+421 917 743 382
Free consultation

One directive, eight different obligations

NIS2 is a directive, and a directive is an instruction to twenty-seven legislatures. Whether an audit is required at all, who may perform it and how often differs by country.

If your group operates in several EU countries, you have probably been told that NIS2 is one rule. It is not. NIS2 is a directive, and a directive is an instruction to twenty-seven legislatures. What arrived at the other end differs — not in spirit, but in the things your programme actually depends on: whether an audit is required at all, who is allowed to perform it, how often, and whether a foreign firm can do it.

What is genuinely the same everywhere

Four instruments apply directly and their text is identical in every member state:

  • GDPR — Regulation (EU) 2016/679
  • DORA — Regulation (EU) 2022/2554
  • AI Act — Regulation (EU) 2024/1689
  • Cyber Resilience Act — Regulation (EU) 2024/2847

For these you can write one policy, run one assessment and keep one set of evidence.

With one caveat that catches groups out. Even GDPR leaves room for national rules — processing in the employment context under Article 88, the age of consent for information society services, and national conditions for special categories of data. A single group-wide privacy framework is correct; a single group-wide employment privacy notice usually is not.

What is not the same

Under NIS2, the audit obligation itself differs by country. This is what we have verified from primary sources:

CountryWho may perform the auditWhat that means in practice
Slovakiacertified cybersecurity auditorcertification and registration required
Czechiaa person trained in auditing, with at least three years' experience in performing cybersecurity or ISMS audits, who assesses independently and holds no other security roleopen to foreign firms
Polandan accredited conformity assessment body, or at least two auditors holding a recognised certificate; no Polish establishment requiredopen; first mandatory audits by April 2028
Hungaryonly a legal entity listed in the SZTFH registera foreign entity cannot realistically register
Austriaan independent body (unabhängige Stelle) with an auditor admitted by the Austrian authorityEU establishment suffices; admissions not yet open
Germanyaccredited assessor for critical installations; most entities have no periodic audit at allpreparation matters more than audit
Romaniaauditor holding a valid DNSC attestationthe register is open to EU citizens
Greecean internal or external auditor; no accreditation, no registeropen; impartiality is the only requirement

Two things in that table usually surprise people.

In Germany, most entities have no recurring audit obligation. Only operators of critical installations must produce evidence of conformity every three years. For everyone else the supervisory authority may order an audit, but there is no periodic duty and no "NIS2 certificate".

In Hungary the door is effectively closed to foreign auditors. Registration requires a domestic company registration number and filing through a domestic portal; every registered auditor is established in Hungary.

And a duty that several countries share

Where the audit obligation is light, something else is heavy: self-assessment. Romania requires an annual maturity self-assessment alongside the audit. Greece requires an annual self-assessment submitted to the national authority, plus an annual external penetration test. Germany and Czechia expect continuous evaluation.

This is the part a group can run centrally — one method, one evidence format, one calendar — and it is the part that most often gets neglected because no certificate comes out of it.

What this means for a group programme

You cannot run one audit programme across the EU. You can run one method. Scope definition, risk methodology, evidence structure, self-assessment and management review can be identical everywhere; the audit is then a local act performed by whoever the local law allows.

That is how we work: one counterpart on your side, unified templates, direct delivery in Slovakia, Poland and Greece, and delivery through a group partner in the remaining countries.

Audits that do not need a national authorisation

An internal audit or a supplier audit under the GDPR or ISO/IEC 27001 is not tied to an authorisation in a particular country, so a network of subsidiaries, dealers or branches across several countries can be covered by a single programme — how such a programme runs is on Automotive network audits.

Where our work ends

  • We do not perform penetration tests or threat-led penetration testing.
  • Nobody audits their own work. Where we hold the security manager role at a client, we do not audit that client.
  • Certificates against ISO/IEC 27001 and ISO 22301 are issued by an accredited certification body, not by an advisor. TISAX assessments may only be performed by an ENX-accredited provider.

Verified against national regulations as of 10 September 2026.

Tell us what you are dealing with.

Thirty minutes with a consultant who knows your industry. The output is a one-page summary with a recommended approach and an indicative scope — we send it to you even if we do not reach an agreement.

info@iosec.eu
+421 917 743 382

Please fill in your name.
Please fill in your organisation.
Please give an address we can reply to.
Please choose a topic.
Please confirm you have read the privacy notice.

No newsletter, no sales sequence — we answer the question you asked.

Call us Free consultation