Download · XLSX

NIS2 evidence matrix: what to show an auditor under Article 21

A spreadsheet covering the 10 risk-management measures in NIS2 Article 21(2). For each requirement: example evidence, the system where it lives, owner, frequency, retention and the ISO/IEC 27001:2022 reference. No form, no sign-up.

What is the NIS2 evidence matrix?

The NIS2 evidence matrix is a spreadsheet that shows, for each of the 10 measures in NIS2 Article 21(2), what evidence to prepare, which system produces it and who owns it. It is for people who build an ISMS or get a company ready for a NIS2 audit and want to start with evidence rather than with another policy.

Why evidence from systems

NIS2 Article 21 requires appropriate and proportionate measures. Whoever checks them (an auditor, a regulator or a customer) wants to see that they work. That shows in records, not in the wording of a policy.

Logs, configuration exports and tool reports are created automatically and carry a date. A screenshot taken a week before the audit shows only that one day. That is why the matrix names, for every requirement, the system that produces the evidence.

National laws say the same. In Poland, the KSC Act counts automatically generated system log records as operational documentation (Article 10(4)) and requires security documentation to be kept for at least 2 years after it is withdrawn from use (Article 10(7)). In Germany, entities must document that they meet the measures (§ 30(1) BSIG). As of 24 September 2026, sources: Dz.U. 2026 item 252, § 30 BSIG, Directive (EU) 2022/2555.

// How to use it

How to use the matrix in four steps

  1. Pick one area

    Start with the area that carries the most risk or the one customers ask about most. Usually that is MFA, backups and suppliers.

  2. Assign system and owner

    For each row, name the system where the evidence is created in your company and the person responsible for it. An empty cell is your first gap.

  3. Favor automatic evidence

    A log, an export or a tool report beats a document written by hand. Where evidence has to be prepared by hand, set a date and a reminder.

  4. Sample before the audit

    Take one piece of evidence from each area and check its date, source and owner. An auditor will start with a similar sample.

    Audits as a continuous process

Preview: the first three areas

The full matrix has 26 requirements across 10 areas. Below are areas (a) to (c), without the columns for legal basis, system, frequency and retention.

NIS2 evidence matrix, areas (a) to (c), excerpt
AreaRequirementExample evidence (artifact)Owner (role)ISO/IEC 27001:2022
(a) Risk analysis and security policiesRegular risk assessment and documented risk treatment decisionsRisk register with owners and review dates; approved risk treatment planCISOClauses 6.1, 8.2, 8.3
(a) Risk analysis and security policiesInformation security policy and topic-specific policies approved by managementPolicy with version history and approval record; staff acknowledgmentsCISO; approved by the management bodyA.5.1, A.5.4
(b) Incident handlingMonitoring that detects incidents and records how they were handledAlert and incident tickets with timestamps (detection, triage, closure); list of detection rulesSOC lead or IT operations leadA.8.15, A.8.16, A.5.25
(b) Incident handlingReporting significant incidents: early warning within 24 hours, notification within 72 hours, final report within one month of the notificationIncident register with the time of detection and the time each report was sent; copies of the reportsIncident manager, CISOA.5.24, A.5.26, A.6.8
(b) Incident handlingLessons learned and corrective actions after incidentsPost-incident review with actions, owners and due datesIncident managerA.5.27, A.5.28
(c) Business continuity, backups and crisis managementBusiness impact analysis and continuity plansBIA with RTO and RPO for critical processes; approved continuity and recovery plansBusiness continuity owner, COOA.5.29, A.5.30
(c) Business continuity, backups and crisis managementBackups that can actually be restoredBackup job reports (success and failures); restore test log with result and durationIT infrastructure leadA.8.13
(c) Business continuity, backups and crisis managementRecovery and crisis management exercisesExercise report: scenario, participants, time to recover, follow-up actionsBusiness continuity ownerA.5.30, A.8.14

Other versions: Polish, with KSC Act references and German, with § 30 BSIG references. FutureCode Evidence Box collects part of this evidence from your systems in read-only mode.

// Scope

What the matrix gives you, and what it cannot replace

The matrix gives you

  • An evidence list for the 10 measures in NIS2 Article 21(2)
  • A pointer to the system where each piece of evidence lives
  • References to ISO/IEC 27001:2022 Annex A
  • A starting point for an obligations register with owners

It cannot replace

  • A risk assessment for your company
  • Legal advice on whether NIS2 applies to you
  • An audit, or a certificate of NIS2 compliance, which no official body issues
  • Implementing controls in your systems

A policy you cannot show in the system is not a control. It is a document about a control.

// FAQ

Questions about the evidence matrix

Is this an ISMS template?

Only part of one. An ISMS also covers policies, risk assessment and management decisions. The matrix covers the other half: evidence that those rules work. You can attach it to your ISMS documentation as an evidence register.

Is a completed matrix enough for an audit?

No. An auditor checks the evidence, not the table. The matrix helps you organize it beforehand. Who runs formal audits depends on the country: in Poland, the KSC audit (Article 15) is done by an accredited conformity assessment body, at least two qualified auditors or a sectoral CSIRT. In Germany, operators of critical facilities prove implementation to the BSI through audits, inspections or certifications (§ 39 BSIG). As of 24 September 2026.

How long should we keep evidence?

NIS2 itself sets no retention period, but national laws can. In Poland, security documentation is kept for at least 2 years after it is withdrawn from use (KSC Article 10(7)). The periods in the matrix are suggestions for your own policy, and GDPR limits apply to personal data.

Does it map to ISO/IEC 27001?

Yes. Every row points to ISO/IEC 27001:2022 Annex A controls or to clauses of the standard. If you already run an ISMS under ISO/IEC 27001, much of that evidence also serves NIS2. More on ISO/IEC 27001 and on what NIS2 means for your business.

Do I need to give my email to download it?

No. The file downloads without a form. If you want to go through the matrix with us, request the first step.

First step: 5 weeks, fixed scope

One framework, without rewriting everything

A gap analysis with priorities, an obligations register with owners and a 90-day roadmap. At the end, one control is implemented in a system together with its evidence. More on NIS2 compliance in Poland and on the other frameworks: ISO/IEC 27001, DORA and the CRA.

Request the first step