+421 917 743 382
Free consultation

One directive, eight different obligations

NIS2 is a directive, and a directive is an instruction to twenty-seven legislatures. Whether an audit is required at all, who may perform it and how often differs by country.

If your group operates in several EU countries, you have probably been told that NIS2 is one rule. It is not. NIS2 is a directive, and a directive is an instruction to twenty-seven legislatures. What arrived at the other end differs — not in spirit, but in the things your programme actually depends on: whether an audit is required at all, who is allowed to perform it, how often, and whether a foreign firm can do it.

What is genuinely the same everywhere

Four instruments apply directly and their text is identical in every member state:

  • GDPR — Regulation (EU) 2016/679
  • DORA — Regulation (EU) 2022/2554
  • AI Act — Regulation (EU) 2024/1689
  • Cyber Resilience Act — Regulation (EU) 2024/2847

For these you can write one policy, run one assessment and keep one set of evidence.

With one caveat that catches groups out. Even GDPR leaves room for national rules — processing in the employment context under Article 88, the age of consent for information society services, and national conditions for special categories of data. A single group-wide privacy framework is correct; a single group-wide employment privacy notice usually is not.

What is not the same

Under NIS2, the audit obligation itself differs by country. This is what we have verified from primary sources:

Country Who may perform the audit What that means in practice
Slovakia certified cybersecurity auditor certification and registration required
Czechia a trained person with at least three years of audit experience, impartial, holding no other security role at the client; no registration open to foreign firms
Poland an accredited conformity assessment body, or at least two auditors holding a recognised certificate; no Polish establishment required open; first mandatory audits by April 2028
Hungary only a legal entity listed in the SZTFH register a foreign entity cannot realistically register
Austria a qualifizierte Stelle established in Austria closed to foreign firms
Germany accredited assessor for critical installations; most entities have no periodic audit at all preparation matters more than audit
Romania auditor holding a valid DNSC attestation the register is open to EU citizens
Greece an internal or external auditor; no accreditation, no register open; impartiality is the only requirement

Two things in that table usually surprise people.

In Germany, most entities have no recurring audit obligation. Only operators of critical installations must produce evidence of conformity every three years. For everyone else the supervisory authority may order an audit, but there is no periodic duty and no "NIS2 certificate".

In Hungary the door is effectively closed to foreign auditors. Registration requires a domestic company registration number and filing through a domestic portal; every registered auditor is established in Hungary.

And a duty that several countries share

Where the audit obligation is light, something else is heavy: self-assessment. Romania requires an annual maturity self-assessment alongside the audit. Greece requires an annual self-assessment submitted to the national authority, plus an annual external penetration test. Germany and Czechia expect continuous evaluation.

This is the part a group can run centrally — one method, one evidence format, one calendar — and it is the part that most often gets neglected because no certificate comes out of it.

What this means for a group programme

You cannot run one audit programme across the EU. You can run one method. Scope definition, risk methodology, evidence structure, self-assessment and management review can be identical everywhere; the audit is then a local act performed by whoever the local law allows.

That is how we work: one counterpart on your side, unified templates, direct delivery in Slovakia, Czechia, Poland and Greece, and delivery through a group partner in the remaining countries.

Where our work ends

  • We do not perform penetration tests or threat-led penetration testing.
  • Nobody audits their own work. Where we hold the security manager role at a client, we do not audit that client.
  • Certificates against ISO/IEC 27001 and ISO 22301 are issued by an accredited certification body, not by an advisor. TISAX assessments may only be performed by an ENX-accredited provider.

Verified against national regulations as of 10 September 2026.

Please fill in your name.
Please fill in your organisation.
Please give an address we can reply to.
Please choose a topic.
Please confirm you have read the privacy notice.

No newsletter, no sales sequence — we answer the question you asked.

Call us Free consultation