Example. Fictional data.
Sample readiness report: Example Manufacturing Ltd.
This is what an Evidence Box report looks like after the auditor signs it off. The company, people, systems, identifiers and hashes are made up. We show the layout and level of detail, not the result of a real assessment.
| Entity | Example Manufacturing Ltd., maker of metal parts, 2 plants, about 400 people (fictional) |
| Engagement | Readiness assessment against NIS2 Article 21(2) and ISO/IEC 27001:2022 |
| Assessment period | 1-18 September 2026 |
| Report date | 22 September 2026 |
| Type | Readiness assessment. Not a certificate and not an audit opinion. |
| Tool | FutureCode Evidence Box, mode 1 (engagement run by FutureCode) |
| Classification | Confidential |
1. Executive summary
Example Manufacturing is partly ready for an audit. Average maturity across the 10 NIS2 Article 21(2) areas is 2.6 on a scale of 1 to 5. Two gaps are the most urgent: no MFA for privileged accounts and remote access, and ERP backup restores that were never tested. Both can be closed within 30 days. The supply chain and the incident reporting procedure need a 90-day plan.
Overall readiness: partial. Maturity: 2.6 out of 5.
| Severity | Findings |
|---|---|
| Critical | 0 |
| High | 3 |
| Medium | 7 |
| Low | 4 |
| Total | 14 |
2. Scope and method
- In scope: public cloud (2 accounts), identity directory, 320 workstations, 24 servers, 6 code repositories, the ERP system, business continuity processes, IT suppliers.
- Out of scope: OT networks at both plants (assessed from documentation only, no active tests) and the group's sales subsidiary.
- Criteria: NIS2 Article 21(2) and ISO/IEC 27001:2022 with Annex A.
- Method: read-only evidence collection, questionnaires for 11 control owners, open-source scanners, a first pass by an AI model checked by a second model, auditor review of the exception queue, a second reviewer for high findings.
- Type: readiness assessment. The report is not a certificate and not an audit opinion.
3. Maturity map for NIS2 Article 21(2)
Scale of 1 to 5: 1 means no control, 3 a control that works but leaves no regular evidence, 5 a control that is measured and backed by evidence from systems.
| Area | Main ISO/IEC 27001 controls | Maturity | Status | Main gap |
|---|---|---|---|---|
| (a) Risk analysis and policies | A.5.1; clause 6.1 | 3 | Amber | 17 of 42 risks have no review date |
| (b) Incident handling | A.5.24-A.5.28 | 2 | Red | Procedure lacks the 24- and 72-hour deadlines (F-05) |
| (c) Business continuity and backups | A.5.29, A.5.30, A.8.13 | 2 | Red | No ERP restore test (F-02) |
| (d) Supply chain | A.5.19-A.5.22 | 2 | Red | 9 of 14 critical suppliers not assessed (F-03) |
| (e) Development, maintenance, vulnerabilities | A.8.8, A.8.25-A.8.29 | 3 | Amber | 11 critical vulnerabilities open for over 30 days (F-04) |
| (f) Effectiveness assessment | A.5.35, A.5.36 | 2 | Red | No metrics and no management review |
| (g) Cyber hygiene and training | A.6.3 | 3 | Amber | Management training not documented |
| (h) Cryptography | A.8.24 | 4 | Green | No certificate inventory with expiry dates |
| (i) HR, access, assets | A.5.9, A.5.15, A.6.1 | 3 | Amber | Asset inventory misses cloud resources |
| (j) MFA and secure communications | A.8.5 | 2 | Red | No MFA on admin accounts and VPN (F-01) |
4. Selected findings
Here are 5 of the 14 findings. Each one points to evidence with an ID and a SHA-256 hash (shortened here to the first and last characters).
F-01. No MFA for privileged accounts and remote access
| Criteria | NIS2 Article 21(2)(j); ISO/IEC 27001 A.8.5 |
| Condition | 7 of 9 administrator accounts in the identity directory and all VPN access sign in with a password only. MFA is enforced for email only. |
| Cause | MFA was rolled out for email. Extending it to VPN and privileged accounts had no owner. |
| Effect | One stolen administrator password gives access to the domain and the ERP servers. |
| Recommendation | Enforce MFA for every privileged account and for VPN. Allow exceptions only with a reason and an expiry date. |
| Owner and due date | IT manager, 30 days |
| Evidence | EV-0112 conditional access policy export (8d2e4c…5901); EV-0118 VPN gateway configuration (ea3eb0…f359) |
| Auditor decision | Confirmed. Second reviewer: confirmed. |
F-02. ERP backup restores are not tested
| Criteria | NIS2 Article 21(2)(c); ISO/IEC 27001 A.8.13, A.5.30 |
| Condition | ERP backups run daily, but the last documented restore test is 19 months old. Nobody has checked the ERP recovery time (8 hours in the plan). |
| Cause | The continuity plan gives the restore test no owner and no date. |
| Effect | Nobody knows whether the ERP can be restored within 8 hours after an outage or a ransomware attack. |
| Recommendation | Run and document an ERP restore test, then repeat it every quarter with a written record. |
| Owner and due date | IT infrastructure lead, 30 days |
| Evidence | EV-0204 ERP backup job report, 90 days (18d6a3…e4de); EV-0207 business continuity plan, version 2.1 (c7a653…412d) |
| Auditor decision | Confirmed. Second reviewer: confirmed. |
F-03. Critical suppliers without a security assessment
