NIS2 compliance evidence: what to keep if supervisors move from guidance to inspections
As the first NIS2 deadlines pass, supervisors can check what organizations implemented. Here is the evidence to keep for each area, and how to make its date verifiable.
Updated on
NIS2 compliance evidence is the dated, intact record that a security measure was in place, or an incident was handled, when the Directive required it. Under Article 32 of Directive (EU) 2022/2555, authorities can ask essential entities for evidence that cybersecurity policies have been implemented. A record you can’t date, or can’t show is unchanged, is hard to rely on in an inspection.
Key takeaways
- Under Article 32 of Directive (EU) 2022/2555, authorities can inspect essential entities on site and remotely, run audits and request evidence that cybersecurity policies have been implemented.
- Important entities are supervised ex post under Article 33 of the NIS2 Directive, when the authority receives evidence or indications of possible non-compliance.
- In Italy, entities listed in 2025 must have baseline security measures in place by October 2026, 18 months after notification of inclusion (ACN NIS Vademecum, September 2026).
- Article 23 of the NIS2 Directive sets an early warning within 24 hours, a notification within 72 hours and a final report within one month: each step needs a provable time.
- Screenshots, exported logs and editable minutes rarely prove their own date or integrity; ISO/IEC 27037 guidelines tie digital evidence to a documented acquisition and preserved integrity.
20,000+
organizations on Italy’s NIS list, more than 5,000 of them essential
ACN, April 15, 2025 (source)
4,875
incidents analyzed in the EU between July 2024 and June 2025
ENISA Threat Landscape 2025, October 1, 2025 (source)
60%
share of initial intrusions that started with phishing
ENISA Threat Landscape 2025, October 1, 2025 (source)
For two years, organizations in scope of NIS2 have done the groundwork: registration, contacts, policies, baseline measures. Authorities spent that time explaining. Italy’s cybersecurity agency, ACN, calls it a collaborative path, and its supervision FAQ says support comes before, and independently of, inspection powers.
For the entities listed earliest, that period is closing. Italian entities listed in 2025 must have their baseline security measures in place by October 2026, 18 months after they were notified of their inclusion. Past that point, an inspection asks when the measure went live and whether the record has stayed intact since. Exported logs, screenshots and minutes in a shared folder can’t answer that alone.
So collect your NIS2 compliance evidence when measures go live and incidents happen, one file per measure, incident and supplier, with a date and integrity a third party can check.
What changes when NIS2 supervision moves from guidance to verification
Once baseline deadlines pass, supervisors can test what you implemented in addition to supporting you.
As baseline deadlines expire, existing verification powers become fully usable. This is our reading, not an ACN announcement. Directive (EU) 2022/2555 already gives authorities inspections, audits and requests for evidence (Article 32), and in Italy, according to the ACN NIS Vademecum of September 2026, entities listed in 2025 must have baseline measures in place by October 2026.
ACN has not announced an inspection campaign. The point is timing: existing powers become fully usable once the obligations they check fall due.
Italy as an example of a national authority reaching its deadline
When ACN began notifying entities in April 2025, its list counted over 20,000 organizations, more than 5,000 of them essential. Under the Vademecum, entities listed in 2025 have reported significant incidents since January 2026.
On September 18, 2026, ACN opened a consultation on reinforced security measures meant to supplement and replace the baseline ones. ACN describes supervision as gradual and risk-based, but a gradual approach does not mean the powers go unused.
What supervisors can already do under Articles 32 and 33
Article 32 of the Directive covers essential entities: on-site and remote inspections with random checks, regular, targeted and ad hoc audits, security scans, requests for information and documents, and requests for evidence of implemented cybersecurity policies. None of it needs a prior incident.
Article 33 covers important entities, and supervision there is ex post: the authority acts on evidence, indications or information of possible non-compliance. By then, what the entity can show is whatever it recorded beforehand.
Why inspections test proof, not declarations
An inspector weighs a document by whether its date and integrity can be shown, whatever it looks like.
A piece of NIS2 compliance evidence proves a measure when you can show when it was produced and that it hasn’t changed since. The same idea underlies ISO/IEC 27037, the international guidelines for identifying, collecting, acquiring and preserving digital evidence: a documented acquisition method, then integrity preserved from that moment on.
The stakes are personal: under Article 20, management bodies approve the risk-management measures, oversee them and can be held liable for infringements.
Where screenshots, exported logs and unsigned minutes fall short
A screenshot takes its date from the device clock, can be edited and doesn’t show whether the page was live. An exported log is usually a CSV that anyone with access can change, and the export date says nothing about when the events happened. Minutes in a word-processing file change metadata at every save.
Each file may be accurate, but nothing in it lets a third party check, so the inspector has to take your word.
Which NIS2 compliance evidence to keep for each area
Each area of NIS2 has a natural moment of capture: when the decision is taken, when the measure goes live, while the incident is happening.
