NIS2: preparing external exposure evidence
A worksheet for scope, observations and follow-up. It does not determine regulatory applicability or establish compliance.
1. Confirm context and authorization
Identify the service, responsible people and rules that need assessment. Applicability depends on the case and relevant legislation; a single employee or revenue figure does not settle it.
Before a technical assessment, record the asset owner, authorized assets, permitted techniques and validity period. Review third-party assets and the authorization withdrawal process separately.
2. Record verifiable observations
A finding count or severity label does not replace evidence. Minimize personal data and secrets captured.
- Asset and its relationship to the authorized scope.
- Observation date and time, method and source.
- Minimum necessary evidence and a safe way to reproduce the observation.
- Separate observations, inferences and confirmed findings.
- Assessment coverage and limitations.
3. Agree priorities and follow-up
Assign an owner, justified priority, planned action and review date. Check frequency and evidence retention should reflect risk, applicable obligations and operating capacity.
When closing a finding, retain the correction check and its limitations. A technical report covers part of security work; it does not certify compliance on its own.
4. Assess whether the result is useful
These questions are a suggested workflow, not an exhaustive legal checklist or a claim about Ziaren's current capabilities.
- Can the observation be reproduced within the authorized scope?
- Have false positives and uncertainty been clarified?
- Does each action have an owner and closure criterion?
- Does the evidence help decide what to fix first?
Legal source and limits
Directive (EU) 2022/2555 is a source for assessing the NIS2 framework. The rules applicable to the country, sector and service also need review. This guide does not state universal schedules, fines or retention periods.