NIS2 gap analysis, in writing
Each NIS2 gap analysis checks the ten Article 21 measures against what runs today and returns a gap matrix, a fix list ordered by risk and an evidence index. Management gets decisions; the IT lead gets a work list.
The report, on one sheet
- Measured against
- The ten Article 21 measures
- Main output
- A gap matrix per measure
- Fix list
- By risk, with owners and dates
- Evidence
- What exists, what is missing
- Certificate
- None, NIS2 has none
What the report contains
Six parts for two readers: management, who approve, and the IT lead, who fixes.
The six parts in full
- Scope and classification
- Sector, size, entity type, national registration duties, and the systems, sites and suppliers covered.
- Summary for management
- The position on one page, the main risks and the decisions the management body needs to take under Article 20.
- Gap matrix
- One row per Article 21 measure: current state, evidence found, gap and fix.
- Fix list
- Every fix ordered by risk, with an owner, an effort estimate and a target date.
- Evidence index
- What exists, where it lives, when it was last tested and what is still missing.
- Reporting readiness
- Who detects, who decides and who notifies within the Article 23 deadlines of 24 hours, 72 hours and one month.
Gap matrix, one example row
An example row from a fictional company.
- Measure
- MFA and secured communications
- Current state
- MFA on email; none on the VPN or the hosting console.
- Evidence found
- Identity provider policy export.
- Gap
- Two admin paths without a second factor.
- Fix
- Enforce MFA on the VPN and the hosting console; remove the shared admin account.
- Owner and priority
- IT lead, high.
NIS2 gap analysis checklist: 30 checks
Free for a first pass; the written analysis adds the technical checks.
12of 30
Risk analysis and security policies
- A risk register reviewed in the last 12 months
- An information security policy approved by management
- An inventory of systems, data and their owners
Incident handling
- A written runbook with named roles and contacts
- Logs that show who did what, kept long enough to investigate
- A tested path for reporting to the national CSIRT within 24 hours
Business continuity and backups
- Backups stored offsite and protected from deletion
- A restore test on record, with date and result
- A continuity plan for the systems the business cannot run without
Supply chain security
- A list of suppliers with access to systems or data
- Security terms in the contracts of critical suppliers
- A record of supplier questionnaires sent and answered
Secure development and vulnerability handling
- A patch process with target times per severity
- Dependency scanning on every code change
- A published contact for vulnerability reports
Effectiveness of the measures
- Checks that run on a schedule
- A record of findings and the date each one closed
- A review of the fix list at set intervals
Cyber hygiene and training
- A baseline configuration for laptops and phones
- Security training records for staff and management
- A password manager in use across the company
Cryptography
- TLS on every public and internal service
- Encryption at rest for databases, backups and laptops
- A record of who holds which keys and certificates
HR security, access control and assets
- Offboarding that closes every account on the last day
- Access reviews for admin and production rights
- Role-based access instead of shared accounts
MFA and secured communications
- MFA on email, remote access and admin consoles
- No shared admin accounts
- A secured channel for incident communication when email is down
How the analysis runs
Duration is set in the quote, after the scope call.
Scope
Systems, sites and suppliers, agreed first.Interviews
Management, the IT lead and process owners.Technical checks
MFA, backups, logs, patches, supplier access.Written report
Gap matrix, fix list, evidence index.Readout
First fixes agreed with management.
Who runs the technical checks
The technical checks come from the studio that builds these controls into client systems such as Mozar, Rarău Rental and Muzeul Baia.
How ELASTO handles vulnerability reports as a software supplier is on the security and disclosure page.
After the report: fixes with ELASTO or with anyone
Any competent engineer can carry out the fix list, ELASTO included.
- Editable documents, kept in the company's own accounts
- Each fix names the system, the change and its evidence
Gap analysis and the NIS2 audit: two different jobs
A gap analysis prepares the company; an audit judges it. NIS2 lets authorities subject essential entities to security audits by an independent body, and national law decides who performs them. In Romania, only auditors attested by DNSC carry out the cybersecurity audit, and an auditor cannot audit a company it currently serves with security work.
ELASTO does not perform audits and issues no certificate. The gap analysis and the fixes produce the evidence the auditor asks for.
- Purpose
- Gap analysis: find the gaps and put them in order. Audit: judge compliance for the authority.
- Performed by
- Gap analysis: ELASTO, or any competent engineer. Audit: an independent auditor under national law; in Romania, attested by DNSC.
- Output
- Gap analysis: gap matrix, fix list, evidence index. Audit: an audit report for the company and the authority.
- Timing
- Gap analysis: before the audit, then repeated. Audit: periodic, or after a significant incident.
NIS2 gap analysis questions
Gap analysis contents, duration and price
A NIS2 gap analysis contains a scope statement, a gap matrix for the ten Article 21 measures, a fix list with owners and dates, an evidence index and a summary for management. Duration and price depend on the number of systems, sites and suppliers in scope, and both are set in writing after the scope call.
Dependence on ELASTO after the report
Nothing in a NIS2 gap analysis ties the company to ELASTO afterwards. The documents are editable, stay in the company's accounts and name the system, the change and the evidence for each fix, so the in-house team or another firm can carry out the work.
Significant incident and the 24-hour clock
A significant incident, under Article 23, has caused or can cause severe operational disruption or financial loss, or considerable damage to others. The 24-hour clock for the early warning starts when the company becomes aware of it, which can be later than the incident itself. The report's reporting-readiness part names who makes that call.
State of the art for a small or medium company
State of the art in Article 21 means measures that match current practice, weighed against cost, company size and risk. For a company of 50 to 250 people it usually means MFA everywhere, offsite backups with tested restores, central logs, a patch process and a supplier list, before any expensive tooling.
Gap analysis template or a written analysis
A gap analysis template, or the free checklist on this page, works for a first pass. The written analysis adds what a template cannot: technical checks on the real systems, evidence collected and indexed, and fixes ordered by risk with owners.
Existing ISO 27001 controls in the gap analysis
They count. The matrix maps each existing control and its evidence to the matching Article 21 measure, so only the real gaps stay on the fix list, typically the reporting deadlines, management training and supplier terms.
The gap analysis starts with a scope call
The call settles which systems, sites and suppliers the analysis covers.
- Studio
- Cluj-Napoca, Romania, EU