide, not a guaranteed script:

Role Likely questions What “ready” looks like
Board / management body Did you approve the Article 21 measures? How do you oversee implementation? What training have you completed? [2] Points to the specific approval record and describes the oversight cadence — not just “yes, we approved it”
CISO / IT Security lead Walk me through your last incident. How is the risk register maintained? Show me the MFA rollout. Narrates a real example end-to-end, not policy language read aloud
Compliance / Legal When was your last notification deadline, and did you meet it? Where’s your evidence repository? Retrieves the specific document within the target time from the table above
General staff (spot-checked) Do you know how to report a suspected incident? Have you had cybersecurity training this year? Describes the reporting process in plain language, without needing technical detail

Run at least one rehearsal in Phase 4 where someone plays the auditor and asks these questions cold — not from a script the interviewee wrote themselves. It’s the same logic as an incident-response tabletop, applied to people instead of systems: the value is in the written record of what was tested and what gaps it exposed, not the exercise itself.

If Gaps Remain: Enforcement Escalation and Personal Liability Exposure

If a review surfaces gaps you haven’t closed, the response is graduated, not automatic. Authorities can issue a warning, adopt binding instructions, order specific compliance steps, or require you to notify affected customers first — administrative fines, and for essential entities a suspension of certifications or a temporary prohibition on named managers exercising their function, sit at the end of that ladder, used when earlier measures haven’t worked [4]. The same enforcement mechanics apply to important entities under Article 33(5), which extends Article 32’s paragraphs 6 through 8 mutatis mutandis [5]. Under Article 34, the ceiling is €10 million or 2% of total worldwide group turnover for essential entities, and €7 million or 1.4% for important entities — whichever figure is higher, calculated against the parent undertaking’s global revenue rather than the standalone entity’s [6]. Our full penalties breakdown covers how Member States apply these ceilings in practice.

Management liability isn’t automatic the moment a gap is discovered. Article 20(1) makes the management body responsible for approving and overseeing the Article 21 measures, and allows liability specifically for infringements of that Article — the liability is tied to an oversight failure, not to the mere existence of a gap a diligent board hadn’t yet identified [2]. That’s precisely why the interview evidence in the previous section matters as much as the paperwork: a board that can describe its own oversight process is answering the liability question directly, not just the compliance one.

Key Takeaways

Audit preparation that holds up starts with timing, not paperwork. Essential entities run this 90-day plan on a standing basis because Article 32 supervision doesn’t wait for a trigger; important entities can compress the same plan into the weeks after an incident, because Article 33’s evidence bar is identical once supervision activates [4][5]. The plan itself doesn’t change — only when you run it.

If you do one thing this week, run Phase 1. Confirm your classification, scan the ten Article 21(2) measures against what genuinely exists today, and write down — honestly — where the biggest gaps sit. The risk × effort sequencing, the evidence repository, and the interview rehearsal later in this plan all depend on that first inventory being accurate rather than optimistic. Browse our full set of NIS2 documentation templates if you need ready-built starting points for Phase 2 and 3.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. Directive (EU) 2022/2555 (NIS2 Directive) — EUR-Lex. eur-lex.europa.eu
  2. NIS2 Directive, Article 20 — Governance. nis-2-directive.com
  3. NIS2 Directive, Article 21 — Cybersecurity risk-management measures. nis-2-directive.com
  4. NIS2 Directive, Article 32 — Supervisory and enforcement measures for essential entities. nis-2-directive.com
  5. NIS2 Directive, Article 33 — Supervisory and enforcement measures for important entities. nis-2-directive.com
  6. NIS2 Directive, Article 34 — General conditions for imposing administrative fines. nis-2-directive.com
  7. NIS2 Technical Implementation Guidance — ENISA. enisa.europa.eu
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: