7 Step NIS2 Gap Assessment for SMEs: Build an Audit Ready Register

A NIS2 gap assessment compares your current security controls against Articles 20, 21, and 23 of the directive, then flags every shortfall as a scored, owned action item. If you run an essential or important entity, this is the prerequisite that stops regulatory risk turning into a fine. Start now with a scoped self-assessment or a trusted template, not a full audit.


TL;DR:

  • Conduct a thorough asset inventory and map controls against the 10 Article 21 measures, prioritizing incident reporting and multi-factor authentication.
  • Confirm if you are an essential or important entity based on sector and size, as this affects supervision and reporting obligations.
  • Score each control's compliance impact and effort to build a phased remediation roadmap with clear owners, deadlines, and evidence requirements.
  • Regularly review and update the gap register every six months, ensuring evidence is collected at implementation, not after audit requests.
  • Use automation tools or platforms to streamline continuous monitoring, evidence management, and scoring, reducing manual workload and improving audit readiness.

Table of Contents

What is a NIS2 gap assessment and why start now?

A NIS2 gap assessment is a structured review that lines your organisation's existing controls up against three specific parts of Directive (EU) 2022/2555: Article 20 (management-body accountability), Article 21 (the ten risk management measures), and Article 23 (incident reporting obligations). The output is not a vague impression of "fairly secure." It is a row-by-row register showing which requirements you meet, which you partially meet, and which you miss entirely, each one tied to evidence, an owner, and a deadline.

Member states transposed NIS2 into national law by 17 October 2024, so the legal clock has already been running for some time. That does not mean the work is finished. Most SMEs discovered mid-2024 that they were newly in scope, ran a rushed initial review, and have not touched the register since. That is the gap this article closes: not "what is NIS2" but "how do you actually run the gap analysis properly, and keep it current."

Some readers will know this process by other names: a NIS2 readiness assessment, a compliance evaluation, or simply a cybersecurity gap assessment scoped to NIS2. They are the same exercise. What matters is the method, not the label.

Quick action checklist: what to do in the first 30 days

You do not need a finished compliance programme to start. You need thirty days of focused, sequenced work.

  • Confirm applicability. Check your sector against Annex I and Annex II, and your headcount and turnover against the essential/important thresholds, before you spend a single hour on controls.
  • Appoint a senior owner and brief the management body. Article 20 makes leadership personally accountable, so this cannot sit quietly with an IT administrator.
  • Start the asset inventory. List every system, data store, and network connection that touches your core service, then pick a self-assessment template or an online checker to structure the review.
  • Test your incident-reporting chain. Confirm you know your national CSIRT's contact details and can realistically detect and escalate an incident inside the required window.
  • Assign quick wins. Multi-factor authentication rollout, overdue policy sign-off, and access-review backlogs are the fastest points to close before the harder architectural gaps.

Pro Tip: Do the incident-reporting test in week one, not week four. If your team cannot say who calls the CSIRT and within what time, every other finding in your assessment is secondary.

Thirty days will not deliver full compliance, but it delivers a defensible starting position: a named owner, a scoped register, and proof that governance has engaged. That is precisely what a competent authority looks for first if it comes asking questions.

Who is in scope for NIS2 and how to determine it?

NIS2 applies by sector first, then by size. Annex I cover "highly critical" sectors, including energy, transport, banking, health, drinking water, and digital infrastructure. Annex II covers "other critical" sectors such as postal services, waste management, chemicals, food production, and manufacturing of specific goods. If your organisation sits in neither annex, you are very likely out of scope regardless of size, though sector-specific national rules can still pull you in.

Size thresholds then decide whether you are an essential entity or an important entity:

  • Essential entities are generally larger organisations in the higher-criticality sectors, typically 250+ employees or €50 million+ annual turnover, plus some entities designated essential regardless of size (qualified trust service providers, certain telecoms operators).
  • Important entities are typically medium-sized organisations, generally 50 to 249 employees or €10 million to €50 million turnover, operating in either annex's sectors.
  • Micro and small entities are usually exempt, though some member states extend obligations to smaller suppliers of critical services.

