Reaching the far bank

Raft

Demonstrating compliance: organised evidence, supervisory readiness, and honest self-assessment.

The river is crossed. Security measures are implemented, tested, and operational. Unlike climbing a mountain, where a flag gets planted at the summit, NIS2 compliance is demonstrated through ongoing evidence and verified through supervisory oversight. There is no certificate ceremony; compliance is operational reality.

Organising the documentation

The ISMS framework provides the foundation: a board-approved information security policy, risk assessment methodology and current results, a risk treatment plan showing how identified risks are addressed, a Statement of Applicability mapping controls to NIS2 requirements, and policies and procedures covering all mandatory measures in operational detail.

Governance evidence demonstrates board accountability: meeting minutes showing security oversight and decisions, management training records, organisational charts with clear security responsibilities, and budget allocations showing resource commitment.

Technical evidence demonstrates that controls actually work. Implementation evidence confirms the control is in place and running. Effectiveness evidence confirms it produces its intended effect under realistic conditions. Both are worth organising.

A penetration test result showing network segmentation held against a realistic attack path, a tabletop result showing the incident reporting chain met the 72-hour deadline under simulated pressure, and a phishing simulation showing click rates have moved after awareness interventions are more persuasive to a supervisory authority assessing proportionality than configuration documentation alone.

The technical file includes:

  • System inventories and network diagrams

  • Control implementation evidence from audits and assessments

  • Configuration documentation for critical systems

  • Vulnerability scan results with remediation tracking

  • Penetration test reports

  • Patch management logs

Operational evidence shows daily practice: incident logs with response and resolution details, business continuity test results, backup and recovery test logs, training completion and test results, access reviews and audit trails.

Supply chain evidence addresses third-party risk: supplier assessments and risk classifications, contractual security requirements in place, monitoring records, documentation for alternative suppliers.

Incident reporting records demonstrate regulatory compliance: submitted notifications with timestamps, internal incident reports with detailed analysis, post-incident reviews and lessons learned, corrective actions implemented after incidents.

Supervisory interactions

Some member states require registration with supervisory authorities; national implementation determines deadlines, required information, update procedures, and fees. Registering promptly avoids penalties for procedural non-compliance, which is a particularly annoying kind of penalty to earn.

Supervisory authorities may conduct inspections and audits: on-site visits, documentation requests, personnel interviews to verify understanding, system access with appropriate safeguards, and recommendations or corrective actions afterwards. A professional response has a designated point of contact, internal response procedures, organised evidence available quickly, answers within required timeframes, and transparency about challenges rather than concealment.

The collaborative posture pays: seeking guidance when uncertain, reporting challenges honestly, demonstrating good faith effort, showing improvement over time, and participating in sector forums. Supervisors remember both kinds of counterparty.

Proportionality in practice

NIS2 requires “appropriate and proportionate” measures, and both words eventually want defending. Appropriate: alignment with the specific risks, sector practice, mandatory requirements, and anywhere the organisation went beyond the minimum. Proportionate: organisation size, available resources, service criticality, likelihood and severity of the risks, cost-benefit reasoning, and alternative controls where standard approaches were not feasible.

Self-assessment before claiming compliance

An honest checklist run, for example:

  • All Article 21 measures implemented and operational

  • Board approval and active oversight

  • Risk assessment current and documented

  • Incident detection and response tested and working

  • Reporting procedures established, with successful test notifications

  • Supply chain programme running, with supplier assessments

  • Continuity plans documented and tested

  • Awareness training deployed with completion tracking (delivery evidence; paired with effectiveness evidence: phishing simulation click rate trends, exercise performance)

  • Evidence organised and accessible

  • Registration completed where required

  • Review cycles established and functioning

Anything that cannot be ticked gets a documented reason and a plan. Proportionality may justify some gaps, but the reasoning has to be clear, written down, and survivable in front of a supervisor.

Output

The output of this stage is a compliance evidence package organised logically, supervisory authority registration confirmation where required, audit-ready documentation, and a self-assessment report showing an honest evaluation of compliance status.

Last updated: 4 July 2026