Basics & Compliance
Running a NIS2 gap assessment with template and guide
The gap assessment measures your NIS2 implementation status against the 12 mandatory measures of § 30 BSIG. This guide takes you through five steps from deriving the audit catalogue to management approval, with concrete assessment criteria and an action plan.
20 min read · Published 20 February 2026
A gap assessment is the first structured step to measure your NIS2 implementation status. The output: a prioritised gap analysis against the 12 mandatory measures of § 30 BSIG, plus an approved action plan that serves as the foundation for the entire NIS2 implementation. This guide walks you through all five steps – from deriving the audit catalogue to presenting it to management for approval.
What a Gap Assessment Is – and What It Is Not
A gap assessment is a structured self-evaluation: you compare your current security posture against the specific requirements of § 30 BSIG. The result shows what is fully implemented, what partially exists, and what is missing.
What it is not:
- Not a risk analysis – the risk analysis (Article B-03) evaluates threat scenarios and damage potential. The gap assessment checks whether the required security measures are in place.
- Not a penetration test – a pentest reviews the technical attack surface. The gap assessment is a document- and interview-based inventory.
- Not an ISO 27001 gap analysis – related, but different focus. NIS2 is more specific in certain areas (e.g. MFA, reporting obligations), less comprehensive in others compared to ISO 27001.
The gap assessment answers the question: "Where are we on the NIS2 compliance map?" – a snapshot showing what is done, what is partial, and what is still missing. Ideally, conduct it before or in parallel with the risk analysis: the gap assessment provides the compliance overview, the risk analysis prioritises threat scenarios. Both outputs inform the action plan.
§ 30 para. 2 BSIG: Essential and important entities shall take appropriate, proportionate and effective technical and organisational measures to manage risks to the security of their network and information systems.
Step 1: Derive the Audit Catalogue from § 30 BSIG
§ 30 para. 2 BSIG defines 12 mandatory measures. For the gap assessment, you derive an audit catalogue from these: each measure is broken down into 3–5 concrete assessment criteria that can be rated Yes / Partial / No.
The 12 mandatory measures and example criteria:
1. Risk analysis and security policy (§ 30 para. 2 no. 1 BSIG)
- A documented IT security policy exists and has been approved by management
- A NIS2-compliant risk analysis has been conducted and is current (not older than 12 months)
- The scope of the risk analysis covers all material network and information systems
- Risk treatment decisions are documented and traceable
2. Incident handling – Incident Response (§ 30 para. 2 no. 2 BSIG)
- An incident response plan exists and has been approved by management
- Roles and escalation paths in the IR process are defined and communicated
- A 24/7 contact for security incidents is designated and reachable
- The BSI notification process (§ 32 BSIG) is documented in the IR plan
- The IR plan has been tested within the last 12 months (tabletop or full exercise)
3. Business continuity management, backup, crisis management (§ 30 para. 2 no. 3 BSIG)
- A BCM plan for essential business processes exists and is approved
- RTO and RPO are defined and documented for each critical system
- Backups are performed regularly and tested for recoverability
- At least one BCM exercise has been conducted in the last 12 months
4. Supply chain security and third-party providers (§ 30 para. 2 no. 4 BSIG)
- Critical IT suppliers are identified and classified
- Security requirements are contractually agreed with critical suppliers
- A process for regular supplier assessments exists
- Incident notification obligations for suppliers are contractually anchored
5. Security in the acquisition, development and maintenance of IT systems (§ 30 para. 2 no. 5 BSIG)
- Security requirements are systematically considered when procuring new IT systems
- A process for secure software deployment exists (staging, testing before production)
- Changes to critical systems go through a documented change management procedure
6. Vulnerability management and disclosure (§ 30 para. 2 no. 6 BSIG)
- A documented patch management process with defined timelines per severity level exists
- Critical and high-severity vulnerabilities (CVSS ≥ 7.0) are remediated within defined timelines
- Vulnerability scans are performed regularly
- A process for handling zero-day vulnerabilities and workarounds is defined
7. Training and cyber hygiene (§ 30 para. 2 no. 7 BSIG)
- All employees receive regular security awareness training
- Management has demonstrably completed the mandatory training under § 38 para. 3 BSIG
- An annual security awareness plan exists
- Phishing simulations or comparable practical tests are conducted
8. Cryptography and encryption (§ 30 para. 2 no. 8 BSIG)
- Data in transit is encrypted (TLS 1.2 or higher)
- Critical data at rest is encrypted
- A policy for approved cryptographic methods and key lengths exists
- Key management processes are documented
9. Personnel security, access control, asset management (§ 30 para. 2 no. 9 BSIG)
- A current asset inventory of all material IT systems exists
- Access rights are based on the least-privilege principle and are reviewed regularly
