Résumer cet article avec :
The NIS2 auditor will not assess your actual security level. They will assess your ability to demonstrate it.
This is a fundamental distinction that many CISOs still underestimate. An organization with a solid security maturity level but scattered, incomplete, or outdated documentation risks emerging from an audit with as many non-conformities as a structurally less advanced — but better documented — organization.
In 2026, NIS2 will be fully applicable. The first formal notices will be issued. Essential and important entities that haven't structured their documentation preparation will discover this at the worst possible moment: when the auditor opens their questionnaire.
This guide tells you exactly what they're looking for — and how to be prepared.
What NIS2 truly requires in terms of documentation
The NIS2 directive is structured around ten areas of cybersecurity risk management measures (Article 21). For each, competent national authorities may request documentary evidence of implementation.
Here are the most frequently auditable areas and what the auditor specifically expects in each.
1. Information System Security Policy
What the auditor is looking for:
- A formalized IS security policy, approved by management, dated, and versioned
- Proof that it has been disseminated to all relevant personnel
- The date of the last revision (NIS2 requires regular review)
- A documented update process
The common pitfall: an existing policy that hasn't been updated since 2022, or a policy validated by the CISO but never presented to the Executive Committee. NIS2 requires management commitment — not just from the security team.
2. Risk Management
What the auditor is looking for:
- A formalized risk analysis, with documented methodology (EBIOS RM, ISO 27005, or equivalent)
- An up-to-date risk register, with criticality levels, owners, and treatment plans
- Proof that the risk analysis informs security decisions (links between risks and measures)
- A risk review schedule
The common pitfall: a risk analysis performed once for ISO 27001 certification, never updated since. The NIS2 auditor checks the recency of the approach — not just its existence.
3. Security Incident Management
What the auditor looks for:
- A documented procedure for incident detection, qualification, and notification
- Criteria for qualifying a significant incident (according to the NIS2 threshold: significant disruption of services)
- The procedure for notifying ANSSI within 24 hours (early warning) and 72 hours (initial notification)
- Evidence of incident management tests or exercises
- The log of incidents handled (even minor ones)
The common pitfall: a well-documented internal escalation procedure, but the absence of a formalized external notification procedure. NIS2 adds a regulatory notification obligation that few organizations had previously.
4. Business Continuity and Crisis Management
What the auditor looks for:
- A formalized Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP)
- Defined RTOs and RPOs for critical services
- Proof of a BCP test within the last 12 months
- A mapping of critical dependencies (cloud, suppliers, systems)
The common pitfall: a theoretical BCP that has never been tested. The auditor will systematically request the report from the last exercise. If it doesn't exist, it's a major non-conformity.
5. Supply Chain Security
What the auditor looks for:
- A documented supplier security policy
- A critical supplier security assessment process
- Security clauses in your key supplier contracts
- A list of critical suppliers with their assessment level
The common pitfall: this is the least prepared area in most organizations. Security contractual clauses are often absent or too generic. NIS2 is explicit on this point — and it's one of the first questions asked during an audit.
6. Human Resources Security
What the auditor looks for:
- A secure onboarding and offboarding procedure (documented access revocation)
- Evidence of staff training and awareness (dates, content, coverage rate)
- An authorization and access rights management policy
7. Access Control and Identity Management (IAM)
What the auditor looks for:
- A documented access management policy (principle of least privilege)
- Privileged Access Management (PAM) with logging
- Multi-factor authentication on critical systems
- A documented periodic review of access rights
8. Cryptography and Encryption
What the auditor is looking for:
- A documented cryptography policy (approved algorithms, key management)
- Proof of encryption for sensitive data in transit and at rest
- A certificate renewal process
The NIS2 documentation preparation checklist
📎 This checklist is designed for self-assessment prior to an audit. For each item, indicate: ✅ Available and up-to-date | ⚠️ Exists but needs updating | ❌ Missing
BLOCK A — Governance and Policy
- [ ] Formalized, dated, version-controlled IS security policy
- [ ] Documented approval by general management
- [ ] Proof of dissemination to personnel (email, intranet, training)
- [ ] Date of last revision (< 12 months)
- [ ] Documented review process
- [ ] Organizational chart of the security function with roles and responsibilities
- [ ] NIS2 commitment formalized in COMEX or equivalent
BLOCK B — Risk Management
- [ ] Documented risk analysis methodology
- [ ] Up-to-date risk analysis (< 12 months or following a major change)
- [ ] Risk register with owners and deadlines
- [ ] Documented critical risk treatment plans
- [ ] Traceable link between risks and security measures
- [ ] Risk review schedule
BLOCK C — Incident Management
- [ ] Incident detection and qualification procedure
- [ ] NIS2 significant incident qualification criteria
- [ ] ANSSI notification procedure (24h / 72h / final report)
- [ ] Documented and up-to-date ANSSI and CERT-FR contacts
- [ ] Incident log (minimum last 12 months)
- [ ] Report from the last incident management exercise
BLOCK D — Business Continuity
- [ ] Formalized BCP with RTO and RPO per critical service
- [ ] Formalized DRP
- [ ] Mapping of critical dependencies (cloud, suppliers, systems)
- [ ] Report from the last BCP test (< 12 months)
- [ ] Crisis communication procedure
BLOCK E — Supply Chain Security
- [ ] Documented supplier security policy
- [ ] List of critical suppliers with assessed criticality
- [ ] Security assessment process for critical suppliers
- [ ] Security clauses in key supplier contracts
- [ ] Security questionnaires sent and archived (supplier responses)
BLOCK F — Human Resources and Training
- [ ] Documented secure onboarding procedure
- [ ] Offboarding procedure with access revocation
- [ ] Training and awareness register (dates, content, attendees)
- [ ] Awareness coverage rate (NIS2 target: all personnel)
BLOCK G — Access Control (IAM)
- [ ] Documented access management policy
- [ ] Least privilege policy applied and documented
- [ ] Privileged Access Management (PAM) with logging
- [ ] MFA deployed on critical systems (proof of deployment)
- [ ] Access rights review (< 6 months)
BLOCK H — Cryptography
- [ ] Documented cryptography policy
- [ ] Certificate inventory with expiration dates
- [ ] Certificate renewal process
- [ ] Documented encryption of sensitive data in transit and at rest
What the auditor does with your documents
Understanding the NIS2 audit process allows you to precisely anticipate what will be requested.
