Abstract representation of audit evidence being examined, a single illuminated data node against a dark network background

Objective Evidence in a NIS2 or ISO 27001 Audit: The 5 Tests Your Screenshot Has to Pass

Ask three auditors what “objective evidence” means and you get the same six-word definition and three different verdicts on the same screenshot. The definition is settled. What decides whether your artefact survives is the test that follows it, and ISO 19011:2018 publishes that test in Annex A.5, four criteria long. Almost nobody quotes it.

Three Audits, Three Standards of Proof

Before asking what good evidence looks like, ask who is entitled to demand it. Three different audits use the phrase, and they run on different authority.

Audit Who runs it What they may demand Governing text
ISO 27001 internal audit Your own staff or a contracted auditor Whatever falls inside the audit programme and criteria you defined yourself ISO/IEC 27001:2022, clause 9.2
ISO 27001 certification audit An accredited certification body Evidence sufficient for a certification decision; findings graded as major or minor nonconformity ISO/IEC 17021-1
NIS2 supervision, essential entity Competent authority or an independent body On-site inspections, random checks, regular and targeted security audits, ad hoc audits, security scans, requests for information and documents, and requests for evidence of implementation NIS2 Article 32(2)(a)-(g)
NIS2 supervision, important entity Competent authority Targeted security audits but not “regular” ones; no random checks, no ad hoc audits, and no standalone power to demand evidence of implementation. Ex post only NIS2 Article 33(1)-(2)

The asymmetry in the last two rows is the one most compliance teams miss. Article 32(2)(g) gives supervisors of essential entities the power to make “requests for evidence of implementation of cybersecurity policies, such as the results of security audits carried out by a qualified auditor”. Article 33 contains no equivalent. Important entities are not evidence-free, because Article 33(2)(d) and (e) still permit requests for information and access to “data, documents and information” — but those are exercised, in the Directive’s words, only when an authority is “provided with evidence, indication or information that an important entity allegedly does not comply”. For an essential entity, evidence production is a schedule. For an important entity, it is a trigger. The full Article 32 versus Article 33 split decides how much of your evidence should stand ready and how much can be assembled on request.

One under-used protection sits in Article 32(3): when an authority exercises the powers in points (e), (f) or (g), it must “state the purpose of the request and specify the information requested”. A request that does neither is not an open door to your document management system.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

The Definition, and Why It Is Not in ISO 27001

The phrase you are judged against does not appear in the standard you are audited to. Search the full text of ISO/IEC 27001:2022 for “objective evidence” and you find it nowhere. The standard’s word is “documented information”.

“Objective evidence” is vocabulary from the ISO 9000 family, and it reaches your ISMS audit through ISO 19011:2018, the auditing guideline management-system auditors actually work to. ISO 19011 term 3.8 defines it as “data supporting the existence or verity of something”, and notes that for audit purposes it “generally consists of records, statements of fact, or other information which are relevant to the audit criteria and verifiable”. Term 3.9 strips it down further: audit evidence is “records, statements of fact or other information, which are relevant to the audit criteria and verifiable”.

Both definitions turn on one word. Verifiable. Clause 6.4.7 makes it operative: “Only information that can be subject to some degree of verification should be accepted as audit evidence. Where the degree of verification is low the auditor should use their professional judgement to determine the degree of reliance that can be placed on it as evidence.”

The wording gap matters because of what each document does and does not give you. ISO 27001 tells you to hold documented information (clause 7.5.1) and to keep it “available as evidence” of monitoring results (9.1) and of the audit programme and its results (9.2.2). It never says what makes a piece of it good enough. ISO 19011 does, and the auditor sitting opposite you is working from ISO 19011, not from your copy of 27001.

The Five Tests Your Evidence Has to Pass

Four of these are ISO 19011:2018 Annex A.5, the short clause on verifying information that compliance blogs almost never quote. The fifth, verifiability, comes from the definition itself and gates the other four: fail it and there is nothing left to test. The grouping below is ours; the criteria are the standard’s.

Test What ISO 19011 says What fails it What passes
1. Verifiable Only information “subject to some degree of verification” is audit evidence (6.4.7) A summary spreadsheet typed by hand from systems nobody can re-query An export from the source system, with the report or query name recorded alongside it
2. Complete “all expected content is contained in the documented information” (A.5 a) A privileged access review covering three of eleven admin accounts, with no statement that it did The review carrying its own scope statement and the account population it was drawn from
3. Correct “the content conforms to other reliable sources such as standards and regulations” (A.5 b) A retention schedule citing a statutory period the cited law does not set Every claim traceable to the clause, article or standard it names
4. Consistent “consistent in itself and with related documents” (A.5 c) An asset register listing 340 devices next to a patch report covering 290, with nothing reconciling them The two artefacts agreeing, or the gap explained inside one of them
5. Current “the content is up to date” (A.5 d) A policy last approved before the reorganisation it describes; an undated export A dated review, a named owner, and a next-review date that has not passed

Test 5 is the one undated artefacts fail, and it costs twice. ISO/IEC 27001:2022 clause 7.5.2(a) requires appropriate “identification and description (e.g. a title, date, author, or reference number)” whenever documented information is created or updated. An undated screenshot therefore fails the currency test on the control it was meant to evidence, and separately breaches 7.5.2(a) in its own right. One careless artefact, two findings.

