Supervisors and chain partners increasingly ask for NIS2-specific evidence — alongside your ISO 27001 certificate. Where ISO yields a certificate, NIS2 does not: you must be able to demonstrate compliance on request. A readiness file that bundles scope, governance, incident processes and your chain register into one set prepares you for supervision and for your customers’ supplier reviews.
Why a separate file?
Your ISMS already contains most of it, but spread across documents. If a supervisor or large customer calls tomorrow, you do not want to search for hours. A readiness file is a curated selection that specifically answers the NIS2 questions: am I in scope, how is the board involved, how do I report incidents, and how do I manage my chain? It is not a new management system, but a presentation layer over your existing ISMS.
The contents of the readiness file
- Scope determination: are you an essential or important entity, which services and entities are in scope, and the justification for it.
- Board: the mandate and involvement of management, evidence of board training, and the minutes of your management review.
- Incident: your incident playbook, evidence of exercises (such as tabletops), and your notification register.
- Chain: your vendor register with tiering and the relevant contract SLAs.
- Controls: a mapping of the NIS2 measures to your ISO 27001 controls and SoA, showing you do nothing twice but cover everything.
Link it to your NIS2 hub and your audit preparation.
The mapping is your biggest time saver
The most important part is the NIS2 ↔ ISO 27001 mapping. Many NIS2 requirements — risk management, incident handling, business continuity, supplier security — map directly to Annex A controls you already have. By making that link explicit, you show in a single table that your NIS2 coverage flows from your existing ISMS. That saves work and prevents you maintaining two separate systems.
The board takes centre stage
Unlike ISO, under NIS2 the board’s responsibility is explicit and personal. Supervisors want to see that the board is trained, knows the risks and demonstrably takes decisions. Make sure your readiness file contains evidence of board involvement: a signed mandate, a training record, and management decisions from your management review. This is often the part organisations underestimate.
Keep it a living document
Supervision does not want a one-off gap analysis from 2024, but a file that moves with you. Put a version number and date on the cover and update it at least quarterly: new incidents, changed suppliers, adjusted scope. A dated, current file radiates maturity; an outdated file raises questions about the rest of your control.
Common mistakes
- Leaning on ISO only — NIS2 asks for specific evidence your ISO certificate does not automatically provide.
- Leaving the board out — the personal responsibility of the board is a core point of NIS2.
- No chain register — you are co-responsible for the security of your suppliers.
- Letting the file age — an old gap analysis is not evidence of current compliance.
Getting started
First determine your applicability and then build the file from your existing ISMS, starting with the NIS2 ↔ ISO mapping. Unsure whether you are in scope? Take the NIS2 readiness scan or see our page on NIS2.