The distinction is not cosmetic. Essential entities face proactive supervision, meaning a competent authority can audit you without waiting for an incident. Important entities are typically supervised reactively, checked only after a report or complaint. Both categories face the same Article 21 and Article 23 obligations; only the intensity of oversight differs.

Because transposition varies by member state, confirm your exact status against your own country's implementing law and its designated competent authority, not against a generic EU summary. If you supply services to an essential entity, check your contract too. Supply-chain clauses under Article 21(d) can pull suppliers into de facto compliance even when they sit outside the annexes.

Who is in scope for NIS2 and how to determine it? — overview diagram

Step-by-step NIS2 gap assessment methodology

A gap assessment done properly follows a fixed sequence. Skip a step and the whole register loses credibility, because gaps get scored against controls nobody has actually verified. The seven-step method below tracks closely with what leading NIS2 readiness guides recommend, and it scales down comfortably for a team of one compliance lead and a part-time IT administrator.

1. Confirm scope and entity status

Before touching a single control, settle whether you are essential or important, and which national authority supervises you. This single decision determines your evidence burden for every step that follows.

2. Build the asset and process inventory

List every system, application, network segment, and third-party service that supports your core service delivery. Include data flows, not just hardware. An incomplete inventory is the single most common reason gap assessments understate real exposure, because you cannot assess the security of an asset you never listed.

3. Map the ten Article 21 measures against your controls

Article 21(2) sets out ten mandatory measures. Work through each one and mark it as met, partially met, or missing:

  1. Risk analysis and information system security policy — do you have a written, board-approved policy, reviewed within the last twelve months?
  2. Incident handling — is there a documented detection-to-escalation procedure with named responders?
  3. Business continuity and crisis management — do backup, disaster recovery, and crisis communication plans exist and get tested?
  4. Supply chain security — do supplier contracts include security clauses, and have critical vendors been assessed?
  5. Security in acquisition, development, and maintenance — is there a secure development lifecycle or equivalent for any in-house systems?
  6. Policies to assess the effectiveness of measures — do you audit or test controls, rather than just documenting them?
  7. Basic cyber hygiene and training — is security awareness training mandatory and refreshed annually?
  8. Cryptography and encryption policies — is data encrypted at rest and in transit according to a documented standard?
  9. Human resources security, access control, and asset management — are joiner, mover, and leaver processes enforced, with access reviewed periodically?
  10. Multi-factor authentication and secure communications — is MFA mandatory for all remote and privileged access?

Guidance for supplier and supply-chain controls under measure four is worth a dedicated pass, since it is the measure SMEs most often leave unassessed.

4. Check incident-reporting readiness against Article 23

Article 23 sets timeframes for incident reporting including an early warning, a notification, and a final report, each with legally mandated timelines that must be tested for compliance. Test whether your organisation could actually hit these, not whether a policy document says you should. A detailed incident-reporting walkthrough helps here, because the 24-hour window is usually the binding constraint in real audits, tighter than most SMEs' existing detection capability.

5. Collect evidence for every control

For each of the ten measures, gather the policy document, proof of implementation, and, where possible, proof of effectiveness. A control marked "met" with no supporting file is not evidence, it is an assertion.

6. Score every gap and rank it

Rate each finding by impact and effort (covered in detail in the next section) to produce a ranked list rather than a flat inventory of problems.

7. Build the remediation roadmap, then verify and repeat

Convert the ranked list into a roadmap with owners, budgets, and deadlines, then schedule a follow-up review. A gap assessment run once and filed away is worse than no assessment at all, because it creates a false sense of closure.

A realistic calendar for an SME running this internally looks like: week 1 to 2 for scope and inventory, week 3 to 4 for the Article 21 mapping and evidence collection, week 5 for scoring and roadmap drafting, and week 6 for management-body sign-off. Larger or more complex organisations should expect eight to ten weeks.

Six-week NIS2 assessment timeline

Scoring, prioritisation and building the remediation roadmap

A gap list with no ranking is just a longer to-do list. Score each finding on two axes: impact, meaning the regulatory or operational damage the gap creates if left open, and effort, meaning the cost, time, and organisational disruption to close it.