- Offboarding processes ensure timely deactivation of accounts
- Privileged accounts are inventoried and managed separately
10. Multi-factor authentication and secure communications (§ 30 para. 2 no. 10 BSIG)
- MFA is enabled for all remote access – Yes / Partial (admins only) / No
- MFA is enabled for all privileged accounts – Yes / Partial / No
- MFA is enabled for access to critical internal systems – Yes / Partial / No
- Secure communication channels for emergencies exist (encrypted, MFA-protected)
11. Physical security (§ 30 para. 2 no. 11 BSIG)
- Server rooms and data centres have access control and log all entries
- Unauthorised physical access to critical systems is prevented by appropriate measures
- Storage media are securely wiped or destroyed when decommissioned
12. IT service provider security (§ 30 para. 2 no. 12 BSIG)
- External IT service providers are assessed to the same standard as internal suppliers
- Supplier access rights are restricted to what is necessary and revoked after project completion
- SLAs with service providers include security and incident notification obligations
In addition, the organisational obligations under §§ 32–38 BSIG must be assessed:
- § 33 BSIG Registration obligation: Entity is registered with BSI – Yes / No
- § 32 BSIG Notification obligation: Process for BSI notification of significant incidents is defined and tested – Yes / Partial / No
- § 38 BSIG Management responsibility: Management has formally approved NIS2 measures and fulfilled training obligation – Yes / Partial / No
Download the Gap Assessment Checklist from the KaitoSec template package – it contains all 12 measure areas with pre-structured assessment criteria, rating fields, and a comment field for evidence.
Step 2: Assess the Current State for Each Measure
The gap assessment is a team effort – do not do it alone in a spreadsheet. The most common source of error is the IT manager estimating the current state from memory and being too optimistic, because operational reality differs from the policy documentation.
Assessment methodology
Each assessment criterion receives one of four ratings:
- Implemented (Yes): The measure is fully implemented, documented, and actively practised. Evidence is available.
- Partially implemented: The measure exists, but with relevant gaps. Document exactly what is missing – e.g. "MFA enabled for admins, but not for all remote employees".
- Not implemented (No): The measure is completely absent, or exists only on paper but is not practised.
- Not applicable (N/A): The criterion does not apply to your entity – e.g. OT security for a pure office services company. Use N/A sparingly and always justify it.
Who must be involved?
- IT operations: Knows the technical reality – which systems have MFA, which patches are outstanding, how backup actually works
- CISO / ISB: Coordinates the assessment, knows the policies and documentation
- Management: Must be consulted on governance questions (§ 38 BSIG training, management resolutions, risk acceptance decisions)
- HR (for personnel security): Onboarding/offboarding processes, data protection training records
- Procurement / supplier management (for supply chain security): Knows existing contracts and supplier relationships
Require evidence
For every "Implemented" criterion: collect the evidence. A Yes without documentation does not count – not before the BSI and not in internal quality assurance. Typical evidence:
- Policies and process documents (with date and management approval)
- Screenshot or configuration extract from the system (e.g. MFA policy in Azure AD)
- Training records with participant lists and dates
- Test reports (backup tests, tabletop exercises)
- Contract excerpts (security clauses with suppliers)
Important: If a policy exists but is not practised – rate it "Partial" or "No", not "Yes". Paper compliance does not protect against fines if a BSI auditor follows up.
Step 3: Identify Gaps Between Target and Actual State
Every "Partial" or "No" rating is a gap. The next step is prioritisation – not all 50+ criteria are equally urgent.
Priority levels
- Critical: Missing measures that are most likely to cause a reportable incident or eliminate response capability. Examples: no incident response plan, no functioning backups, no MFA for privileged accounts, BSI registration missing.
- High: Measures whose absence creates an independent fine risk or that are explicitly required by law. Examples: notification process under § 32 BSIG not defined, management training under § 38 para. 3 BSIG not evidenced.
- Medium: Partially implemented measures with relevant gaps. Examples: MFA for admins only, not all remote access; patch management process exists but without defined timelines.
- Low: Documentation gaps for technically implemented measures. The measure exists but is not formally documented or approved.
The risk analysis (B-03) informs this prioritisation: gaps that overlap with high or critical risks from your risk analysis are always critical or high – regardless of their formal classification.
Compliance score
Calculate a rough compliance score: number of criteria rated "Yes" / total applicable criteria. A result of e.g. 60% Yes, 25% Partial, 15% No gives management a quick orientation – and signals that the need for action is real but manageable. Do not rely too heavily on the percentage; what matters are the critical gaps, not the average.
