NIS2 Audit Correction: What to do after a non-compliant result?

2026/ 10/09

A Non-compliant NIS2 audit result is a serious warning, but it does not mean that the entire preparation process needs to start again from the beginning. At this stage, the organization already has a detailed, independent auditor assessment that provides a precise starting point for the next steps.

The next task is therefore not to carry out another general GAP analysis, but to perform targeted audit correction based on the findings of the audit report. This requires identifying the root causes of the deviations, defining the necessary corrective actions, prioritizing their implementation, and ensuring that the resulting compliance can be demonstrated with appropriate evidence.

 

Start with the audit report

Following a failed audit, the audit report becomes the most important professional basis for the correction process.

The report provides more than the organization's overall SZEKI score. It can also reveal which elementary requirements and requirement groups were not adequately fulfilled, the severity of the deviations identified by the auditor, the assessment method behind each finding, and what evidence was or was not available during the audit.

When planning corrective actions, at least the following aspects should be considered:

  • which requirement is affected by the finding;
  • what exactly the auditor identified as deficient;
  • how severe the deviation is;
  • what caused the requirement not to be fulfilled appropriately;
  • what corrective action is required;
  • what evidence will demonstrate successful implementation.

Rather than simply closing an auditor finding, the objective should therefore be to identify and eliminate the root cause of the deviation.

 

The same Non-compliant result may reflect completely different problems

One of the most important steps in NIS2 audit correction is determining why a particular requirement was not fulfilled appropriately.

If a required policy or procedure is missing, preparing the necessary document may be an appropriate corrective action. A completely different approach is required, however, when the relevant policy already exists but the organization's actual operations do not follow the documented process.

Several types of underlying issues may be identified:

  • Documentation gap: a required policy, procedure, or record is missing or inadequate.
  • Operational gap: the process is formally regulated but is not performed, or is not performed appropriately in practice.
  • Technical gap: a required security control is missing or does not operate appropriately.
  • Evidence gap: the control operates in practice, but its execution is not adequately documented or cannot be demonstrated.
  • Combined deviation: documentation, operational, and technical deficiencies occur together.

A corrective action can only be considered effective if the actual cause of the deviation identified by the auditor is eliminated, rather than merely addressing its documentary symptoms.

 

Turn each audit finding into a concrete corrective action

Once the detailed audit report has been assessed, individual findings should be transformed into a consistent and actionable correction structure:

 

Each element of the process has an important role:

  • identifying the root cause ensures that the actual source of the problem is addressed;
  • the severity of the deviation helps determine the appropriate priority;
  • assigning a responsible person and deadline turns the measure into an actionable task;
  • defining the required evidence in advance ensures that the implemented correction can be demonstrated during the next audit.

 

How should corrective actions be prioritized?

A failed audit may result in a significant number of corrective actions, while the available time, expert capacity, and budget are usually limited.

The order of implementation should therefore not be determined solely by which measures can increase the SZEKI score most quickly.

Appropriate prioritization requires several factors to be considered together:

 

A significant or critical deviation may require immediate attention even if a less important measure could generate additional SZEKI points more easily.

Implementation time is another important factor. Corrective actions involving an external service provider, procurement process, or major technical development should generally be initiated early in the correction process.

 

Define the evidence of implementation when planning the correction

One of the important lessons of NIS2 audits is that even a functioning control may not be sufficient if its implementation cannot be demonstrated.

When defining a corrective action, the organization should therefore also determine what evidence will be used to demonstrate its successful implementation.

If, for example, regular access-right reviews were missing, introducing the process alone is not sufficient. The organization also needs to document its actual execution appropriately. The same principle applies to recovery tests, vulnerability assessments, training activities, risk assessments, and regular security reviews.

The result of audit correction should therefore not simply be a completed task, but a functioning and auditable control.

 

The objective is not simply to reach 71 SZEKI points

When an organization's result is close to the compliance threshold, focusing exclusively on obtaining the few missing SZEKI points may seem like the most straightforward approach.

Compliance, however, is not merely a mathematical threshold.

If the auditor has identified a significant or critical deviation in an important cybersecurity area, addressing that issue may deserve priority even if another, less significant measure could increase the overall score more quickly.

NIS2 compliance also does not end with a successful audit. The implemented controls must continue to operate, be performed regularly, reviewed and documented, and adapted to organizational and technological changes.

 

Audit correction is not solely an IT responsibility

Addressing audit findings usually requires cooperation between several areas of the organization.

In addition to technical measures, corrective actions may involve HR, procurement, legal, operational, or management responsibilities, as well as the participation of external IT service providers, system developers, and other suppliers.

Management support and the coordinating role of the Information Security Officer are therefore also essential during the correction process. Without clearly assigned responsibilities and deadlines, continuous monitoring of corrective actions, and systematic collection of evidence, even a professionally prepared action plan can easily stall during implementation.

 

From a Non-compliant result to compliance

The process following a failed audit is therefore not about restarting the entire NIS2 preparation process. It is about targeted and demonstrable remediation of the specific deficiencies identified by the auditor.

In a well-structured audit correction process, the findings of the audit report are transformed into an actionable remediation plan. Tasks are prioritized according to their cybersecurity risk and impact on the audit result, while implementation is planned from the outset so that the outcome can be demonstrated with appropriate audit evidence.

 

NIS2 Audit Correction – from identified gaps to compliance

Régens' NIS2 Audit Correction service does not start with another general NIS2 preparation project. It starts with the existing audit report.

Our experts assess the auditor's findings, identify the root causes of the deviations, evaluate their severity and impact on compliance, and then define and prioritize the necessary documentation, organizational, and technical corrective actions.

The objective is to establish a level of compliance where the implemented measures operate effectively, are properly documented, and can be demonstrated with appropriate evidence during the next audit.

Did your NIS2 audit result in Non-compliance?
Upload your audit report! Our experts will assess the auditor's findings, identify and prioritize the necessary corrective actions, and provide targeted support to help your organization achieve compliance.
UPLOAD YOUR AUDIT REPORT →

 

Related NIS2 Services
Outsourced Chief Information Security Officer (CISO)
Experienced information security expertise to support continuous NIS2 compliance and preparation for the next audit cycle.
Learn more →
 
Featured service
NIS2 Audit Correction
Based on the audit report, we identify and prioritize the necessary corrective actions and support their implementation to help your organization achieve compliance.
Learn more →
 
NIS2 Preparation
Assessment, GAP analysis, action planning, and expert support for structured implementation of NIS2 requirements and successful audit preparation.
Learn more →