Example. Fictional data.

Sample readiness report: Example Manufacturing Ltd.

This is what an Evidence Box report looks like after the auditor signs it off. The company, people, systems, identifiers and hashes are made up. We show the layout and level of detail, not the result of a real assessment.

Report details
EntityExample Manufacturing Ltd., maker of metal parts, 2 plants, about 400 people (fictional)
EngagementReadiness assessment against NIS2 Article 21(2) and ISO/IEC 27001:2022
Assessment period1-18 September 2026
Report date22 September 2026
TypeReadiness assessment. Not a certificate and not an audit opinion.
ToolFutureCode Evidence Box, mode 1 (engagement run by FutureCode)
ClassificationConfidential

1. Executive summary

Example Manufacturing is partly ready for an audit. Average maturity across the 10 NIS2 Article 21(2) areas is 2.6 on a scale of 1 to 5. Two gaps are the most urgent: no MFA for privileged accounts and remote access, and ERP backup restores that were never tested. Both can be closed within 30 days. The supply chain and the incident reporting procedure need a 90-day plan.

Overall readiness: partial. Maturity: 2.6 out of 5.

Findings by severity
SeverityFindings
Critical0
High3
Medium7
Low4
Total14

2. Scope and method

  • In scope: public cloud (2 accounts), identity directory, 320 workstations, 24 servers, 6 code repositories, the ERP system, business continuity processes, IT suppliers.
  • Out of scope: OT networks at both plants (assessed from documentation only, no active tests) and the group's sales subsidiary.
  • Criteria: NIS2 Article 21(2) and ISO/IEC 27001:2022 with Annex A.
  • Method: read-only evidence collection, questionnaires for 11 control owners, open-source scanners, a first pass by an AI model checked by a second model, auditor review of the exception queue, a second reviewer for high findings.
  • Type: readiness assessment. The report is not a certificate and not an audit opinion.

3. Maturity map for NIS2 Article 21(2)

Scale of 1 to 5: 1 means no control, 3 a control that works but leaves no regular evidence, 5 a control that is measured and backed by evidence from systems.

Maturity across the NIS2 Article 21(2) areas
AreaMain ISO/IEC 27001 controlsMaturityStatusMain gap
(a) Risk analysis and policiesA.5.1; clause 6.13Amber17 of 42 risks have no review date
(b) Incident handlingA.5.24-A.5.282RedProcedure lacks the 24- and 72-hour deadlines (F-05)
(c) Business continuity and backupsA.5.29, A.5.30, A.8.132RedNo ERP restore test (F-02)
(d) Supply chainA.5.19-A.5.222Red9 of 14 critical suppliers not assessed (F-03)
(e) Development, maintenance, vulnerabilitiesA.8.8, A.8.25-A.8.293Amber11 critical vulnerabilities open for over 30 days (F-04)
(f) Effectiveness assessmentA.5.35, A.5.362RedNo metrics and no management review
(g) Cyber hygiene and trainingA.6.33AmberManagement training not documented
(h) CryptographyA.8.244GreenNo certificate inventory with expiry dates
(i) HR, access, assetsA.5.9, A.5.15, A.6.13AmberAsset inventory misses cloud resources
(j) MFA and secure communicationsA.8.52RedNo MFA on admin accounts and VPN (F-01)

4. Selected findings

Here are 5 of the 14 findings. Each one points to evidence with an ID and a SHA-256 hash (shortened here to the first and last characters).

F-01. No MFA for privileged accounts and remote access

Finding F-01, severity high
CriteriaNIS2 Article 21(2)(j); ISO/IEC 27001 A.8.5
Condition7 of 9 administrator accounts in the identity directory and all VPN access sign in with a password only. MFA is enforced for email only.
CauseMFA was rolled out for email. Extending it to VPN and privileged accounts had no owner.
EffectOne stolen administrator password gives access to the domain and the ERP servers.
RecommendationEnforce MFA for every privileged account and for VPN. Allow exceptions only with a reason and an expiry date.
Owner and due dateIT manager, 30 days
EvidenceEV-0112 conditional access policy export (8d2e4c…5901); EV-0118 VPN gateway configuration (ea3eb0…f359)
Auditor decisionConfirmed. Second reviewer: confirmed.

F-02. ERP backup restores are not tested

Finding F-02, severity high
CriteriaNIS2 Article 21(2)(c); ISO/IEC 27001 A.8.13, A.5.30
ConditionERP backups run daily, but the last documented restore test is 19 months old. Nobody has checked the ERP recovery time (8 hours in the plan).
CauseThe continuity plan gives the restore test no owner and no date.
EffectNobody knows whether the ERP can be restored within 8 hours after an outage or a ransomware attack.
RecommendationRun and document an ERP restore test, then repeat it every quarter with a written record.
Owner and due dateIT infrastructure lead, 30 days
EvidenceEV-0204 ERP backup job report, 90 days (18d6a3…e4de); EV-0207 business continuity plan, version 2.1 (c7a653…412d)
Auditor decisionConfirmed. Second reviewer: confirmed.

