Download · XLSX
NIS2 evidence matrix: what to show an auditor under Article 21
A spreadsheet covering the 10 risk-management measures in NIS2 Article 21(2). For each requirement: example evidence, the system where it lives, owner, frequency, retention and the ISO/IEC 27001:2022 reference. No form, no sign-up.
What is the NIS2 evidence matrix?
The NIS2 evidence matrix is a spreadsheet that shows, for each of the 10 measures in NIS2 Article 21(2), what evidence to prepare, which system produces it and who owns it. It is for people who build an ISMS or get a company ready for a NIS2 audit and want to start with evidence rather than with another policy.
Why evidence from systems
NIS2 Article 21 requires appropriate and proportionate measures. Whoever checks them (an auditor, a regulator or a customer) wants to see that they work. That shows in records, not in the wording of a policy.
Logs, configuration exports and tool reports are created automatically and carry a date. A screenshot taken a week before the audit shows only that one day. That is why the matrix names, for every requirement, the system that produces the evidence.
National laws say the same. In Poland, the KSC Act counts automatically generated system log records as operational documentation (Article 10(4)) and requires security documentation to be kept for at least 2 years after it is withdrawn from use (Article 10(7)). In Germany, entities must document that they meet the measures (§ 30(1) BSIG). As of 24 September 2026, sources: Dz.U. 2026 item 252, § 30 BSIG, Directive (EU) 2022/2555.
// How to use it
How to use the matrix in four steps
Pick one area
Start with the area that carries the most risk or the one customers ask about most. Usually that is MFA, backups and suppliers.
Assign system and owner
For each row, name the system where the evidence is created in your company and the person responsible for it. An empty cell is your first gap.
Favor automatic evidence
A log, an export or a tool report beats a document written by hand. Where evidence has to be prepared by hand, set a date and a reminder.
Sample before the audit
Take one piece of evidence from each area and check its date, source and owner. An auditor will start with a similar sample.
Audits as a continuous process
Preview: the first three areas
The full matrix has 26 requirements across 10 areas. Below are areas (a) to (c), without the columns for legal basis, system, frequency and retention.
| Area | Requirement | Example evidence (artifact) | Owner (role) | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| (a) Risk analysis and security policies | Regular risk assessment and documented risk treatment decisions | Risk register with owners and review dates; approved risk treatment plan | CISO | Clauses 6.1, 8.2, 8.3 |
| (a) Risk analysis and security policies | Information security policy and topic-specific policies approved by management | Policy with version history and approval record; staff acknowledgments | CISO; approved by the management body | A.5.1, A.5.4 |
| (b) Incident handling | Monitoring that detects incidents and records how they were handled | Alert and incident tickets with timestamps (detection, triage, closure); list of detection rules | SOC lead or IT operations lead | A.8.15, A.8.16, A.5.25 |
| (b) Incident handling | Reporting significant incidents: early warning within 24 hours, notification within 72 hours, final report within one month of the notification | Incident register with the time of detection and the time each report was sent; copies of the reports | Incident manager, CISO | A.5.24, A.5.26, A.6.8 |
| (b) Incident handling | Lessons learned and corrective actions after incidents | Post-incident review with actions, owners and due dates | Incident manager | A.5.27, A.5.28 |
| (c) Business continuity, backups and crisis management | Business impact analysis and continuity plans | BIA with RTO and RPO for critical processes; approved continuity and recovery plans | Business continuity owner, COO | A.5.29, A.5.30 |
| (c) Business continuity, backups and crisis management | Backups that can actually be restored | Backup job reports (success and failures); restore test log with result and duration | IT infrastructure lead | A.8.13 |
| (c) Business continuity, backups and crisis management | Recovery and crisis management exercises | Exercise report: scenario, participants, time to recover, follow-up actions | Business continuity owner | A.5.30, A.8.14 |
Other versions: Polish, with KSC Act references and German, with § 30 BSIG references. FutureCode Evidence Box collects part of this evidence from your systems in read-only mode.
// Scope
What the matrix gives you, and what it cannot replace
The matrix gives you
- An evidence list for the 10 measures in NIS2 Article 21(2)
- A pointer to the system where each piece of evidence lives
- References to ISO/IEC 27001:2022 Annex A
- A starting point for an obligations register with owners
It cannot replace
- A risk assessment for your company
- Legal advice on whether NIS2 applies to you
- An audit, or a certificate of NIS2 compliance, which no official body issues
- Implementing controls in your systems
A policy you cannot show in the system is not a control. It is a document about a control.
// FAQ
Questions about the evidence matrix
Is this an ISMS template?
Only part of one. An ISMS also covers policies, risk assessment and management decisions. The matrix covers the other half: evidence that those rules work. You can attach it to your ISMS documentation as an evidence register.
Is a completed matrix enough for an audit?
No. An auditor checks the evidence, not the table. The matrix helps you organize it beforehand. Who runs formal audits depends on the country: in Poland, the KSC audit (Article 15) is done by an accredited conformity assessment body, at least two qualified auditors or a sectoral CSIRT. In Germany, operators of critical facilities prove implementation to the BSI through audits, inspections or certifications (§ 39 BSIG). As of 24 September 2026.
How long should we keep evidence?
NIS2 itself sets no retention period, but national laws can. In Poland, security documentation is kept for at least 2 years after it is withdrawn from use (KSC Article 10(7)). The periods in the matrix are suggestions for your own policy, and GDPR limits apply to personal data.
Does it map to ISO/IEC 27001?
Yes. Every row points to ISO/IEC 27001:2022 Annex A controls or to clauses of the standard. If you already run an ISMS under ISO/IEC 27001, much of that evidence also serves NIS2. More on ISO/IEC 27001 and on what NIS2 means for your business.
Do I need to give my email to download it?
No. The file downloads without a form. If you want to go through the matrix with us, request the first step.
First step: 5 weeks, fixed scope
One framework, without rewriting everything
A gap analysis with priorities, an obligations register with owners and a 90-day roadmap. At the end, one control is implemented in a system together with its evidence. More on NIS2 compliance in Poland and on the other frameworks: ISO/IEC 27001, DORA and the CRA.
Request the first step