Annex A.5 raises a sixth consideration without numbering it: “If information is provided in a manner other than expected (e.g. by different individuals, alternate media), the integrity of the evidence should be assessed.” Producing the same log three different ways, from three different people, invites the auditor to start testing your chain of custody instead of your control. Pick one authoritative route to each artefact and use it every time. An internal audit checklist earns more if it is built around those routes than around the control list alone.

What Does Not Count, and the Exception Everyone Gets Wrong

Five artefacts get handed to auditors constantly and fail on arrival.

  • An attestation. “All staff complete security training at onboarding” is a statement about a control, not data supporting its existence. The completion log is the evidence; the sentence is the claim the evidence has to support.
  • A policy with no operating record. A signed policy evidences that a rule exists. It says nothing about whether anyone followed it, and the completeness and currency tests apply to what the management system produced, not to what it promised.
  • A certificate treated as proof of a control. A supplier’s ISO 27001 certificate evidences that a certification body reached a decision about a scope you have probably not read. Ask for the scope statement and the Statement of Applicability, or you are citing someone else’s audit conclusion as your own evidence.
  • A vendor’s product claim. Marketing copy is not “relevant to the audit criteria and verifiable” in any sense ISO 19011 recognises.
  • An undated export. Fails currency and clause 7.5.2(a) at the same time.

Now the exception, which cuts the other way. Objective evidence does not have to be a document at all. The joint ISO and IAF Auditing Practices Group states it plainly: “objective evidence does not necessarily depend on the existence of documented information, except where specifically mentioned”. ISO 19011 clause 6.4.7 lists three collection methods — “interviews; observations; review of documented information” — and Annex A.14 adds observed activities, performance indicators, databases and modelling to the legitimate sources.

Two calibrations before you lean on that. First, the Auditing Practices Group paper is written for ISO 9001 certification-body auditors and carries its own notice that it “has not been subject to an endorsement process” by ISO, ISO/TC 176 or the IAF. It shows how auditors reason; it does not amend ISO 27001. Second, where ISO 27001 does specifically require documented information — 9.1 and 9.2.2 both say it “shall be available as evidence” — an interview is no substitute. The exception buys room on controls the standard leaves to your judgement, not on clauses that name the record.

On the NIS2 side, ENISA’s Technical Implementation Guidance publishes examples of evidence beneath each requirement of Commission Implementing Regulation (EU) 2024/2690. Those examples are guidance: indicative, not a closed list you are marked against. Which of them actually bind you is a separate question from whether the artefact you hand over survives the five tests.

Sampling Changes What “Having Evidence” Means

The most expensive misunderstanding about audit evidence is this: the auditor is not checking your artefact, they are checking your population through your artefact.

ISO 19011’s evidence-based approach principle says audit evidence “should in general be based on samples of the information available, since an audit is conducted during a finite period of time and with finite resources”, and that “an appropriate use of sampling should be applied, since this is closely related to the confidence that can be placed in the audit conclusions”. Annex A.6.1 defines sampling as “selecting less than 100 % of the items within the total available data set (population)… in order to form a conclusion concerning the population”.

The mechanism that follows is unforgiving. One immaculate exhibit drawn from forty inconsistent records does not pass, because it fails the consistency test and, worse, lowers the confidence the auditor can place in every other conclusion drawn from that population. The unit of compliance is the population, not the exhibit. “We found a good example” is the wrong preparation; “every instance looks the same” is the right one.

Role What sampling changes for you
CISO or IT security manager Make each artefact a system output rather than a hand-assembled file. A generated report is uniform across the population by construction; a curated one is uniform only where someone curated it.
Compliance officer Know the population size and the refresh cadence behind every requirement before the audit, not the location of one good example. That number is what an auditor’s sample is drawn from.
SME owner or board member Fund the review cadence, not the document. A policy is a one-off cost; the dated evidence that it is reviewed and followed is a recurring one, and it is the recurring half that gets sampled.

Tracking evidence at population level rather than artefact level is exactly what a compliance monitoring dashboard is for: it answers “how many, how fresh, who owns it” without anyone opening a folder.

What Happens When Evidence Fails

A rejected artefact is not automatically a nonconformity, and you have procedural rights when it becomes one.

