Independent review of NIS2 control

Does your NIS2 control work in practice?

Kynexis Information Security NIS2 audit independently assesses how the relevant obligations of your organisation from NIS2 and the Dutch Cybersecurity Act have been translated into governance, processes, technology, suppliers and evidence. You will receive a reasoned assessment of the actual functioning and an improvement agenda in logical order.

Do you recognize this?
  • Measures and policies have been set up, but there is no independent evidence of their operation.
  • Governance and oversight want to know whether the duty of care is being demonstrable.
  • Supplier agreements and internal responsibilities are in line with paperwork, but have not yet been reviewed.
  • An earlier GAP analysis has been followed and you want to determine the residual risk that remains.

What are the risks? Without independent review, an organisation can rely on documents and self-reports that do not demonstrate how NIS2 measures function during daily implementation and in incidents.

Our promise of service

Independent assurance on NIS2 execution and evidence

The NIS2 audit assesses how legal obligations have been set up, implemented and demonstrated and translates findings into board-level priorities.

  • Judgment on the actual effect
  • Findings with traceable evidence
  • Prioritized improvement agenda

NIS2 audit

What is NIS2 audit?

Kynexis Information Security NIS2 audit independently assesses how the relevant obligations of your organisation from NIS2 and the Dutch Cybersecurity Act have been translated into governance, processes, technology, suppliers and evidence. You will receive a reasoned assessment of the actual functioning and an improvement agenda in logical order.

FOR WHOMFor essential and important entities
WHENFor organisations beyond inventory
RESULTAn independent audit image with clear decision points

When does this service fit?

For organisations beyond inventory

Choose an NIS2 audit when measures are already set up and management, customers or chain partners need certainty about the execution. The audit can follow a GAP analysis or implementation process and is defined in such a way as to preserve independence and practical usability.

For essential and important entitiesFor management, audit committee and oversightFor detection towards chain partners

Audit areas

From board-level decision to demonstrate its effectiveness

The audit criteria shall follow from the applicable obligations, risk profile, sector and the pre-agreed scope.

Governance and decision-making

Assess defined policies, responsibilities, knowledge, resources, risk acceptance and periodic reporting.

Risk management measures

The design and implementation of appropriate measures shall be checked with interviews, documents and technical evidence.

Incident reporting and response

Detection, classification, escalation, reporting routes, reporting, practicing and learning from incidents assess.

Continuity and recovery

Critical processes, recovery targets, backups, tests and decision-making around re-enactment tests.

Suppliers and supply chain

Classification, due diligence, contractual arrangements, access, assurance, monitoring and exit assessment based on relevant information and evidence.

Evidence and improvement

Examine control owners, registrations, deviations, corrective actions and the board-level improvement cycle.

Your result

An independent audit image with clear decision points

The reporting distinguishes between facts, findings, risks and recommendations. the board and management see what control works demonstrably, what shortcomings require attention and who is responsible for the follow-up.

  • Management summary for governance and oversight
  • Audit findings with traceable evidence
  • Assessment of design, existence and where appropriate functioning
  • Priorities for risk and legal relevance
  • Improvements, owners and advice on re-examination
KYNEXISNIS2 audit
3High priority7Improving14Demonstrable
FocusOperation, evidence and board-level follow-upRisk-driven and enforceable

How we work

A transparent audit from scope to follow-up

  1. 01

    Scope and criteria

    Identify entity status, research demand, relevant obligations, systems, processes and exclusions.

  2. 02

    Examine evidence

    Collect and validate interviews, documentation, registrations and selected technical evidence.

  3. 03

    Matching Findings

    Verify facts and context and carefully identify risk, cause and impact.

  4. 04

    Reporting and monitoring

    Set up board-level decision points, improvement actions, owners and a review moment.

NIS2 research route

Choose the depth that suits your question

A quickscan orients, diagnoses a GAP analysis and an audit independently tests the demonstrable effect.

01 ORIENTATION

NIS2 Quickscan

Quickly a first picture of strengths and points of interest.

View this phase →
02 DIAGNOSIS

NIS2 GAP Analysis

To systematically determine differences and need for evidence.

View this phase →
03 IMPLEMENTATION

NIS2 implementation

Making measures, processes and safeguards work.

View this phase →
05 ASSURANCE

Re-assessment

Follow-up and permanent control periodically confirm.

Make your next step concreteHave demonstrated NIS2 control checked?

Discuss the audit question, desired security, available evidence and an appropriate independent scope.

Schedule an audit intake

Frequently Asked Questions

Practical answers on NIS2 audit

What is an NIS2 audit?

An NIS2 audit is an independent assessment based on traceable evidence. We investigate how relevant obligations under NIS2 and the Dutch Cybersecurity Act have been set up and demonstrated in the organisation.

What is the difference between an NIS2 GAP analysis and an NIS2 audit?

A GAP analysis determines what is already present and what is still needed. An audit shall require more evidence and shall independently assess the design, existence and, where appropriate, the functioning of already established management measures.

Does an NIS2 audit give you a certificate?

No. The Dutch Cybersecurity Act does not have a general NIS2 certificate that Kynexis can issue Information Security. The audit provides independent reporting within the agreed scope and can support preparation or assurance towards governance and chain partners.

Can Kynexis audit after own implementation guidance?

The desired independence is discussed in advance. In previous intensive implementation guidance, roles, scope and any additional independent review are designed to ensure that the reliability of the judgement remains clear.

Wouter Parent

An NIS2 audit should make visible where evidence and actual effect differ. That is precisely the difference that gives the board and management reliable steering information.

Current
WebinarFree webinars on NIS2, cyber risk management and oversight

Choose a live session for the board, executive team, supervisory board or board of trustees and register directly.

View webinars and dates