Skip to content

NIS2 Audit Pack

A structured package of the NIS2 readiness work recorded in OTReady.

The Audit Pack exists to make a conversation with an auditor efficient: here is what was assessed, here is the evidence that was offered for each control, and here is what a reviewer concluded about it.

  • Built from the submitted state, not from today's live answers
  • Every evidence link carries its own review outcome
  • Metadata about a document is not a claim about the document

This is not proof of NIS2 compliance.

The Audit Pack is a record of readiness work: what was assessed, what evidence was offered, and what was concluded. It is not a certificate, not an audit approval, and not a statement that an entity is NIS2 compliant. OTReady is not a certification body, and nothing in the pack should be presented as though it were an external assurance opinion.

What is in it

The submitted state, and the evidence behind it.

Contents follow the current export. The assessment side is read from the frozen submission rather than from live answers, so the pack describes what was actually submitted.

Scope answers
The scoping responses as they stood when the assessment was submitted.
The frozen result
The readiness result recorded at submission, read verbatim rather than recalculated.
Evidence register
Each artifact with its title, description, type, owner, version and approval date.
Validity window
The period an artifact covers, and its review or expiry date where one was recorded.
Handling metadata
Scope locations and confidentiality classification, plus file name, type and size.
Upload checksum
The checksum recorded when the file was uploaded: labelled as exactly that, and never presented as certified integrity proof.
Control links
Which controls each artifact was linked to, and when the link was made.
Review outcome
The review status per link, the level a reviewer verified it to, their explanation, and how long that verification is valid.
Derived link state
Whether a link is unreviewed, rejected, expired or usable: derived, and shown as the reason a piece of evidence does or does not count.
The OTReady NIS2 Full Readiness assessment, showing controls with their recorded answers and evidence state.
The assessment the pack is built from.

The assessment behind it

Evidence-gated, and honest about incompleteness.

NIS2 Full Readiness scores against evidence rather than assertion: what a control claims is capped by what has actually been supplied to support it. A policy statement cannot carry a claim that needs demonstrated operation.

That is why the pack is worth handing over. It shows not only the position, but what that position rests on, including where it rests on nothing yet.

Coming in a later phase

  • NIS2 overview pagePlanned
  • NIS2 Quick Scan and Full Readiness pagesPlanned

This page describes the report. The NIS2 modules themselves get their own pages later.

Related

See what an auditor would actually receive.

Look at a generated Audit Pack, including the links a reviewer had already ruled on.