Use simple scales rather than elaborate models. A 1 to 4 scale for both works well for SMEs:

  • Impact 4 (critical): no incident-reporting capability, or no MFA on privileged access.
  • Impact 3 (high): missing supplier security assessments, no business continuity plan.
  • Impact 2 (medium): outdated policy documents, incomplete training records.
  • Impact 1 (low): cosmetic documentation gaps with no operational exposure.
  • Effort 1 (low): enabling MFA, updating a policy template.
  • Effort 4 (high): replacing legacy infrastructure, renegotiating supplier contracts.

Multiply impact by effort inverted (high impact, low effort rises to the top) to produce four rough buckets: critical, high, medium, and low priority. Readiness guides commonly recommend phasing remediation across a twelve-month window, and the structure below is a sensible default:

  • 0 to 3 months: close every critical finding, especially anything touching Article 23 incident reporting or MFA.
  • 3 to 6 months: work through high-priority items, typically supply-chain and business continuity gaps.
  • 6 to 9 months: address medium-priority items such as training refreshes and policy reviews.
  • 9 to 12 months: clear low-priority documentation and process polish.

**A well-structured, countable register with named owners and due dates measurably speeds up management-body sign-off, because leadership can see progress in a single glance rather than trawling narrative reports. That single change, from prose findings to a scored spreadsheet, is often what turns a stalled remediation effort into a funded one.

Budget estimation should follow the same phasing. Critical items usually need modest, fast spend (MFA licensing, a policy-drafting sprint). Medium and low items can often be absorbed into existing IT budgets rather than requiring a separate business case. Present the roadmap to your management body as a phased investment, not a single lump request. It reads as more credible and is easier to approve in stages.

Evidence, documentation and what supervisors will check

Competent authorities do not take your word for a control's existence. They expect a three-tier evidence model behind every row in your gap register: policy or procedure (the written rule), implementation proof (screenshots, configuration exports, signed sign-off logs), and effectiveness proof (test results, audit logs, incident drill records).

Control area Policy/procedure evidence Implementation proof Effectiveness proof
Access control Written access-control policy User access list with role mapping Quarterly access review log
MFA MFA policy document Configuration export showing enforcement Login logs showing MFA challenge rate
Incident handling Incident response plan Named responder roster Tabletop exercise report
Supplier security Supplier security policy Signed supplier questionnaires Supplier audit or assessment scorecard
Training Training policy Completion records Post-training phishing test results

Each evidence item should link back to a specific requirement row in your register, not float loose in a shared folder. This traceability is what separates an audit-ready evidence pack from a pile of documents nobody can quickly justify. Version control matters too: date every policy, log every review, and keep a change history. A policy last reviewed three years ago, however well written, tells a supervisor the control is not actively managed.

Tools, templates and resources to run a gap assessment

Most SMEs start with a free template rather than commissioning bespoke work, and that is a sensible starting point. A well-built NIS2 gap assessment template in Excel typically includes a register sheet with one row per obligation, a scoring summary, and a how-to guide explaining each column. Similar downloadable registers, such as Ansvar's XLSX quick-register, pair each Article 21 measure with a verdict dropdown, an evidence field, and owner columns, which makes the register genuinely countable rather than a wall of text.

The core trade-off is privacy versus reporting depth:

  • Offline XLSX templates keep everything on your own infrastructure, which suits organisations wary of uploading security posture data to a third-party server.
  • Online SaaS checkers, such as a self-serve NIS2 compliance checker that maps controls and exports a PDF gap report, trade a little data exposure for automated scope determination and faster reporting.
  • Curated resource kits, including aggregated free assessment tools and checklists, suit teams who want several starting templates to compare before committing to one structure.

Choose based on your team's capacity, not just cost. A spreadsheet is free but demands someone disciplined enough to keep it current. An online tool costs little or nothing at entry level but assumes you are comfortable with cloud-based scoring. If your organisation has no dedicated security resource at all, or you are heading towards an external audit, consider bringing in external assessors or an audit-readiness service rather than stretching a part-time IT lead across the full process.

Common mistakes and practical guardrails

The same handful of errors show up across most NIS2 gap-assessment audits, and each one is avoidable.

