Skip to content
AuditFront

Illustrative sample

NIS2 Readiness Report

Sample EU SaaS Company · Quick readiness assessment

56%

Partially ready

9/9

questions assessed

5

ready domains

1

partial domain

3

critical gaps

Executive summary

The sample organization completed all nine priority questions and met five of them. The result indicates useful foundations in incident handling, continuity, training, cryptography, and access control. Three critical governance and reporting gaps require immediate attention, while secure-development coverage needs to be made consistent. This quick result is a triage view, not a statement of NIS2 compliance.

Readiness by domain

Governance

Art. 20(1)

Gap

Incident handling

Art. 21(2)(b)

Ready

Business continuity

Art. 21(2)(c)

Ready

Supply chain security

Art. 21(2)(d)

Gap

Secure development

Art. 21(2)(e)

Partial

Cyber hygiene and training

Art. 21(2)(g)

Ready

Cryptography

Art. 21(2)(h)

Ready

Access control and HR security

Art. 21(2)(i)

Ready

Incident reporting

Art. 23

Gap

Prioritized findings

Critical issues first, with an action and target window for each.

3 critical · 1 high

CriticalAF-2026-001Article 20(1)Target: 0-30 days

Obtain management approval for NIS2 risk measures

Observed condition

The sample organization has security measures in operation, but no meeting minutes or decision record shows formal management-body approval.

Recommended action

Present the Article 21 risk measures and residual risks to the management body. Record approval, owners, review cadence, and accepted exceptions.

CriticalAF-2026-002Article 21(2)(d)Target: 0-30 days

Build and risk-rank the direct supplier inventory

Observed condition

Procurement records exist, but critical suppliers are not held in one inventory with service dependency, data access, and cybersecurity risk ratings.

Recommended action

Create one supplier register, identify critical services and data flows, assign inherent risk, and schedule proportionate reviews for high-risk providers.

CriticalAF-2026-003Article 23Target: 0-30 days

Document the NIS2 incident reporting sequence

Observed condition

The incident plan covers technical response but does not identify the national CSIRT, accountable reporter, or the 24-hour, 72-hour, and final-report steps.

Recommended action

Add a regulator-notification playbook with decision criteria, contacts, accountable roles, evidence preservation, and pre-approved message templates. Test it in a tabletop exercise.

HighAF-2026-004Article 21(2)(e)Target: 30-60 days

Apply security checks consistently across the delivery pipeline

Observed condition

Code review and dependency scanning are used for the main product, but infrastructure changes and two supporting services are outside the documented secure-development process.

Recommended action

Define a minimum secure-development baseline and enforce it for application, infrastructure, and supporting repositories. Track exceptions with owners and expiry dates.

What this sample does and does not prove

  • This is an illustrative report built from fictional answers to the real nine-question AuditFront diagnostic.
  • The score is self-reported and shows readiness signals, not certification, legal compliance, or regulator acceptance.
  • NIS2 scope and national implementation depend on country, sector, entity size, and applicable law.
  • A full assessment covers detailed controls, evidence expectations, findings, and a remediation roadmap beyond this triage result.

Generate your own NIS2 readiness result

Answer the same nine priority questions and see your score. Create an account only if you decide to save and continue.

Check my NIS2 readiness

No account · No credit card · About 10 minutes