One directive, eight different obligations
NIS2 is a directive, and a directive is an instruction to twenty-seven legislatures. Whether an audit is required at all, who may perform it and how often differs by country.
If your group operates in several EU countries, you have probably been told that NIS2 is one rule. It is not. NIS2 is a directive, and a directive is an instruction to twenty-seven legislatures. What arrived at the other end differs — not in spirit, but in the things your programme actually depends on: whether an audit is required at all, who is allowed to perform it, how often, and whether a foreign firm can do it.
What is genuinely the same everywhere
Four instruments apply directly and their text is identical in every member state:
- GDPR — Regulation (EU) 2016/679
- DORA — Regulation (EU) 2022/2554
- AI Act — Regulation (EU) 2024/1689
- Cyber Resilience Act — Regulation (EU) 2024/2847
For these you can write one policy, run one assessment and keep one set of evidence.
With one caveat that catches groups out. Even GDPR leaves room for national rules — processing in the employment context under Article 88, the age of consent for information society services, and national conditions for special categories of data. A single group-wide privacy framework is correct; a single group-wide employment privacy notice usually is not.
What is not the same
Under NIS2, the audit obligation itself differs by country. This is what we have verified from primary sources:
| Country | Who may perform the audit | What that means in practice |
|---|---|---|
| Slovakia | certified cybersecurity auditor | certification and registration required |
| Czechia | a trained person with at least three years of audit experience, impartial, holding no other security role at the client; no registration | open to foreign firms |
| Poland | an accredited conformity assessment body, or at least two auditors holding a recognised certificate; no Polish establishment required | open; first mandatory audits by April 2028 |
| Hungary | only a legal entity listed in the SZTFH register | a foreign entity cannot realistically register |
| Austria | a qualifizierte Stelle established in Austria | closed to foreign firms |
| Germany | accredited assessor for critical installations; most entities have no periodic audit at all | preparation matters more than audit |
| Romania | auditor holding a valid DNSC attestation | the register is open to EU citizens |
| Greece | an internal or external auditor; no accreditation, no register | open; impartiality is the only requirement |
Two things in that table usually surprise people.
In Germany, most entities have no recurring audit obligation. Only operators of critical installations must produce evidence of conformity every three years. For everyone else the supervisory authority may order an audit, but there is no periodic duty and no "NIS2 certificate".
In Hungary the door is effectively closed to foreign auditors. Registration requires a domestic company registration number and filing through a domestic portal; every registered auditor is established in Hungary.
And a duty that several countries share
Where the audit obligation is light, something else is heavy: self-assessment. Romania requires an annual maturity self-assessment alongside the audit. Greece requires an annual self-assessment submitted to the national authority, plus an annual external penetration test. Germany and Czechia expect continuous evaluation.
This is the part a group can run centrally — one method, one evidence format, one calendar — and it is the part that most often gets neglected because no certificate comes out of it.
What this means for a group programme
You cannot run one audit programme across the EU. You can run one method. Scope definition, risk methodology, evidence structure, self-assessment and management review can be identical everywhere; the audit is then a local act performed by whoever the local law allows.
That is how we work: one counterpart on your side, unified templates, direct delivery in Slovakia, Czechia, Poland and Greece, and delivery through a group partner in the remaining countries.
Where our work ends
- We do not perform penetration tests or threat-led penetration testing.
- Nobody audits their own work. Where we hold the security manager role at a client, we do not audit that client.
- Certificates against ISO/IEC 27001 and ISO 22301 are issued by an accredited certification body, not by an advisor. TISAX assessments may only be performed by an ENX-accredited provider.
Verified against national regulations as of 10 September 2026.