NIS2 Directive
NIS2 Chapter VII: Supervision and Enforcement

NIS2 Directive Art.32: Cooperate with supervision: inspections, security audits, scans and requests for information and evidence

Supervision is a duty on the competent authority, but it lands on the entity as a set of things it must be able to submit to and produce. Essential entities are subject to both ex ante and ex post supervision, important entities to ex post supervision triggered by evidence of an infringement. In either case the measures include on-site inspections and off-site supervision, targeted security audits based on risk assessment, ad hoc audits after a significant incident or where non-compliance is indicated, security scans, requests for information needed to assess the risk-management measures, requests for access to data, documents and information, and requests for evidence of implementation of the entity's cybersecurity policies including audit results and their underlying evidence. Audit results must be made available to the authority, and the cost of a targeted audit performed by an independent body is normally borne by the audited entity. Enforcement can go on to binding instructions, ordered implementation of audit recommendations, a designated monitoring officer and, for essential entities, temporary suspension of a certification or of a senior individual's management functions. Readiness is therefore evidential: the entity must be able to produce the underlying evidence, not a summary of it.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 32 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 4 controls

  • 5.28 Collection of evidence
  • 5.35 Independent review of information security
  • 5.5 Contact with authorities
  • 8.34 Protection of information systems during audit testing 

ISO 27002:2022 · 4 controls

  • 5.28 Collection of evidence
  • 5.35 Independent review of information security
  • 5.5 Contact with authorities
  • 8.34 Protection of information systems during audit testing

C5 (Germany) · 3 controls

  • C5-COM-01 Identification of applicable legal, regulatory, self-imposed or contractual requirements
  • C5-COM-02 Policy for planning and conducting audits
  • C5-COM-03 Internal audits of the information security management system

APRA CPS 234 · 2 controls

  • CPS234-25 Internal Audit Review of Information Security Controls
  • CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days

CMMC 2.0 · 2 controls

FedRAMP High · 2 controls

  • CA-2 Control Assessments
  • CA-2(3) Control Assessments | Leveraging Results from External Organizations (CA-2(3))

FedRAMP Moderate · 2 controls

  • CA-2 Control Assessments
  • CA-2(3) Control Assessments | Leveraging Results from External Organizations (CA-2(3))

GDPR · 2 controls

  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties

NIST SP 800-171 Rev 3 · 2 controls

  • 7.1.a Article 7(1)(a): supply the Presidency with the data, information, documents, hardware and software it requests, with priority and on time
  • 8.4 Article 8(4): keep systems open for audit and provide the audit infrastructure

DORA · 1 control

  • DORA-Art.50 Administrative penalties and remedial measures

EU AI Act · 1 control

PCI DSS 4.0 · 1 control

  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.32 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 32 it maps to, and the evidence behind each claim, over MCP and REST.