NIS2 entered into force across all EU member states in October 2024. Eighteen months later, fewer than 40 percent of newly in-scope entities have run a formal assessment against Articles 20 and 21. The rest sit in a comfortable ambiguity: "we have started", "it is in progress", "we plan to come back to it".
That delay is not harmless. Unlike GDPR, whose enforcement took years to structure, national competent authorities already hold formal inspection powers and direct sanctions: up to 10 million euros or 2 percent of global turnover for essential entities, 7 million or 1.4 percent for important ones. This article examines the three audit angles most consistently skipped, and proposes a 90-day structure.
Key figures
- Under 40 percent of in-scope NIS2 entities have run a structured maturity audit (Q1 2026 estimate)
- 10 mandatory minimum measures, NIS2 Article 21
- 24 hours: early notification deadline to the competent authority (Article 23)
- 18 sectors covered by the directive (Annexes I and II)
1. Article 20: board governance, the systemic blind spot
Nearly every NIS2 project concentrates on Article 21, the technical risk management measures. That is understandable: IT and security leaders recognise the territory, checklists are plentiful, and audit firms sell standardised grids.
Article 20 is structurally harder to operationalise. It requires management bodies, including the board, to approve cybersecurity risk management measures, oversee their implementation, and receive adequate training. This is not a governance detail. It is an explicit legal obligation creating personal accountability for directors. An entity that deployed MFA, network segmentation and an incident response plan, but whose board never formally approved the cybersecurity policy, is non-compliant under NIS2.
In the first NIS2 inspections of 2026, findings were raised on the absence of traceable board decisions on cybersecurity. Those findings are not sanctions, but they appear in inspection reports as insufficient controls, which can shift how fault is assessed after a later incident.
Common error: treating Article 20 as a documentation formality. In audit, the question is not "does an approved document exist?" but "which director can explain what they approved, and why?"
In practice: assess the two pillars separately, technical (Art. 21) and governance (Art. 20). For the board, a quarterly cyber risk dashboard, voted in session and archived, is robust evidence.
2. Supply chain: the most frequent gap
Article 21.2(d) requires supply chain security management, including measures covering relationships with direct and indirect providers.
In practice, in-scope organisations often run hundreds of providers. Many hold no consolidated inventory of them, let alone a formal security qualification process. Supply chain is the gap most frequently identified in maturity audits. The vector is well documented: the ENISA Threat Landscape 2025 report puts attacks through compromised providers at over a third of significant incidents notified to NIS2 authorities in the EU.
Common error: assuming a contractual security clause is enough. A provider that signs a security addendum is not thereby secure. Contractual compliance and your third party's operational maturity are two different things.
In practice: categorise providers by criticality (access to information systems, sensitive data processing, business continuity component). For critical providers, plan at minimum an annual security questionnaire and a review of reported incidents. For essential ones, consider a contractual audit every two years.
3. Regulatory notification: fine on paper, impossible under pressure
NIS2 Article 23 requires early notification within 24 hours to the competent authority, followed by a detailed report at 72 hours. These constraints are known. What organisations underestimate is their operational nature: they apply from the start of the incident, not after full investigation.
A maturity audit must test your ability to notify, not only to document the procedure. At hour 24 of a live incident, your team is simultaneously handling technical containment, internal communication, business pressure, and the drafting of a partial regulatory notification. Simulations consistently reveal two gaps: no template pre-approved by the DPO and legal counsel, and no clearly designated notification owner, distinct from the incident owner.
Common error: validating the notification procedure in a document review, never testing it under time pressure. A process signed off in committee and a reflex at three in the morning are different things.
In practice: build a regulatory notification simulation into your next crisis exercise. Target: produce a NIS2-compliant partial notification in under four hours, using only the information available at T+4 of a fictional incident. Involve your DPO and legal counsel, not only the technical teams.
A 90-day structure
Phase 1, days 1 to 30, scoping: inventory of entities in regulatory scope (essential against important), mapping of critical systems, identification of tier-1 and tier-2 providers, review of existing board governance and documented cybersecurity deliberations.
Phase 2, days 30 to 60, assessment: audit of the ten Article 21 measures, risk management, incident handling, business continuity, supply chain security, access control, cryptography, MFA, network system security, human resources policies, and communications security. Separate Article 20 assessment with traceability of management decisions.
Phase 3, days 60 to 90, remediation plan: gaps prioritised by regulatory and operational risk, action plan with owners and deadlines, board tracking dashboard, notification simulation with DPO and legal counsel.
Presidio automates the collection, scoring and traceability of this audit: unified NIS2, DORA and GDPR frameworks, built-in third-party questionnaires, board dashboards and pre-configured notification workflows.
Conclusion
NIS2 is no longer a future deadline. Eighteen months in, it is an active legal obligation, with a competent inspection authority, an effective sanctions regime, and entities beginning to experience both directly.
Organisations that get through their first compliance audit with the least friction share one trait: they treated all three pillars with equal rigour, the technical measures (Art. 21), board governance (Art. 20), and operational notification capability (Art. 23). Every neglected pillar is a documented gap in the inspection report.
In your context: have you tested your ability to notify on time, or only your ability to describe the procedure that should apply?