  • Treating the assessment as one-off. A register filed away after the first review goes stale within months. Fix this by scheduling a mandatory review every six months, or immediately after any material change to systems or suppliers.
  • Confusing gap analysis with risk assessment. A gap analysis tells you what is missing against the directive's requirements; a risk assessment tells you how likely and damaging an exploited gap would be. They produce different outputs and both are needed, but do not let one substitute for the other.
  • Failing to evidence controls that genuinely exist. Audit experience consistently shows organisations with reasonable controls still failing reviews because nobody captured proof. Capture evidence at the point of implementation, not retroactively when an audit is announced.
  • Ignoring supplier obligations and management-body duties. Article 21(d) and Article 20 are frequently the last items checked and the first ones missed. Build supplier due diligence and board briefings into the same cadence as your technical control reviews, not as an afterthought.

Pro Tip: Underestimating supply-chain requirements is one of the most cited pitfalls in gap-assessment audits. Add a supplier security questionnaire to your register before your next review, even if you think your vendors are low-risk.

How an AI-powered GRC platform can speed assessments

Running the seven-step methodology manually works, but it consumes real hours: inventory building, control mapping, evidence chasing, and roadmap drafting all compete with a compliance lead's other duties. This is the exact gap a governance, risk, and compliance platform is built to close.

A governance, risk, and compliance platform can run automated assessments with built-in scoring and gap analysis across NIS2 and related frameworks, so the ten Article 21 measures and Article 23 reporting checks are mapped rather than built from scratch in a spreadsheet. AI-driven policy drafting shortens the "write the missing document" step that stalls most manual assessments, and a centralised dashboard keeps controls, risks, vendors, assets, and evidence in one place rather than scattered across shared drives.

  • Limited internal resource: a platform structures the register and scoring automatically, so a single compliance lead is not building the framework from a blank sheet.
  • Continuous monitoring: deadline tracking and status updates replace the "review it every six months if we remember" habit that causes registers to go stale.
  • Audit packaging: centralised evidence management turns scattered proof into a traceable, exportable bundle when a supervisor asks for it.

Automation speeds up mapping, scoring, and evidence organisation. It does not replace the judgement calls: which supplier relationships matter, how much risk the board is willing to accept, and when a gap is genuinely closed. Those decisions stay with your governance team, not the software.

Author perspective: candid advice from a practitioner

Two things stand out after watching SMEs work through NIS2 assessments. The first is that the technical gaps are rarely the hard part. MFA rollout and encryption policies are solvable in weeks. The genuine bottleneck is governance: getting a management body that has never engaged with cybersecurity to sit through a briefing, understand Article 20's personal accountability, and actually approve a budget. Secure that buy-in in week one, not week six, because every remediation item downstream needs their sign-off eventually.

The second lesson is less comfortable. Organisations that treat the gap assessment as a one-time compliance exercise, do it once, file the spreadsheet, move on, are the ones that fail supervisory reviews years later. The requirement was never "assess once." It was "know your posture continuously." A template run every six months beats a perfect assessment run once and forgotten.

If there is one piece of advice worth repeating, it is this: use a proper template from day one, however basic, rather than a narrative report nobody can score. A countable register is what turns a compliance conversation into a project plan.

— Matthew Lemon

How ShieldIQ can help you close the gap faster

If the seven-step methodology above sounds sound but exhausting to run manually every six months, using an automated platform can absorb that workload. Such a platform combines automated assessments with scoring and gap analysis across NIS2, GDPR, ISO 27001, DORA, and the EU AI Act, so instead of maintaining separate spreadsheets for each framework, teams can work from one centralised dashboard covering controls, risks, vendors, assets, incidents, and DPIAs.

ShieldIQ

For a growing SME, the practical advantage is speed without hiring a dedicated security team: AI-driven policy drafting fills documentation gaps, automated scoring keeps your remediation roadmap current without manual recalculation, and centralised evidence management means an audit request does not trigger a scramble across shared drives. If you would rather talk through specific gaps with a person first, ShieldIQ's consulting and vCISO services support remediation and audit preparation directly.

Start by reviewing ShieldIQ's NIS2 compliance page to see how the platform maps to your entity's obligations, then request a demo to see your own gap register scored automatically rather than built by hand.

Sources

Recommended