Act No. 264/2025 Coll. On cybersecurity entered into force in October 2025 and introduced the obligation to carry out systematic security audits. Approximately 6 000 organisations in the Czech Republic must demonstrate compliance with NIS2 requirements. The question that concerns every security director or IT manager is: What tasks can the company handle in-house, and where does it require an external expert?
The answer depends on your size, internal capacity and the complexity of your environment. This guide will show you how to carry out a NIS2 audit step by step, and where self-help reaches its limits.
What does a NIS2 audit actually involve?
The NIS2 audit is not a one-off event but a structured process resulting in an accurate understanding of your cybersecurity status and a clear plan for achieving legal compliance. Decree No. 409/2025 Coll. (implementing regulation to Act No. 264/2025 Coll.) specifies 13 areas of security measures that regulated entities must cover.
The audit typically comprises four main areas:
- Scope: Which systems, processes and organisational components fall under NIS2?
- Assets: What do you own, what do you operate, and what is critical for your key services?
- Risks: What threats and vulnerabilities endanger your assets?
- Measures: What safety measures do you have in place, and which are missing according to Decree No. 409/2025?
5-step procedure for a NIS2 audit
Step 1: Scoping
The first step is to define the scope of the audit. Not all systems in your company are equally important from the perspective of NIS2. The law distinguishes between essential and important entities. basic services (essential services) - these must be identified precisely.
During the scoping phase, answer the following:
- What are your key services that your business or customers rely on?
- Which IT systems support these services?
- What are the dependencies on suppliers and third parties?
- Does the law apply to you as a critical entity (Annex I) or an important entity (Annex II)?
What you can do yourself: Internal workshops with key managers, creation of a diagram of key processes and systems.
Where you need an expert: Legal interpretation of whether your sector and size actually create an obligation, and precise classification as a critical or important entity.
Step 2: Asset Inventory
Without an accurate overview of assets, risks cannot be managed. The asset inventory includes all hardware, software, data, processes and people relevant to your key services.
Structure the inventory by categories:
- Hardware assets: servers, network equipment, employee end devices
- Software assets: applications, operating systems, cloud services
- Data assets: database, backups, documentation
- Process assets: key business processes and procedures
- Human assets: key roles, know-how, approaches
Assess every asset in terms of confidentiality, integrity and availability (the CIA triad). Tools: NÚKIB methodology for asset inventory, Excel templates available on the NÚKIB website or via SecureOn audit tools.
Step 3: Risk Analysis
Risk analysis is the core of the entire NIS2 audit. For each critical asset, you identify threats and vulnerabilities, estimate the likelihood of their occurrence and the potential impact on your business.
The basic methodology uses the formula:
Risk = Probability × Impact
Typické hrozby pro regulované subjekty zahrnují ransomware útoky, phishingové kampaně, selhání dodavatele, výpadky napájení nebo přírodní katastrofy. Podrobný postup analýzy rizik popisujeme v samostatném článku NIS2 Risk Analysis: How to Carry It Out Correctly.
Step 4: Gap analysis against Decree 409/2025
A gap analysis compares your current status with the requirements of Decree No. 409/2025 Coll. The decree defines specific safety measures in 13 areas:
- Cybersecurity risk management
- Supply chain security
- Asset management
- Access control and authentication
- Physical security
- Cryptography and Encryption
- Security of networks and information systems
- Detection of cybersecurity incidents
- Managing cybersecurity incidents
- Continuity of operations (BCM)
- Training and awareness in cybersecurity
- Safe development environment
- Disclosure of vulnerabilities
For each area, mark what is fully implemented, what is partially in place, and what is completely missing. The result is a clear gap matrix. Free online audit helps you quickly identify these gaps: try it out check.nis2ok.cz.
Step 5: Action Plan
Based on the gap analysis, compile a prioritised corrective action plan. Assign each gap to a category according to urgency:
- Critical (within 3 months): Absence of an incident response plan, missing MFA for privileged accounts, and unsecured internet access.
- High (up to 6 months): Incomplete asset inventory, missing staff training, and unimplemented patch management.
- Medium-term (up to 12 months): Optimisation of logging, expansion of security monitoring, formalisation of supplier management.
What you can do yourself
Smaller organisations with internal IT capacity can manage the following in-house: creating an asset inventory, basic risk classification, comparison against the NIS2 requirements checklist and preparation of an action plan. The following tools are used for this purpose:
- NÚKIB methodology: The National Cyber and Information Security Bureau (NÚKIB) has published free guides and templates on its website nukib.gov.cz.
- Excel templates: Tabular templates for asset inventory, risk register and gap matrix
- Online audit tool: SecureOn / nis2ok.cz - free structured questionnaire that guides you through key areas and produces a report on your current status
Where you need an expert
There are areas where a DIY approach is insufficient and where an error can have legal consequences. We recommend expert assistance for:
- Penetration testing: Revealing actual vulnerabilities requires specialised tools and knowledge of ethical hacking.
- Technical measures: Implementation of SIEM, SOAR, anomaly detection or zero-trust architecture
- Legal interpretation: Confirmation of whether your company is actually subject to the Act and in which category, first verify on secureon.cz NIS2OK.cz free audit
- Incident response plan: Preparation and testing of an incident response plan in accordance with NÚKIB requirements.
- Certification and audit: If you require a formal certificate of compliance for customers or regulators,
- NIS2 consultant: For comprehensive support throughout the entire compliance process, contact us. NIS2Manager.cz
How to get started today
A NIS2 audit need not be overwhelming if approached systematically. Begin with a scoping workshop (lasting 2–4 hours), proceed to an asset inventory, and then launch the free online audit on secureon.cz. nis2ok.czwhich will show you your biggest gaps in just 10 minutes.
SecureOn.cz offers both a standalone audit tool for self-assessment and full professional audits with a final report and recommendations. More information at secureon.cz secureon.cz.