secria.eu

which evidence document must I provide for each security measure

Each measure requires evidence that demonstrates its status

Evidence is something that shows that a measure is not only conceived but also genuinely exists and is used in practice. For access control, this might be an overview of who has access to what and how that access is tracked; for patch management, a log or report showing that updates are actually being applied; for an incident process, a description of the steps to be followed, possibly supplemented with a record of a time when the process was executed or tested. The form varies per measure, but the principle is always the same: a claim without supporting evidence is difficult to distinguish from an intention.

The specific evidence that is appropriate depends on what the measure itself entails — an organizational measure such as a policy document requires different types of evidence than a technical measure such as encryption or network segmentation. For the organizational side, it often involves documented policy; which policy documents must I have for NIS2 goes further into this. For the technical side, it is more often about configurations, logs or test results. In all cases, the supporting evidence should have a name, a date and ideally an owner — someone who can explain why the document says what it says. Who that person is within the organization is a separate question that is addressed separately under who should be responsible within my organisation for a measure.

Where this breakdown into ten measures comes from

Article 21(2) of the NIS2 Directive lists the ten categories of measures on which the due diligence obligation rests, from risk analysis to access control and crisis management; the Cybersecurity Act incorporates this breakdown in the Dutch transposition. The Directive itself does not prescribe a fixed evidence format, but the well-known control objectives from ISO/IEC 27001 Annex A are often used as a practical application, including the type of evidence that fits with it. The NCSC provides guidance on the due diligence obligation in general terms, without prescribing mandatory evidence for each individual measure.

What you concretely need to do

The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.

View the subscription First the free NIS2 check

This is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.

Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.