NIS2 compliance evidence falls into four families mapped to the Directive: governance (Article 20), cybersecurity risk-management measures (Article 21), incident reporting (Article 23) and supply chain security (Article 21(2)(d)). Each needs records whose date and integrity can be verified.
| Area | Evidence | When to capture it | How to make it verifiable |
|---|---|---|---|
| Governance (Art. 20) | Board resolution approving risk-management measures, training attendance | On approval, after each training session | Certify the signed file, dated at certification |
| Policies and risk analysis (Art. 21) | Approved security policies, risk assessment, asset register | On approval and at each revision | File certification of each approved version |
| Technical measures (Art. 21) | MFA settings, backup jobs, patch and vulnerability status in admin consoles | The day the measure goes live, then at each change | Forensic acquisition of the console page, sealed and timestamped |
| Incidents (Art. 23) | Timeline, screens of affected systems, early warning, notification, final report | While the incident unfolds and at each reporting deadline | Certified screen recording, file certification of each report as sent |
| Suppliers (Art. 21(2)(d)) | Security clauses, supplier attestations, supplier portal status | At onboarding and at each renewal | Guided certified acquisition by the supplier, forensic capture of supplier portals |
| Physical sites | Photos of server rooms, backup media, site inspections | During the visit | Live photo capture with time, and location when the flow requires it |
Governance and policies
Keep the resolution approving the measures, every revision and proof that board members followed the training Article 20 requires. A certified copy shows the document existed in that form on that day.
Technical measures: configurations, MFA, backups and vulnerability handling
Article 21(2) sets a minimum list that includes backup management, vulnerability handling, access control, cryptography and multi-factor authentication. These NIS2 Article 21 measures are easy to check against a live system. The ENISA Threat Landscape 2025, based on 4,875 incidents between July 2024 and June 2025, found phishing behind around 60% of initial intrusions and vulnerability exploitation behind 21.3%. MFA and patching target those entry points, so capture the console showing each setting on the day it took effect.
Incidents: timeline and reports
Article 23 sets the sequence: early warning within 24 hours, incident notification within 72 hours, final report within one month of the notification. You need to prove what you saw and when, and that each report left on time. Record affected systems while the incident is visible and keep each report as sent.
Suppliers and the supply chain
Article 21(2)(d) brings supply chain security into scope, including relationships with direct suppliers. Gather scattered supplier evidence into one file per supplier, with a data audit trail showing when each attestation arrived and in what form.
How to build an evidence file before the inspector asks
A defensible file of NIS2 compliance evidence is built as you go, one folder per measure, incident and supplier, each item dated at capture.
An evidence file for NIS2 is a set of records, each tied to an obligation, captured when the underlying fact happened and stored so its integrity can be checked without trusting whoever hands it over.
-
Map each measure to its evidence
List every measure adopted under Article 21 and the NIS2 compliance evidence that proves it: a configuration page, a signed resolution, a backup report. Add an owner and the event that triggers a capture.
-
Capture evidence when the measure goes live
Capture the live system with a forensic method on the day MFA is enforced, a backup policy starts or a vulnerability is patched. Repeat at every material change so the file shows history.
-
Document incidents while they unfold
Start recording when an incident is declared, capture the dashboards and alerts, and certify each report as it goes out. Article 23 starts the clock when you become aware of a significant incident, and a timeline built in real time holds up better than one rebuilt from memory.
-
Store the file so a third party can verify it
Keep the originals alongside their integrity data: hashes, seal and timestamp. A reviewer should be able to confirm independently that nothing changed, which is the logic of a digital chain of custody from capture to presentation.
How can TrueScreen make the date and integrity of NIS2 compliance evidence verifiable?
TrueScreen certifies evidence when it is collected, so anyone can check its date and integrity later.
TrueScreen, the Data Authenticity Platform, supports NIS2 integrity and traceability obligations with certified data. It acquires consoles, web pages, screens and photos with a forensic methodology that follows ISO/IEC 27037 guidelines, certifies existing files from the moment of certification, and every certification carries a qualified electronic seal and a qualified timestamp, qualified under eIDAS. The acquisition process is designed to prevent tampering, and later alterations are detectable.
Consoles and web pages: Forensic Browser and Browser Extension
The Forensic Browser is a desktop application for macOS and Windows suited to admin consoles, SaaS dashboards and supplier portals. Its package records the page, the network traffic where captured and a clock check, with the fingerprint of every file. Files downloaded in the same session are certified too. For quicker captures, use the Browser Extension for Chrome and Edge. More on web page certification with legal value.
Screens, files and site photos: Portal and TrueScreen App
For business applications and desktop clients, use screen recording in the Portal on a computer, or the TrueScreen App on phones. A certified screen recording of a restore test keeps the sequence intact. Policies, board resolutions, registers and exported logs can be certified as files in the Portal or the App, dated from the moment of certification rather than file creation. For site inspections, the App captures photos live, with time, and location when the flow requires it.
Suppliers and third-party verification: TrueFlow and the public verifier
TrueFlow guides a third party, such as a supplier, through a certified acquisition from a link, even without an account if the TrueFlow does not require a login. Each package contains the report and the original files. The public verifier recalculates SHA-256 hashes in the browser without uploading anything, while validating the certificate against EU trust lists is done separately with the European Commission’s DSS validator. Under eIDAS, the qualified electronic seal is defined in Article 3(27) and the qualified timestamp in Article 3(34).
