
Independent review of NIS2 control
Does your NIS2 control work in practice?
Kynexis Information Security NIS2 audit independently assesses how the relevant obligations of your organisation from NIS2 and the Dutch Cybersecurity Act have been translated into governance, processes, technology, suppliers and evidence. You will receive a reasoned assessment of the actual functioning and an improvement agenda in logical order.
- Measures and policies have been set up, but there is no independent evidence of their operation.
- Governance and oversight want to know whether the duty of care is being demonstrable.
- Supplier agreements and internal responsibilities are in line with paperwork, but have not yet been reviewed.
- An earlier GAP analysis has been followed and you want to determine the residual risk that remains.
What are the risks? Without independent review, an organisation can rely on documents and self-reports that do not demonstrate how NIS2 measures function during daily implementation and in incidents.
Our promise of service
Independent assurance on NIS2 execution and evidence
The NIS2 audit assesses how legal obligations have been set up, implemented and demonstrated and translates findings into board-level priorities.
- Judgment on the actual effect
- Findings with traceable evidence
- Prioritized improvement agenda
NIS2 audit
What is NIS2 audit?
Kynexis Information Security NIS2 audit independently assesses how the relevant obligations of your organisation from NIS2 and the Dutch Cybersecurity Act have been translated into governance, processes, technology, suppliers and evidence. You will receive a reasoned assessment of the actual functioning and an improvement agenda in logical order.
When does this service fit?
For organisations beyond inventory
Choose an NIS2 audit when measures are already set up and management, customers or chain partners need certainty about the execution. The audit can follow a GAP analysis or implementation process and is defined in such a way as to preserve independence and practical usability.
Audit areas
From board-level decision to demonstrate its effectiveness
The audit criteria shall follow from the applicable obligations, risk profile, sector and the pre-agreed scope.
Governance and decision-making
Assess defined policies, responsibilities, knowledge, resources, risk acceptance and periodic reporting.
Risk management measures
The design and implementation of appropriate measures shall be checked with interviews, documents and technical evidence.
Incident reporting and response
Detection, classification, escalation, reporting routes, reporting, practicing and learning from incidents assess.
Continuity and recovery
Critical processes, recovery targets, backups, tests and decision-making around re-enactment tests.
Suppliers and supply chain
Classification, due diligence, contractual arrangements, access, assurance, monitoring and exit assessment based on relevant information and evidence.
Evidence and improvement
Examine control owners, registrations, deviations, corrective actions and the board-level improvement cycle.
Your result
An independent audit image with clear decision points
The reporting distinguishes between facts, findings, risks and recommendations. the board and management see what control works demonstrably, what shortcomings require attention and who is responsible for the follow-up.
- Management summary for governance and oversight
- Audit findings with traceable evidence
- Assessment of design, existence and where appropriate functioning
- Priorities for risk and legal relevance
- Improvements, owners and advice on re-examination
How we work
A transparent audit from scope to follow-up
- 01
Scope and criteria
Identify entity status, research demand, relevant obligations, systems, processes and exclusions.
- 02
Examine evidence
Collect and validate interviews, documentation, registrations and selected technical evidence.
- 03
Matching Findings
Verify facts and context and carefully identify risk, cause and impact.
- 04
Reporting and monitoring
Set up board-level decision points, improvement actions, owners and a review moment.
NIS2 research route
Choose the depth that suits your question
A quickscan orients, diagnoses a GAP analysis and an audit independently tests the demonstrable effect.
NIS2 Quickscan
Quickly a first picture of strengths and points of interest.
View this phase →NIS2 GAP Analysis
To systematically determine differences and need for evidence.
View this phase →NIS2 implementation
Making measures, processes and safeguards work.
View this phase →NIS2 audit
Independently assess functioning and evidence.
Fit for this implementation phaseRe-assessment
Follow-up and permanent control periodically confirm.
Discuss the audit question, desired security, available evidence and an appropriate independent scope.
Schedule an audit intake →Frequently Asked Questions
Practical answers on NIS2 audit
What is an NIS2 audit?
An NIS2 audit is an independent assessment based on traceable evidence. We investigate how relevant obligations under NIS2 and the Dutch Cybersecurity Act have been set up and demonstrated in the organisation.
What is the difference between an NIS2 GAP analysis and an NIS2 audit?
A GAP analysis determines what is already present and what is still needed. An audit shall require more evidence and shall independently assess the design, existence and, where appropriate, the functioning of already established management measures.
Does an NIS2 audit give you a certificate?
No. The Dutch Cybersecurity Act does not have a general NIS2 certificate that Kynexis can issue Information Security. The audit provides independent reporting within the agreed scope and can support preparation or assurance towards governance and chain partners.
Can Kynexis audit after own implementation guidance?
The desired independence is discussed in advance. In previous intensive implementation guidance, roles, scope and any additional independent review are designed to ensure that the reliability of the judgement remains clear.

An NIS2 audit should make visible where evidence and actual effect differ. That is precisely the difference that gives the board and management reliable steering information.