NIS2 Audit Pack
A structured package of the NIS2 readiness work recorded in OTReady.
The Audit Pack exists to make a conversation with an auditor efficient: here is what was assessed, here is the evidence that was offered for each control, and here is what a reviewer concluded about it.
- Built from the submitted state, not from today's live answers
- Every evidence link carries its own review outcome
- Metadata about a document is not a claim about the document
This is not proof of NIS2 compliance.
The Audit Pack is a record of readiness work: what was assessed, what evidence was offered, and what was concluded. It is not a certificate, not an audit approval, and not a statement that an entity is NIS2 compliant. OTReady is not a certification body, and nothing in the pack should be presented as though it were an external assurance opinion.
What is in it
The submitted state, and the evidence behind it.
Contents follow the current export. The assessment side is read from the frozen submission rather than from live answers, so the pack describes what was actually submitted.
- Scope answers
- The scoping responses as they stood when the assessment was submitted.
- The frozen result
- The readiness result recorded at submission, read verbatim rather than recalculated.
- Evidence register
- Each artifact with its title, description, type, owner, version and approval date.
- Validity window
- The period an artifact covers, and its review or expiry date where one was recorded.
- Handling metadata
- Scope locations and confidentiality classification, plus file name, type and size.
- Upload checksum
- The checksum recorded when the file was uploaded: labelled as exactly that, and never presented as certified integrity proof.
- Control links
- Which controls each artifact was linked to, and when the link was made.
- Review outcome
- The review status per link, the level a reviewer verified it to, their explanation, and how long that verification is valid.
- Derived link state
- Whether a link is unreviewed, rejected, expired or usable: derived, and shown as the reason a piece of evidence does or does not count.

The assessment behind it
Evidence-gated, and honest about incompleteness.
NIS2 Full Readiness scores against evidence rather than assertion: what a control claims is capped by what has actually been supplied to support it. A policy statement cannot carry a claim that needs demonstrated operation.
That is why the pack is worth handing over. It shows not only the position, but what that position rests on, including where it rests on nothing yet.
Coming in a later phase
- NIS2 overview pagePlanned
- NIS2 Quick Scan and Full Readiness pagesPlanned
This page describes the report. The NIS2 modules themselves get their own pages later.
Related
Reports
The other report kinds, and issuance.
Findings & Evidence
How evidence artifacts and their contextual links work.
See what an auditor would actually receive.
Look at a generated Audit Pack, including the links a reviewer had already ruled on.