An Edge Built on Knowledge and Experience
NIS2 — Internal Audit / Gap Analysis

Conducting an Internal NIS2 Audit

NIS2 requires not only security measures, but also proof that they work. An internal audit shows where you stand — and makes priorities defensible.

Technical & Legal Expertise Experience From Numerous NIS2 Projects Based in Sindelfingen
Why an Internal Audit?

Investing Without a Status Analysis Wastes Budget

An internal audit is not a bureaucratic obligation — it is the most efficient way to direct limited budget to where the greatest risks lie. And it delivers the documentation the BSI can demand in the event of an incident.

A note on terminology: The first internal audit for a new standard — here NIS2 — is often referred to as a gap analysis. It is the recommended starting point for any NIS2 compliance project.

Structured Process

The NIS2 Audit in Four Steps

1. Planning

Define scope and benchmark: which sites, systems and processes will be reviewed? Which requirements serve as the benchmark?

  • Define NIS2-relevant services
  • Derive review criteria from § 30 BSIG
  • Appoint points of contact
  • Plan timeline and resources

2. Status Analysis

A robust stocktake: what has been implemented, what is missing, what is documented but not actually practised?

  • Interviews with responsible staff
  • Document review
  • Reality check: do processes work in a real incident?
  • Technical spot checks

3. Evaluation

Identify gaps and prioritise by risk — not all findings are equally critical.

  • Risk analysis, incident management
  • Supply chain, vulnerability management
  • Training, documentation
  • Technical protective measures

4. Action Plan

A prioritised plan with responsibilities, deadlines and resource needs — as a management instrument for the executive board.

  • Short term: quick wins
  • Medium term: structural measures
  • Long term: strategic investments
What a Robust Audit Delivers

Three Things That Must Be in Place at the End

Frequently Asked Questions

Internal Audit and NIS2

Can the internal audit be carried out by our own IT department?
Partially. Technical checks can be carried out internally. For a robust overall assessment, external support is recommended — not because internal teams are incompetent, but because external reviewers uncover blind spots and provide an independent assessment that carries more weight with the BSI.
How does an internal audit differ from ISO 27001 certification?
An internal audit is a self-assessment, with or without external support. ISO 27001 certification is an external confirmation by an accredited body. Both have their place — the internal audit is the faster, more cost-effective entry point; certification provides the strongest external evidence.
How often should an internal NIS2 audit be repeated?
At least annually, supplemented by ad-hoc reviews following major changes to the IT infrastructure, after security incidents, or after changes to regulatory requirements. An audit is not a one-off project but part of a continuous ISMS process.
Related Topics

Further NIS2 Topics

NIS2 Gap Analysis by Experienced Experts

We conduct your gap analysis, assess all NIS2 building blocks and hand over a prioritised action plan — a solid basis for decision-making for your executive board.

Request a Gap Analysis
Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com