NIS2 requires not only security measures, but also proof that they work. An internal audit shows where you stand — and makes priorities defensible.
An internal audit is not a bureaucratic obligation — it is the most efficient way to direct limited budget to where the greatest risks lie. And it delivers the documentation the BSI can demand in the event of an incident.
A note on terminology: The first internal audit for a new standard — here NIS2 — is often referred to as a gap analysis. It is the recommended starting point for any NIS2 compliance project.
Define scope and benchmark: which sites, systems and processes will be reviewed? Which requirements serve as the benchmark?
A robust stocktake: what has been implemented, what is missing, what is documented but not actually practised?
Identify gaps and prioritise by risk — not all findings are equally critical.
A prioritised plan with responsibilities, deadlines and resource needs — as a management instrument for the executive board.
We conduct your gap analysis, assess all NIS2 building blocks and hand over a prioritised action plan — a solid basis for decision-making for your executive board.
Request a Gap Analysis