| Criteria | NIS2 Article 21(2)(d) and 21(3); ISO/IEC 27001 A.5.19-A.5.21 |
| Condition | 9 of 14 critical suppliers have no security assessment. 6 contracts contain no duty to report incidents. |
| Cause | Procurement assesses suppliers on price and delivery. Security is not part of the process. |
| Effect | An incident at a supplier with remote access, such as the ERP service partner, may reach the company too late to meet the 24- and 72-hour deadlines. |
| Recommendation | Add a security assessment and contract clauses to procurement. Start with the 5 suppliers that have remote access. |
| Owner and due date | Procurement manager with the CISO, 90 days |
| Evidence | EV-0301 ICT supplier register (2955f2…aabd); EV-0306 service contract template (18c89f…0394) |
| Auditor decision | Confirmed. Second reviewer: confirmed. |
F-04. Critical vulnerabilities open for more than 30 days
| Criteria | NIS2 Article 21(2)(e); ISO/IEC 27001 A.8.8 |
| Condition | Authenticated scanning found 11 critical vulnerabilities older than 30 days on 4 servers, including the file server. |
| Cause | Servers are patched once a quarter. Critical patches have no separate deadline. |
| Effect | Known vulnerabilities stay open for weeks. |
| Recommendation | Set a 14-day deadline for critical patches and report every month whether it was met. |
| Owner and due date | IT operations lead, 60 days |
| Evidence | EV-0415 vulnerability scan report of 9 September 2026 (6b9b8a…901a); EV-0416 server patching schedule (30c5ba…209f) |
| Auditor decision | Confirmed. |
F-05. Incident procedure without the NIS2 reporting deadlines
| Criteria | NIS2 Article 21(2)(b) and Article 23; ISO/IEC 27001 A.5.24, A.5.26 |
| Condition | The incident procedure dates from 2021. It has no early warning within 24 hours and no notification within 72 hours to the CSIRT or competent authority. No exercise has taken place. |
| Cause | The procedure was not updated when the national NIS2 law came into force. |
| Effect | In a significant incident, the reporting deadlines may be missed. |
| Recommendation | Update the procedure, name the people who report to the CSIRT and run a tabletop exercise. |
| Owner and due date | CISO, 60 days |
| Evidence | EV-0502 incident handling procedure, version 1.3 (712ff3…b5fb); EV-0507 control owner answer to questionnaire IR-02 (4ac242…8a01) |
| Auditor decision | Confirmed. |
5. Statement of Applicability (SoA), excerpt
Draft Statement of Applicability for ISO/IEC 27001:2022. We show 6 of the 93 Annex A controls.
| Control | Applicable | Justification | Status | Evidence |
|---|---|---|---|---|
| A.5.19 Information security in supplier relationships | Yes | Suppliers with access to the ERP and the network | Partly implemented (F-03) | EV-0301 |
| A.5.24 Incident management planning and preparation | Yes | Required by NIS2 Article 21(2)(b) | Partly implemented (F-05) | EV-0502 |
| A.7.4 Physical security monitoring | Yes | Two plants with warehouses | Implemented | EV-0611 |
| A.8.5 Secure authentication | Yes | Remote access and privileged accounts | Not implemented (F-01) | EV-0112, EV-0118 |
| A.8.13 Information backup | Yes | ERP and file server | Partly implemented (F-02) | EV-0204 |
| A.8.30 Outsourced development | No | The company does not outsource software development | Excluded | EV-0620 (questionnaire DEV-01) |
6. Evidence index, excerpt
| ID | Evidence and source | Collected | SHA-256 |
|---|---|---|---|
| EV-0112 | Conditional access policy export Identity directory, read-only | 2026-09-03 10:14 | 8d2e4c…5901 |
| EV-0118 | VPN gateway configuration Configuration export, read-only | 2026-09-03 11:02 | ea3eb0…f359 |
| EV-0204 | ERP backup job report, 90 days Backup console | 2026-09-04 09:40 | 18d6a3…e4de |
| EV-0301 | ICT supplier register Questionnaire, owner: procurement | 2026-09-08 14:22 | 2955f2…aabd |
| EV-0415 | Authenticated vulnerability scan report Vulnerability scanner | 2026-09-09 21:05 | 6b9b8a…901a |
| EV-0502 | Incident handling procedure, version 1.3 Questionnaire, owner: CISO | 2026-09-10 08:51 | 712ff3…b5fb |
The full index has 212 entries. Each has a source, a timestamp and a SHA-256 hash.
7. Remediation plan
| Phase | Findings | Timeline | Owner |
|---|---|---|---|
| Quick wins | F-01, F-02 | within 30 days | IT manager |
| Short term | F-04, F-05 | 30-90 days | CISO |
| Before the audit | F-03 and the remaining medium findings | 90-180 days | CISO with procurement |
Once the first two phases are closed, a repeat review in self-assessment mode shows what changed (why audits should repeat). The formal audit is done by an independent auditor, not by the team that helped with the implementation.
8. Sign-off
| Approved by | IT auditor |
| Second reviewer (high findings) | Security engineer |
| Signed on | 22 September 2026 |
| Evidence pack | Sealed after sign-off, manifest hash fa9efa…c508 |
Our team includes certified auditors and security engineers. For the background on the requirements, see what the NIS2 directive means for your business.
A 30-minute demo on a fictional company
See how a report like this is built
We walk through the run from questionnaires to the sealed pack. Nothing gets connected to your systems.
Book a demo