Phase 1 — Preliminary Questionnaire. Before the on-site audit, you will receive a structured maturity questionnaire. This is your first opportunity to demonstrate the thoroughness of your preparation — and the first opportunity to reveal any documentation gaps that the auditor will then explore further.
Phase 2 — Document Review. The auditor requests to review the documents listed in your questionnaire. They verify the consistency between what you have declared and what you produce. They check update dates, approval signatures, and versions. A policy not approved by management or a never-tested BCP will be immediately flagged.
Phase 3 — Interviews. The auditor meets with the CISO, CIO, and sometimes the CEO. They ask questions about specific scenarios: "Describe the last significant incident you managed." "How did you assess the security of your main cloud provider?" The answers must be consistent with the documents produced.
Phase 4 — Technical Tests. In certain areas, the auditor may request technical demonstrations: configuration review, notification procedure testing, and MFA deployment verification.
The three most common documentation errors
Error 1: Documents that exist but no one can find. The security policy is in SharePoint, folder Security > Policies > Archives > 2024. The auditor asks to see the current version. It takes 20 minutes to find it. This sends a negative signal about the maturity of your documentation organization.
Error 2: Approval dates that betray a lack of review. A document approved in 2021 and never updated since will be systematically questioned. The NIS2 auditor doesn't just ask if the document exists — they ask when it was last reviewed, and what has changed since.
Error 3: Inconsistent documents. The access management policy states that rights reviews are quarterly. The review log shows the last one was 11 months ago. This type of inconsistency between stated policy and proof of implementation is the most common discrepancy — and the easiest to avoid.
How to prepare for document collection without paralyzing your team
NIS2 documentation preparation represents between 3 and 6 weeks of work for a team of 2 to 3 people in a mid-sized organization. This timeframe can be significantly reduced if the existing documentation base is accessible and searchable.
Optivalue.ai allows you to centralize all your security documentation (policies, certifications, audit reports, procedures, minutes) and to answer NIS2 audit questionnaires by directly leveraging your own documents, providing the exact source (document, page, date) for each answer.
In practice: when the auditor's preliminary questionnaire arrives, each question is addressed by automatically leveraging the relevant documents from your database. Your team reviews, adjusts, and validates. The time to produce responses is reduced from several days to a few hours.
Jérôme Emin, CISO at Sully Group, used this approach to prepare for the renewal of the company's ISO 27001 certification: "Compiling the evidence file, which usually took us a week, was reduced to one day. Each answer was sourced from our own documents — the auditor had no questions about the origin of the information."
Where to start this week
If your NIS2 audit is within the next 3 to 6 months, here are three actions to prioritize immediately.
Action 1 — Map your documentation gaps. Use the checklist above to identify the areas where you are at ⚠️ or ❌. First, focus your efforts on areas A (governance), C (incidents), and E (supply chain) — these are the three areas most frequently found to be non-compliant during initial NIS2 audits.
Action 2 — Check all your approval dates. Review each key document and identify those whose last approval date is older than 12 months. Schedule a review and re-approval — even a formal one — before the audit.
Action 3 — Build your evidence file. Each NIS2 area must be demonstrable with documentary evidence. Start gathering this evidence now, in a file structured by area — not in the week leading up to the audit.
**Optivalue.ai allows you to answer NIS2 questionnaires by directly leveraging your existing documentation base. Dedicated private instance, hosting in France, answers sourced document by document.** Request a personalized demo →
Turn your quizzes into opportunities, right now
30 days free • No credit card required • No commitment
.png)
.png)