Main content

NIS2 gap analysis, in writing

Each NIS2 gap analysis checks the ten Article 21 measures against what runs today and returns a gap matrix, a fix list ordered by risk and an evidence index. Management gets decisions; the IT lead gets a work list.

The report, on one sheet

Measured against
The ten Article 21 measures
Main output
A gap matrix per measure
Fix list
By risk, with owners and dates
Evidence
What exists, what is missing
Certificate
None, NIS2 has none

What the report contains

Six parts for two readers: management, who approve, and the IT lead, who fixes.

FIG. 1The report, annotatedSchematic
The NIS2 gap analysis report as a document, annotated: scope and classification, a one-page summary for management, a gap matrix with one row per measure, a fix list ordered by risk with owners and dates, an evidence index and a reporting-readiness page. Delivered as editable documents in the company's own accounts.ScopeSummaryGap matrixFix listEvidenceReportingEditable

The six parts in full

Scope and classification
Sector, size, entity type, national registration duties, and the systems, sites and suppliers covered.
Summary for management
The position on one page, the main risks and the decisions the management body needs to take under Article 20.
Gap matrix
One row per Article 21 measure: current state, evidence found, gap and fix.
Fix list
Every fix ordered by risk, with an owner, an effort estimate and a target date.
Evidence index
What exists, where it lives, when it was last tested and what is still missing.
Reporting readiness
Who detects, who decides and who notifies within the Article 23 deadlines of 24 hours, 72 hours and one month.

Gap matrix, one example row

An example row from a fictional company.

Measure
MFA and secured communications
Current state
MFA on email; none on the VPN or the hosting console.
Evidence found
Identity provider policy export.
Gap
Two admin paths without a second factor.
Fix
Enforce MFA on the VPN and the hosting console; remove the shared admin account.
Owner and priority
IT lead, high.

NIS2 gap analysis checklist: 30 checks

Free for a first pass; the written analysis adds the technical checks.

Checks in placeDemo data

12of 30

Risk analysis and security policies

  • A risk register reviewed in the last 12 months
  • An information security policy approved by management
  • An inventory of systems, data and their owners

Incident handling

  • A written runbook with named roles and contacts
  • Logs that show who did what, kept long enough to investigate
  • A tested path for reporting to the national CSIRT within 24 hours

Business continuity and backups

  • Backups stored offsite and protected from deletion
  • A restore test on record, with date and result
  • A continuity plan for the systems the business cannot run without

Supply chain security

  • A list of suppliers with access to systems or data
  • Security terms in the contracts of critical suppliers
  • A record of supplier questionnaires sent and answered

Secure development and vulnerability handling

  • A patch process with target times per severity
  • Dependency scanning on every code change
  • A published contact for vulnerability reports

Effectiveness of the measures

  • Checks that run on a schedule
  • A record of findings and the date each one closed
  • A review of the fix list at set intervals

Cyber hygiene and training

  • A baseline configuration for laptops and phones
  • Security training records for staff and management
  • A password manager in use across the company

Cryptography

  • TLS on every public and internal service
  • Encryption at rest for databases, backups and laptops
  • A record of who holds which keys and certificates

HR security, access control and assets

  • Offboarding that closes every account on the last day
  • Access reviews for admin and production rights
  • Role-based access instead of shared accounts

MFA and secured communications

  • MFA on email, remote access and admin consoles
  • No shared admin accounts
  • A secured channel for incident communication when email is down

How the analysis runs

Duration is set in the quote, after the scope call.

  1. Scope

    Systems, sites and suppliers, agreed first.
  2. Interviews

    Management, the IT lead and process owners.
  3. Technical checks

    MFA, backups, logs, patches, supplier access.
  4. Written report

    Gap matrix, fix list, evidence index.
  5. Readout

    First fixes agreed with management.

Who runs the technical checks

The technical checks come from the studio that builds these controls into client systems such as Mozar, Rarău Rental and Muzeul Baia.

How ELASTO handles vulnerability reports as a software supplier is on the security and disclosure page.

After the report: fixes with ELASTO or with anyone

Any competent engineer can carry out the fix list, ELASTO included.

  • Editable documents, kept in the company's own accounts
  • Each fix names the system, the change and its evidence

Gap analysis and the NIS2 audit: two different jobs

A gap analysis prepares the company; an audit judges it. NIS2 lets authorities subject essential entities to security audits by an independent body, and national law decides who performs them. In Romania, only auditors attested by DNSC carry out the cybersecurity audit, and an auditor cannot audit a company it currently serves with security work.

ELASTO does not perform audits and issues no certificate. The gap analysis and the fixes produce the evidence the auditor asks for.

Purpose
Gap analysis: find the gaps and put them in order. Audit: judge compliance for the authority.
Performed by
Gap analysis: ELASTO, or any competent engineer. Audit: an independent auditor under national law; in Romania, attested by DNSC.
Output
Gap analysis: gap matrix, fix list, evidence index. Audit: an audit report for the company and the authority.
Timing
Gap analysis: before the audit, then repeated. Audit: periodic, or after a significant incident.

NIS2 gap analysis questions

Gap analysis contents, duration and price

A NIS2 gap analysis contains a scope statement, a gap matrix for the ten Article 21 measures, a fix list with owners and dates, an evidence index and a summary for management. Duration and price depend on the number of systems, sites and suppliers in scope, and both are set in writing after the scope call.

Dependence on ELASTO after the report

Nothing in a NIS2 gap analysis ties the company to ELASTO afterwards. The documents are editable, stay in the company's accounts and name the system, the change and the evidence for each fix, so the in-house team or another firm can carry out the work.

Significant incident and the 24-hour clock

A significant incident, under Article 23, has caused or can cause severe operational disruption or financial loss, or considerable damage to others. The 24-hour clock for the early warning starts when the company becomes aware of it, which can be later than the incident itself. The report's reporting-readiness part names who makes that call.

State of the art for a small or medium company

State of the art in Article 21 means measures that match current practice, weighed against cost, company size and risk. For a company of 50 to 250 people it usually means MFA everywhere, offsite backups with tested restores, central logs, a patch process and a supplier list, before any expensive tooling.

Gap analysis template or a written analysis

A gap analysis template, or the free checklist on this page, works for a first pass. The written analysis adds what a template cannot: technical checks on the real systems, evidence collected and indexed, and fixes ordered by risk with owners.

Existing ISO 27001 controls in the gap analysis

They count. The matrix maps each existing control and its evidence to the matching Article 21 measure, so only the real gaps stay on the fix list, typically the reporting deadlines, management training and supplier terms.

The gap analysis starts with a scope call

The call settles which systems, sites and suppliers the analysis covers.

Studio
Cluj-Napoca, Romania, EU