which evidence document must I provide for each security measure
Each measure requires evidence that demonstrates its status
Evidence is something that shows that a measure is not only conceived but also genuinely exists and is used in practice. For access control, this might be an overview of who has access to what and how that access is tracked; for patch management, a log or report showing that updates are actually being applied; for an incident process, a description of the steps to be followed, possibly supplemented with a record of a time when the process was executed or tested. The form varies per measure, but the principle is always the same: a claim without supporting evidence is difficult to distinguish from an intention.
The specific evidence that is appropriate depends on what the measure itself entails — an organizational measure such as a policy document requires different types of evidence than a technical measure such as encryption or network segmentation. For the organizational side, it often involves documented policy; which policy documents must I have for NIS2 goes further into this. For the technical side, it is more often about configurations, logs or test results. In all cases, the supporting evidence should have a name, a date and ideally an owner — someone who can explain why the document says what it says. Who that person is within the organization is a separate question that is addressed separately under who should be responsible within my organisation for a measure.
Where this breakdown into ten measures comes from
Article 21(2) of the NIS2 Directive lists the ten categories of measures on which the due diligence obligation rests, from risk analysis to access control and crisis management; the Cybersecurity Act incorporates this breakdown in the Dutch transposition. The Directive itself does not prescribe a fixed evidence format, but the well-known control objectives from ISO/IEC 27001 Annex A are often used as a practical application, including the type of evidence that fits with it. The NCSC provides guidance on the due diligence obligation in general terms, without prescribing mandatory evidence for each individual measure.
What this is based on
- Directive (EU) 2022/2555 (NIS2), Article 21(2) — the ten measures
- Cybersecurity Act — the Dutch transposition of NIS2
- ISO/IEC 27001 — Annex A, the control measures
- NCSC — guidance on the security obligation and the reporting obligation
The Regulation itself is available on EUR-Lex. We provide references for each statement; you need not take our word for it.
What you concretely need to do
The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.
View the subscription First the free NIS2 checkThis is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.
Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.