An example: proving when MFA went live
A security team enforces MFA on administrator accounts. That day, the CISO acquires the identity provider’s console with the Forensic Browser and files the sealed package as NIS2 compliance evidence for that measure. A year later, the package shows MFA was active that day and the evidence hasn’t changed. A certified configuration proves how and when it was captured, not that the measure is adequate or compliant: that judgment stays with you and your supervisor. Certification does not replace legally compliant long-term preservation or the incident notification to the authority, which remain the entity’s responsibility.
Conclusion
NIS2 inspections look at records, not intentions. Whether a supervisor arrives on a random check or after an incident, what you can show is what you captured at the time, with a date and integrity that someone outside your organization can verify. A file built measure by measure, incident by incident and supplier by supplier, from the day each fact happens, is far easier to defend than one assembled under pressure. It will not settle whether a measure is adequate, which remains a judgment for you and your supervisor, but it settles when the measure existed and what it looked like.
This article is for information only and is not legal advice: which measures and obligations apply to a specific entity should be assessed with a qualified professional.
FAQ: common questions about NIS2 compliance evidence
What evidence can NIS2 supervisors ask for?
Under Article 32 of Directive (EU) 2022/2555, authorities can subject essential entities to on-site and remote inspections, random checks, security audits and scans, requests for information, access to data and documents, and requests for evidence that cybersecurity policies have been implemented. Important entities are supervised ex post under Article 33, on indications of possible non-compliance.
Can a screenshot or exported log count as NIS2 compliance evidence?
A screenshot or exported log can support your account but rarely proves anything alone: its date comes from a device clock or an export, and the file can be edited. To carry weight in an inspection, a record has to show when it was produced and that it hasn’t changed since, the basis of digital evidence in the ISO/IEC 27037 guidelines.
How do you prove the date and integrity of NIS2 compliance evidence?
Capture the evidence with a forensic method when the fact occurs, then seal it with a qualified timestamp and a qualified electronic seal, as defined in eIDAS Article 3(34) and 3(27). TrueScreen certifies consoles, screens and photos this way, and certifies existing files from the moment of certification, and a third party can check the resulting package with its public verifier.
What are the maximum fines under NIS2?
Article 34 of Directive (EU) 2022/2555 requires Member States to set maximum fines of at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher, for essential entities. For important entities the floor is EUR 7 million or 1.4% of worldwide annual turnover. National laws set the exact amounts and procedures.
Is there a NIS2 certification?
The NIS2 Directive doesn’t create a certificate declaring an organization NIS2 compliant. Compliance is assessed by the national competent authority through supervision under Articles 32 and 33, on the evidence the organization can produce. TrueScreen doesn’t issue any NIS2 certification: it certifies individual pieces of evidence. More on data integrity under NIS2.
Sources and verification
Every figure and principle cited here links to its source, listed with type and date. Links checked on the publication date.
| Source | Type | Date | What it supports |
|---|---|---|---|
| Directive (EU) 2022/2555 (NIS2), Article 20 | Law | 2022 | Governance: management bodies approve and oversee measures, training, liability |
| Directive (EU) 2022/2555 (NIS2), Article 21 | Law | 2022 | Cybersecurity risk-management measures, including supply chain security (21(2)(d)) |
| Directive (EU) 2022/2555 (NIS2), Article 23 | Law | 2022 | Reporting deadlines: 24 hours, 72 hours, one month |
| Directive (EU) 2022/2555 (NIS2), Article 32 | Law | 2022 | Supervisory powers over essential entities, including requests for evidence of implementation |
| Directive (EU) 2022/2555 (NIS2), Article 33 | Law | 2022 | Ex post supervision of important entities |
| Directive (EU) 2022/2555 (NIS2), Article 34 | Law | 2022 | Maximum administrative fines for essential and important entities |
| ACN, NIS Vademecum: general guidance and compliance calendar, v1.0 | Document | 09/2026 | Italian deadlines: incident notification from January 2026, baseline measures by October 2026 for entities listed in 2025 |
| ACN, FAQ on monitoring, supervision and enforcement | Document | 2026 | Support before inspection powers, gradual risk-based approach, ex ante and ex post supervision |
| ACN, NIS: second phase started | Survey | 15/04/2025 | Over 20,000 organizations on the NIS list, more than 5,000 essential |
| ACN, news for NIS entities: list updated, consultation on reinforced measures | Document | 18/09/2026 | Consultation on reinforced security measures supplementing and replacing baseline measures |
| ENISA Threat Landscape 2025, press release | Survey | 01/10/2025 | 4,875 incidents analyzed; phishing 60% and vulnerability exploitation 21.3% of initial intrusions |
A NIS2 evidence file an inspector can verify
Admin consoles, web pages and screen recordings are acquired with a forensic methodology, files are certified when they are collected, and the package can be verified without TrueScreen.
TrueScreen editorial team
This section is edited by the TrueScreen editorial team, which brings together expertise in digital forensics, the law of digital evidence and regulatory compliance. Every article is checked against primary sources: legislation, published rulings, technical standards and official documentation, always cited in the text.