ISO 19011 clause 6.4.8 requires that “nonconformities and their supporting audit evidence should be recorded”, and that findings “should be reviewed with the auditee in order to obtain acknowledgement that the audit evidence is accurate and that the nonconformities are understood”. Disagreement is anticipated by the guideline itself: “every attempt should be made to resolve any diverging opinions concerning the audit evidence or findings. Unresolved issues should be recorded in the audit report.” Asking to see the evidence behind a finding is part of the process, not obstruction of it.

In certification audits, classification comes second. European Accreditation’s guidance to certification bodies stresses that “firstly the finding shall be nonconformity and then needed to be classified” — the body has to demonstrate actual non-fulfilment of a requirement before grading it — and cites the ISO/IEC 17021-1 definition of a major nonconformity as one “that affects the capability of the management system to achieve the intended results”.

The reverse holds too, and it is worth knowing. The ISO and IAF guidance tells auditors that “if the auditor is not capable of finding evidence of conformity it should not necessarily be taken to infer that the auditee does not comply with the audit criteria”. That is not a hiding place, because the same paper is equally direct that “it is the organization’s responsibility to provide objective evidence of conformity”. What it does mean is that your burden is production, not persuasion.

Where to Start

Most failed evidence is repairable faster than the control it describes. Before rebuilding anything, work out which of the two you actually have.

  1. Run the identification sweep first. Pull every artefact you would hand over tomorrow and check it for a title, a date, an author and a reference number. That is clause 7.5.2(a), it is the cheapest test to pass, and it removes an entire class of finding in an afternoon.
  2. Name the population behind each artefact. For every requirement, write down what the total set is and how often it refreshes. If you cannot state the denominator, you cannot predict what a sample will show.
  3. Fix one route per artefact. Decide which system, report or export is the authoritative source for each piece of evidence, and stop producing it any other way.

Frequently Asked Questions

Is a screenshot ever acceptable as objective evidence?
Yes, on the same terms as anything else. It has to be verifiable, meaning traceable back to a system someone could re-query, and it has to carry identification: which system, which scope or account, and when. A screenshot fails not because it is a screenshot but because it usually arrives with none of that attached.

Does NIS2 define “objective evidence”?
No. The term does not appear in the Directive. Article 32(2)(g) refers to “evidence of implementation of cybersecurity policies, such as the results of security audits carried out by a qualified auditor”, and the detailed evidence examples sit in ENISA guidance rather than in the binding text of the Directive or of Commission Implementing Regulation (EU) 2024/2690.

How long do we have to keep evidence?
Neither instrument sets a period for you. ISO/IEC 27001:2022 clause 7.5.3 requires you to address “retention and disposition” as part of controlling documented information, which means you set the period and then have to live by it. A retention rule you wrote and then breached is worse evidence than having written no rule at all.

Can one artefact satisfy both a NIS2 supervisor and an ISO 27001 auditor?
Often, because the quality tests are the same. The criteria are not. An audit finding is “the result of the evaluation of the collected audit evidence against audit criteria” (ISO 19011, term 3.10), so the same access log answers an Annex A control and an Article 21(2) measure only if you have mapped which requirement it is answering. Left undeclared, it answers neither cleanly.

Sources

  • Guidance on: Evidence collection — ISO 9001 Auditing Practices Group (ISO and IAF, 13 January 2016). Source of the ISO 9000 definition quoted here, the burden-of-production statement, and the note that objective evidence does not necessarily depend on documented information. The paper states that it has not been through an ISO, ISO/TC 176 or IAF endorsement process.
  • Article 32, Directive (EU) 2022/2555 (NIS2) — supervisory measures for essential entities, including 32(2)(g) and 32(3).
  • Article 33, Directive (EU) 2022/2555 (NIS2) — supervisory measures for important entities, including the ex post trigger in 33(1) and the powers listed in 33(2).
  • Technical Implementation Guidance on cybersecurity risk-management measures — ENISA, June 2025. Source of the examples of evidence mapped to Commission Implementing Regulation (EU) 2024/2690. Non-binding guidance.
  • Question 39.1 — Findings classification, nonconformities — European Accreditation. Source of the ISO/IEC 17021-1 major nonconformity definition and the finding-before-classification principle.
  • ISO 19011:2018, Guidelines for auditing management systems — terms 3.8, 3.9 and 3.10, the evidence-based approach principle in Clause 4, clauses 6.4.7 and 6.4.8, and Annexes A.5, A.6 and A.14. Available from ISO; not linked here because iso.org blocks automated access.
  • ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements — clauses 7.5.1, 7.5.2, 7.5.3, 9.1 and 9.2.2. Available from ISO; not linked here because iso.org blocks automated access.

Verification note: all quoted clause and term text was checked against the text of the standards and the Directive articles themselves rather than against secondary commentary. The observation that “objective evidence” does not appear in ISO/IEC 27001:2022 is a full-text search of the published standard, which returns no occurrences.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: