Loading the automated NIS2 audit

Automated readiness audit for NIS2 and the Cybersecurity Act

Suitable for CISOs, information security specialists and administrators, internal and external auditors, technology lawyers, compliance and risk managers, business owners and executives responsible for regulatory readiness.

  • Executive summary for managementExecutive summary for management
  • NIS2 gap mapGap map
  • Prioritised action planPrioritised action plan
NIS2 and the Cybersecurity Act

Why this matters now?

Automated NIS2 readiness audit
NIS2 and changes to the Cybersecurity Act

NIS2 and changes to the Cybersecurity Act

NIS2, formally Directive (EU) 2022/2555, is no longer a future requirement. Member States had to transpose it into national law by October 2024, and it now applies across the European Union. The specific provisions, supervisory authorities and level of penalties are set by each country's national legislation.

Risk management and NIS2 measures

The organisation must be able to demonstrate

The organisation must be able to demonstrate how it manages risk, which measures it has implemented, how it maintains evidence and how it responds to incidents. For management this means visibility and control. For CISOs and IT teams it means clear priorities. For auditors, consultants and lawyers it means traceable documentation that can be verified.

  • This audit turns the regulatory requirements into a clear picture of the current state and an action plan that can be discussed with management, an external auditor or a client.
  • Suitable for CISOs, information security specialists and administrators, internal and external auditors, technology lawyers, compliance and risk managers, business owners and executives responsible for regulatory readiness.
  • You receive an evidence-based assessment of your organisation’s cybersecurity readiness, presented in a report that clearly links each finding to the applicable requirement and the evidence provided. The assessment covers key areas: management accountability, risk management, supplier management, incident reporting and business continuity.
Readiness assessment

What is the audit?

Assess where your organisation stands against the requirements NIS2 and the Bulgarian Cybersecurity Act online. Submit documentation for review, complete the questionnaire, or combine both.

Предоставяне на документи за анализ за автоматизиран NIS2 audit
Одит чрез предоставяне на документи

By submitting documents

The service provides an online assessment of your organisation's readiness to meet the requirements of the NIS2 Directive and the Bulgarian Cybersecurity Act. You can submit documentation for analysis, complete a questionnaire, or combine both approaches.

NIS2 readiness assessment
Purpose of the NIS2 readiness audit

Purpose of the audit

The audit is not a certificate and does not replace an official inspection by a competent authority. Its purpose is different: to show where you stand right now, what is missing, which risks matter most and what actions are needed to move towards better compliance.

Automated NIS2 audit with expert support
Automation and expert support

Automation and expert support

Automation enables fast, consistent information processing and significantly reduces manual effort. For packages that include expert support, an information security consultant reviews the results and discusses them with you. This combines the speed of automated assessment with professional judgement.

Automated approach

Why an automated approach?

The classic gap analysis often begins with lengthy coordination, meetings, interviews and manual collection of evidence. Here the process is laid out in advance. You start straight away, move through clear steps and get a result that can support a management decision.

A faster start

A faster start: the self-service part can be completed within a working day if the team has the necessary information to hand.

Consistent criteria

Consistent criteria: the assessment does not depend on who asks the questions or how they phrase them.

Less administrative burden

Less administrative burden: fewer preliminary meetings and less manual structuring of information.

Traceability

Traceability: every finding has a basis, a source and a link to a specific requirement.

Repeatability

Repeatability: suitable for annual reviews, internal control and preparation ahead of an external audit.

Human oversight

Human oversight: in the higher packages the results are reviewed by an expert, which matters when discussing cases that call for additional expert judgement.

Audit results

What will you receive?

You receive a report on your organisation's readiness against the requirements of the Bulgarian Cybersecurity Act: cybersecurity risk management, business continuity, supply chain security, incident reporting and the responsibilities of the management body. Each finding identifies the specific requirement, the evidence behind it and the level of risk. Where there is no evidence that a measure has been implemented, the report records this as a gap that makes it harder to demonstrate compliance to the competent authority.

Executive summary for management
View the executive summary for management

Executive summary for management

Executive summary for management: a brief overview of the current state, the main risks, the strengths and the priorities.

Detailed NIS2 audit report
View the detailed audit report

Detailed audit report

Detailed audit report: findings by area, documents, questions and applicable requirements.