F-03. Critical suppliers without a security assessment

Finding F-03, severity high
CriteriaNIS2 Article 21(2)(d) and 21(3); ISO/IEC 27001 A.5.19-A.5.21
Condition9 of 14 critical suppliers have no security assessment. 6 contracts contain no duty to report incidents.
CauseProcurement assesses suppliers on price and delivery. Security is not part of the process.
EffectAn incident at a supplier with remote access, such as the ERP service partner, may reach the company too late to meet the 24- and 72-hour deadlines.
RecommendationAdd a security assessment and contract clauses to procurement. Start with the 5 suppliers that have remote access.
Owner and due dateProcurement manager with the CISO, 90 days
EvidenceEV-0301 ICT supplier register (2955f2…aabd); EV-0306 service contract template (18c89f…0394)
Auditor decisionConfirmed. Second reviewer: confirmed.

F-04. Critical vulnerabilities open for more than 30 days

Finding F-04, severity medium
CriteriaNIS2 Article 21(2)(e); ISO/IEC 27001 A.8.8
ConditionAuthenticated scanning found 11 critical vulnerabilities older than 30 days on 4 servers, including the file server.
CauseServers are patched once a quarter. Critical patches have no separate deadline.
EffectKnown vulnerabilities stay open for weeks.
RecommendationSet a 14-day deadline for critical patches and report every month whether it was met.
Owner and due dateIT operations lead, 60 days
EvidenceEV-0415 vulnerability scan report of 9 September 2026 (6b9b8a…901a); EV-0416 server patching schedule (30c5ba…209f)
Auditor decisionConfirmed.

F-05. Incident procedure without the NIS2 reporting deadlines

Finding F-05, severity medium
CriteriaNIS2 Article 21(2)(b) and Article 23; ISO/IEC 27001 A.5.24, A.5.26
ConditionThe incident procedure dates from 2021. It has no early warning within 24 hours and no notification within 72 hours to the CSIRT or competent authority. No exercise has taken place.
CauseThe procedure was not updated when the national NIS2 law came into force.
EffectIn a significant incident, the reporting deadlines may be missed.
RecommendationUpdate the procedure, name the people who report to the CSIRT and run a tabletop exercise.
Owner and due dateCISO, 60 days
EvidenceEV-0502 incident handling procedure, version 1.3 (712ff3…b5fb); EV-0507 control owner answer to questionnaire IR-02 (4ac242…8a01)
Auditor decisionConfirmed.

5. Statement of Applicability (SoA), excerpt

Draft Statement of Applicability for ISO/IEC 27001:2022. We show 6 of the 93 Annex A controls.

Statement of Applicability, excerpt
ControlApplicableJustificationStatusEvidence
A.5.19 Information security in supplier relationshipsYesSuppliers with access to the ERP and the networkPartly implemented (F-03)EV-0301
A.5.24 Incident management planning and preparationYesRequired by NIS2 Article 21(2)(b)Partly implemented (F-05)EV-0502
A.7.4 Physical security monitoringYesTwo plants with warehousesImplementedEV-0611
A.8.5 Secure authenticationYesRemote access and privileged accountsNot implemented (F-01)EV-0112, EV-0118
A.8.13 Information backupYesERP and file serverPartly implemented (F-02)EV-0204
A.8.30 Outsourced developmentNoThe company does not outsource software developmentExcludedEV-0620 (questionnaire DEV-01)

6. Evidence index, excerpt

Evidence index, excerpt
IDEvidence and sourceCollectedSHA-256
EV-0112Conditional access policy export
Identity directory, read-only
2026-09-03 10:148d2e4c…5901
EV-0118VPN gateway configuration
Configuration export, read-only
2026-09-03 11:02ea3eb0…f359
EV-0204ERP backup job report, 90 days
Backup console
2026-09-04 09:4018d6a3…e4de
EV-0301ICT supplier register
Questionnaire, owner: procurement
2026-09-08 14:222955f2…aabd
EV-0415Authenticated vulnerability scan report
Vulnerability scanner
2026-09-09 21:056b9b8a…901a
EV-0502Incident handling procedure, version 1.3
Questionnaire, owner: CISO
2026-09-10 08:51712ff3…b5fb

The full index has 212 entries. Each has a source, a timestamp and a SHA-256 hash.

7. Remediation plan

Remediation plan by phase
PhaseFindingsTimelineOwner
Quick winsF-01, F-02within 30 daysIT manager
Short termF-04, F-0530-90 daysCISO
Before the auditF-03 and the remaining medium findings90-180 daysCISO with procurement

Once the first two phases are closed, a repeat review in self-assessment mode shows what changed (why audits should repeat). The formal audit is done by an independent auditor, not by the team that helped with the implementation.

8. Sign-off

Report sign-off
Approved byIT auditor
Second reviewer (high findings)Security engineer
Signed on22 September 2026
Evidence packSealed after sign-off, manifest hash fa9efa…c508

Our team includes certified auditors and security engineers. For the background on the requirements, see what the NIS2 directive means for your business.

A 30-minute demo on a fictional company

See how a report like this is built

We walk through the run from questionnaires to the sealed pack. Nothing gets connected to your systems.

Book a demo