One directive, eight different obligations
NIS2 is a directive, and a directive is an instruction to twenty-seven legislatures. Whether an audit is required at all, who may perform it and how often differs by country.
If your group operates in several EU countries, you have probably been told that NIS2 is one rule. It is not. NIS2 is a directive, and a directive is an instruction to twenty-seven legislatures. What arrived at the other end differs — not in spirit, but in the things your programme actually depends on: whether an audit is required at all, who is allowed to perform it, how often, and whether a foreign firm can do it.
What is genuinely the same everywhere
Four instruments apply directly and their text is identical in every member state:
- GDPR — Regulation (EU) 2016/679
- DORA — Regulation (EU) 2022/2554
- AI Act — Regulation (EU) 2024/1689
- Cyber Resilience Act — Regulation (EU) 2024/2847
For these you can write one policy, run one assessment and keep one set of evidence.
With one caveat that catches groups out. Even GDPR leaves room for national rules — processing in the employment context under Article 88, the age of consent for information society services, and national conditions for special categories of data. A single group-wide privacy framework is correct; a single group-wide employment privacy notice usually is not.
What is not the same
Under NIS2, the audit obligation itself differs by country. This is what we have verified from primary sources:
| Country | Who may perform the audit | What that means in practice |
|---|---|---|
| Slovakia | certified cybersecurity auditor | certification and registration required |
| Czechia | a person trained in auditing, with at least three years' experience in performing cybersecurity or ISMS audits, who assesses independently and holds no other security role | open to foreign firms |
| Poland | an accredited conformity assessment body, or at least two auditors holding a recognised certificate; no Polish establishment required | open; first mandatory audits by April 2028 |
| Hungary | only a legal entity listed in the SZTFH register | a foreign entity cannot realistically register |
| Austria | an independent body (unabhängige Stelle) with an auditor admitted by the Austrian authority | EU establishment suffices; admissions not yet open |
| Germany | accredited assessor for critical installations; most entities have no periodic audit at all | preparation matters more than audit |
| Romania | auditor holding a valid DNSC attestation | the register is open to EU citizens |
| Greece | an internal or external auditor; no accreditation, no register | open; impartiality is the only requirement |
Two things in that table usually surprise people.
In Germany, most entities have no recurring audit obligation. Only operators of critical installations must produce evidence of conformity every three years. For everyone else the supervisory authority may order an audit, but there is no periodic duty and no "NIS2 certificate".
In Hungary the door is effectively closed to foreign auditors. Registration requires a domestic company registration number and filing through a domestic portal; every registered auditor is established in Hungary.
And a duty that several countries share
Where the audit obligation is light, something else is heavy: self-assessment. Romania requires an annual maturity self-assessment alongside the audit. Greece requires an annual self-assessment submitted to the national authority, plus an annual external penetration test. Germany and Czechia expect continuous evaluation.
This is the part a group can run centrally — one method, one evidence format, one calendar — and it is the part that most often gets neglected because no certificate comes out of it.
What this means for a group programme
You cannot run one audit programme across the EU. You can run one method. Scope definition, risk methodology, evidence structure, self-assessment and management review can be identical everywhere; the audit is then a local act performed by whoever the local law allows.
That is how we work: one counterpart on your side, unified templates, direct delivery in Slovakia, Poland and Greece, and delivery through a group partner in the remaining countries.
Audits that do not need a national authorisation
An internal audit or a supplier audit under the GDPR or ISO/IEC 27001 is not tied to an authorisation in a particular country, so a network of subsidiaries, dealers or branches across several countries can be covered by a single programme — how such a programme runs is on Automotive network audits.
Where our work ends
- We do not perform penetration tests or threat-led penetration testing.
- Nobody audits their own work. Where we hold the security manager role at a client, we do not audit that client.
- Certificates against ISO/IEC 27001 and ISO 22301 are issued by an accredited certification body, not by an advisor. TISAX assessments may only be performed by an ENX-accredited provider.
Verified against national regulations as of 10 September 2026.
Tell us what you are dealing with.
Thirty minutes with a consultant who knows your industry. The output is a one-page summary with a recommended approach and an indicative scope — we send it to you even if we do not reach an agreement.