The bulletin
NIS2 and your office network: the evidence you'll be asked for
NIS2 is not a network project, but a large part of the evidence auditors and insurers ask for lives in the network. Here is what they will want to see, and what 'having it' looks like in practice.
NIS2 (Directive (EU) 2022/2555) widens the circle of organisations that must show they manage cybersecurity risk. In broad terms it reaches medium and large entities — from 50 employees or EUR 10 million turnover — in a long list of sectors, plus suppliers pulled in through their customers' supply-chain obligations. Member states transpose it into national law; across the EU/EEA that process is complete or well under way, so the question for most organisations is no longer "does it apply" but "what do we have to show".
The directive is about governance: risk management, policies, incident reporting, management accountability. None of that is a network task. But when an auditor or an insurer asks for evidence that the measures in Article 21 are in place, a surprising share of the answer comes from the network.
What Article 21 asks for, seen from the network
Article 21(2) lists ten families of measures. The network-side evidence for the ones that touch it:
- Risk analysis and security policies: a current, accurate inventory of what is on the network (devices, firmware, who manages them). You cannot assess risk on assets you cannot list.
- Incident handling: an incident log with timestamps, classification, what was done and when; and monitoring that would actually have detected the incident.
- Business continuity and backup: configuration backups you can prove exist, and a restore you have actually tested (a screenshot of a backup job is not a restore test).
- Supply chain security: who has access to your network equipment, under what contract, and where their tooling runs.
- Security in acquisition, development and maintenance: patch and firmware status per device, with a process for handling vulnerabilities as they are published.
- Measures to assess effectiveness: periodic reviews of firewall rules, unused accounts, and segmentation that still holds.
- Cyber hygiene: segmentation between staff, guest, VoIP and IoT; nobody's printer sitting next to the finance server.
- Cryptography: encryption on management access and on links between sites.
- Access control and asset management: who can log in to network equipment, with what privileges, and how that access is recorded.
- Multi-factor authentication and secured communications: MFA on administrative access to the network, not only on e-mail.
Notice that most of these are things a well-run network already has. The gap is usually not the control; it is the evidence: the inventory is in someone's head, the backups are "somewhere", the change history is a mailbox.
What "having the evidence" looks like
An evidence pack an auditor can work with is boring on purpose: an asset inventory exported from the source of truth; a segmentation diagram that matches the configuration; an access-control statement (who, what, MFA); backup and restore attestations with dates; a vulnerability status list against published advisories; an incident log for the period; a summary of changes; the continuity measures per site; and the list of sub-processors with where their tooling runs. Produced every quarter, dated, from the tooling that runs the network — not assembled by hand the week before the audit.
Two honest caveats
NIS2 compliance is a management-system question. Network evidence is a large and usually neglected part of it, not the whole. Your legal and governance advisors own the framework; the network should simply be able to answer their questions with documents instead of meetings.
And proportionality is written into the directive: measures must be appropriate to the risk. A 60-person office does not need a bank's control set. It needs the basics done and provable.
If you would like to know what your network can already prove today, and what it cannot, that is a conversation we are happy to have.
