Blog NIS2 Audit

How to conduct a NIS2 audit yourself: A step-by-step guide for businesses

Act 264/2025 Coll. Sets strict requirements for cybersecurity. We know how to carry out an NIS2 audit systematically, what you can handle on your own and where it pays to call in a specialist.

30 October 2025 · 8 minutes reading · NIS2 Audit

Act No. 264/2025 Coll. On cybersecurity entered into force in October 2025 and introduced the obligation to carry out systematic security audits. Approximately 6 000 organisations in the Czech Republic must demonstrate compliance with NIS2 requirements. The question that concerns every security director or IT manager is: What tasks can the company handle in-house, and where does it require an external expert?

The answer depends on your size, internal capacity and the complexity of your environment. This guide will show you how to carry out a NIS2 audit step by step, and where self-help reaches its limits.

What does a NIS2 audit actually involve?

The NIS2 audit is not a one-off event but a structured process resulting in an accurate understanding of your cybersecurity status and a clear plan for achieving legal compliance. Decree No. 409/2025 Coll. (implementing regulation to Act No. 264/2025 Coll.) specifies 13 areas of security measures that regulated entities must cover.

The audit typically comprises four main areas:

5-step procedure for a NIS2 audit

Step 1: Scoping

The first step is to define the scope of the audit. Not all systems in your company are equally important from the perspective of NIS2. The law distinguishes between essential and important entities. basic services (essential services) - these must be identified precisely.

During the scoping phase, answer the following:

What you can do yourself: Internal workshops with key managers, creation of a diagram of key processes and systems.

Where you need an expert: Legal interpretation of whether your sector and size actually create an obligation, and precise classification as a critical or important entity.

Step 2: Asset Inventory

Without an accurate overview of assets, risks cannot be managed. The asset inventory includes all hardware, software, data, processes and people relevant to your key services.

Structure the inventory by categories:

Assess every asset in terms of confidentiality, integrity and availability (the CIA triad). Tools: NÚKIB methodology for asset inventory, Excel templates available on the NÚKIB website or via SecureOn audit tools.

Step 3: Risk Analysis

Risk analysis is the core of the entire NIS2 audit. For each critical asset, you identify threats and vulnerabilities, estimate the likelihood of their occurrence and the potential impact on your business.

The basic methodology uses the formula:

Risk = Probability × Impact

Typické hrozby pro regulované subjekty zahrnují ransomware útoky, phishingové kampaně, selhání dodavatele, výpadky napájení nebo přírodní katastrofy. Podrobný postup analýzy rizik popisujeme v samostatném článku NIS2 Risk Analysis: How to Carry It Out Correctly.

Step 4: Gap analysis against Decree 409/2025

A gap analysis compares your current status with the requirements of Decree No. 409/2025 Coll. The decree defines specific safety measures in 13 areas:

  1. Cybersecurity risk management
  2. Supply chain security
  3. Asset management
  4. Access control and authentication
  5. Physical security
  6. Cryptography and Encryption
  7. Security of networks and information systems
  8. Detection of cybersecurity incidents
  9. Managing cybersecurity incidents
  10. Continuity of operations (BCM)
  11. Training and awareness in cybersecurity
  12. Safe development environment
  13. Disclosure of vulnerabilities

For each area, mark what is fully implemented, what is partially in place, and what is completely missing. The result is a clear gap matrix. Free online audit helps you quickly identify these gaps: try it out check.nis2ok.cz.

Step 5: Action Plan

Based on the gap analysis, compile a prioritised corrective action plan. Assign each gap to a category according to urgency:

What you can do yourself

Smaller organisations with internal IT capacity can manage the following in-house: creating an asset inventory, basic risk classification, comparison against the NIS2 requirements checklist and preparation of an action plan. The following tools are used for this purpose:

Where you need an expert

There are areas where a DIY approach is insufficient and where an error can have legal consequences. We recommend expert assistance for:

How to get started today

A NIS2 audit need not be overwhelming if approached systematically. Begin with a scoping workshop (lasting 2–4 hours), proceed to an asset inventory, and then launch the free online audit on secureon.cz. nis2ok.czwhich will show you your biggest gaps in just 10 minutes.

SecureOn.cz offers both a standalone audit tool for self-assessment and full professional audits with a final report and recommendations. More information at secureon.cz secureon.cz.

Ready to start the audit?

A free online audit at nis2ok.cz will show you in 10 minutes where you stand and what needs to be done according to Act No. 264/2025 Coll.

Start a free audit →