NIS2 gap map
View the gap map

Gap map

Gap map: missing documents, incomplete processes and higher-risk areas.

Audit trail with regulatory requirements and evidence
View the audit trail

Audit trail

Audit trail: the link between a finding, a legal requirement, evidence and a recommendation.

Prioritised action plan
View the action plan

Action plan

Action plan: практични следващи стъпки, подредени по според нивото на риск и значение.

Comparability of the assessment over time
View comparability over time

Comparability over time

Comparability over time: the ability to repeat the assessment and show progress to management, an auditor or a client.

Preparation and confidentiality

What will you need?

Prepare the information security documentation your organisation already has: information security policy, business continuity and disaster recovery plan, access control and incident response procedures, risk and asset registers, supplier contracts and any other relevant documents.

Data protection and confidentiality

Data and confidentiality

The data is used only for the audit

  • It is encrypted in transit and at rest
  • Access to it is restricted

It is deleted after a set period

Optional: an NDA that fixes the retention period
NIS2 audit data deletion period
Data Processing Agreement and Privacy Policy

The full terms are set out in the Data Processing Agreement and the Privacy Policy

Information security specialist
Information security auditor
NIS2 compliance consultant

30

Review of ~30 documents

Preparing documents for the NIS2 audit

Packages

The three packages cover different levels of assurance, from a quick self-service assessment to working with a real consultant.

Basic package

999 EUR

Suitable for:

  • A quick self-assessment without a consultant
  • Organisations getting ready before mid-2026
  • A starting point for the management body

What is included:

  • Assessment against the 11 NIS2 measures
  • Review of ~30 documents
  • Maturity assessment
  • Gap map
  • Prioritised action plan
  • Conclusions linked to specific articles
  • Executive summary for management
  • Report by email to several addresses
  • Audit history

Standard package

1 399 EUR

Suitable for:

  • A report for a regulator or a client
  • RFP and contractual procedures
  • CISO and compliance teams

What is included:

  • Everything in the Basic package
  • Recommendations for each non-conformity
  • Steps to remediate the non-conformities
  • Legal text, evidence, conclusion and recommendation in one place
  • Risk prioritisation
  • A more convenient format for an external auditor, a client or regulatory preparation

Premium package

1 999 EUR

Suitable for:

  • Essential entities under supervision
  • Ahead of a first official inspection
  • Documenting management's obligations

What is included:

  • Everything in the Standard package
  • 10 hours with a real consultant
  • Review and discussion of the results
  • Help with planning corrective actions
  • Preparation for a meeting with management, a client, a consultant or an external auditor
  • Discussion of cases that call for additional expert judgement
  • 30% discount on your next audit30% discount on your next audit after each completed engagement. Valid for 13 months.
  • Report by email to several addressesReport by email to several addresses
  • History of completed auditsAudit history
Online process

How does the process work?

You choose a level to match your organisation's needs: a self-service assessment, an assessment with recommendations, or an assessment with consultant hours included.

01

1. Choosing a package

You choose a level to match your organisation's needs: a self-service assessment, an assessment with recommendations, or an assessment with consultant hours included.

02

2. Confidentiality and report language

You can sign an NDA before you begin. You then choose whether the report is in Bulgarian, English or another language from the available options.

03

3. Providing information

You upload the policies, procedures, registers and contracts you have, or you answer targeted questions. You can combine the two.

04

4. Checking the available documents

The system records which key documents are present and which are missing. Missing documents are flagged as potential non-conformities.

05

5. Draft for review

You receive a preliminary report. You can confirm the findings, add clarifications or provide further information.

06

6. Final report

After the review you receive the final result by email. The report can also be sent to addresses specified in advance.

Application within the organisation

Who benefits from an independent audit?

Who benefits from an independent audit?

CISOs and information security managers

They get an overall picture of maturity, the main gaps and the priorities for budget and delivery.

Information security specialists and administrators

They see which technical and organisational measures need to be improved, and with what priority.

Internal and external auditors

They work from organised non-conformities, evidence and links to the requirements, instead of starting from a blank page.

Lawyers and legal advisers

They get a clearer link between the regulatory obligations, management accountability and the organisation's actual state.

Compliance and risk managers

They get a basis for internal reporting, a plan for improvement and arguments for management decisions.

Business owners and managers

They see the risk in plain language and can decide what actions and resources are needed.

Suppliers and subcontractors

They can use the results as evidence of maturity in tenders, RFP procedures and client reviews.

Answers to frequently asked questions about the NIS2 audit
NIS2 by informationsc.com

30%

discount on your next audit

NIS2 audit

Frequently asked questions

The Act applies to public bodies and to companies in the 18 sectors under Annexes 1 and 2 if they are medium-sized or large (more than 50 employees or over EUR 10 million in turnover). Providers of DNS, cloud services, data centres, trust services and public electronic communications networks fall within scope regardless of size. The audit begins with a classification of whether you are an essential entity, an important entity, or outside scope.

You can do both. You upload the documentation and the system checks it. Or you go through the questionnaire entirely, with no files at all. You can also combine the two.

No. It is an assessment of readiness and compliance. It supports internal preparation, the management decision and work with auditors, but it is not a certificate and does not replace an inspection by a competent authority.

Yes. Before the final report is issued, the results are checked by an information security expert. This is a standard step in all packages. With the Premium package you get 10 hours of direct work with the consultant to discuss specific cases.

It is not mandatory. You can upload the documentation you have, answer the questions only, or combine the two approaches. If a document is missing, it is recorded as a potential non-conformity.

The data is processed only for the audit. It is not used for anything else. It is encrypted in transit and at rest. Access to it is restricted. It is deleted after a set period. Optionally, you can sign an NDA that fixes the period. The full terms are set out in the Data Processing Agreement.

The self-service part can be completed within a working day if the information is ready. After that comes the review of the draft and the finalisation of the report. With the Premium package, time is added for the meetings with the consultant.

By email, in a structured file with two sections. The first is an executive summary with overall findings, strengths and recommendations. The second is a detailed list of NIS2 non-conformities, each with a reference to a specific provision. The report can be sent to several addresses.

Yes. The report is designed to support conversations with external auditors, clients, partners and management. It contains findings, references to requirements and evidence, which makes verification easier.

Yes. Many clients and partners already require demonstrable maturity in cybersecurity and risk management, even when the supplier does not fall directly within scope. A proactive assessment helps in tenders, contracts and internal planning, as a way to demonstrate the organisation's cyber maturity.

It does not replace the training. The consultant hours in the Premium package, however, can be used precisely for training the management body under Article 21 of the Directive. Failing to meet this requirement leads to a personal fine. The report documents the training that was carried out.

Unlimited. You can download the completed audit without restrictions and at no extra charge. For your next annual audit you get a 30% discount, valid for 13 months.

The Basic package shows you the gaps and ties them to specific articles of the law. The Standard package adds a recommendation for each finding: not just what is wrong, but what to do specifically to remedy the non-conformity. It is the better fit when the report will be presented to a regulator, a client or in a tender procedure.

Your next step

How ready is your organisation for NIS2?

Check your readiness in good time. Start the automated audit and get a clear, traceable and useful assessment that management, the IT team, auditors, consultants and legal advisers can all rely on.

  • Automated process
  • Clear action plan
  • Traceable final report
Scope and accountability

Why this matters now?

Essential entities under NIS2

Essential entities

The requirements cover medium-sized and large undertakings across 18 sectors, public administration and certain digital service providers regardless of their size. Annex I lists the essential entities: energy, transport, banking, financial market infrastructures, healthcare, drinking water, digital infrastructure, ICT service management, public administration and space.

Important entities under NIS2

Important entities

Annex II covers the important entities: postal and courier services, waste management, the chemical and food industries, manufacturers of medical devices, electronics, machinery and vehicles, digital providers and research organisations.

NIS2 penalties, management accountability and deadlines

Penalties, management and deadlines

The penalties are substantial. For essential entities, fines can reach EUR 10 million or 2% of global annual turnover. For important entities, they can reach EUR 7 million or 1.4% of turnover. Individual Member States may set higher amounts.

The risk is not the company's alone. Senior management bears personal responsibility for approving and overseeing the risk-management measures. Even a missed cybersecurity training session, which has to be held regularly, can lead to a personal penalty under the national law of many countries.

There is a purely operational side as well. After an incident, the organisation has 24 hours for an early warning, 72 hours for a full notification and one month for a final report to the national CSIRT. The documentation that proves the measures have been implemented may be subject to inspection. The audit itself should be repeated annually.