Step 4: Create the Action Plan
For every identified gap, define a concrete measure to close it. The action plan is the central steering document for your entire NIS2 implementation – it must be actionable, not aspirational.
Required fields per measure
- Measure description: What exactly needs to be done (not "implement MFA", but "enable MFA for all 47 remote access accounts in Microsoft 365 by [date]")
- Responsible party: Assigned by name or role – not "IT department"
- Deadline: A specific date, not "as soon as possible"
- Priority: Critical / High / Medium / Low (from Step 3)
- Estimated effort: Person-days or cost range – essential for resource planning
- Reference to the gap: Which assessment criterion from the gap assessment is being closed
Time horizon
- Quick wins (under 2 weeks): BSI registration if not done, MFA for remote access if technically ready, documented emergency contact list for security incidents, schedule and commission management training.
- Short-term (under 3 months): Create or update incident response plan, perform and document backup tests, define vulnerability management process, identify critical suppliers.
- Medium-term (3–12 months): Create BCM plan, contractually anchor supply chain security, create complete asset inventory, establish awareness training programme.
- Long-term (over 12 months): ISMS build-out, ISO 27001 certification if targeted, network segmentation, continuous monitoring.
Use the Action Plan template from the KaitoSec template package – it is designed to work with the gap assessment output and contains all required fields plus a summary view by time horizon and priority.
Practical tip: The action plan should contain at most 20–30 entries. If you have 60 individual measures, consolidate. An unmanageable plan results in nothing being prioritised and therefore nothing getting done.
Step 5: Present to Management and Obtain Approval
§ 38 BSIG obliges management bodies to approve and oversee the implementation of cybersecurity measures. Presenting the gap assessment and formally approving the action plan is therefore not optional – it is a legal requirement.
What belongs in the presentation
- Summary of the gap assessment: compliance score, Yes/Partial/No distribution, number of critical and high gaps
- Top-3 gaps with justification of criticality: why are these gaps priority?
- Action plan with quick wins and medium-term roadmap overview
- Resource requirements: total effort in person-days and cost range
- Recommended next steps and request for formal approval
Document the approval
Management must formally approve the action plan – not verbally, but through documented resolution. Acceptable formats:
- Minutes extract from a management meeting with signatures
- Separate NIS2 management resolution (Template B-13)
- Email confirmation by all management members with explicit reference to the action plan
Store the approval as an annex to the gap assessment document. It is a central compliance record in a BSI inspection.
Establish a follow-up structure
The gap assessment is not a one-time exercise. Establish the following structure immediately:
- Quarterly review: check progress on measures, mark completed items, capture new gaps
- Annual update: repeat the full gap assessment – NIS2 requirements and your IT landscape change
- Event-driven update: after significant incidents, IT infrastructure changes, or new legal requirements
Common Mistakes
- Conducting the assessment alone: The IT manager fills in the checklist from memory – results are too optimistic because operational reality differs from the policy documentation.
- Counting paper compliance as Yes: The policy exists but is not practised. That is "Partial" – in practice, the BSI cares about what actually happens, not what the document says.
- No prioritisation: All 50+ criteria are treated as equally important. Result: overwhelm, and the truly critical gaps disappear in the noise.
- Gap assessment without risk analysis: You know what is missing, but not which gaps are actually dangerous. Conduct both – in either order.
- No management approval: The action plan has no authority, resources are not released, and in a BSI inspection there is no evidence that the management body fulfilled its oversight obligation.
- One-time exercise: A gap assessment from 2025 does not protect you in 2027. The IT landscape changes, new requirements emerge – the assessment must be updated regularly.
Position in the NIS2 Implementation Process
The gap assessment is typically the first structured step after confirming your NIS2 applicability (B-01) and BSI registration (B-02). It provides the foundation for all subsequent implementation steps:
- Risk analysis (B-03): Gap assessment and risk analysis inform each other – gaps in security measures increase risk exposure, risk analysis results prioritise gaps
- Incident Response Plan (B-09): Will appear as a critical gap for many organisations – the gap assessment creates the basis to address this immediately
- Supplier assessment (B-14), BCM plan (B-16), MFA rollout (B-06): Follow the action plan according to their priority
- All further guides in the chapter structure build on the action plan
The approved action plan is your NIS2 project plan. It tells you not only what to do – it gives every step a responsible party, a deadline, and a priority. This makes the gap assessment not an end in itself, but the starting point for implementation.
This article does not constitute legal advice. The description of legal requirements under BSIG is for general information purposes only. For legal assessment of your specific situation, and for questions regarding applicability, notification obligations, and sanction risks, consult a lawyer specialising in IT law or data protection law.
This article is orientation, not legal advice. Verify scope, deadlines and notification routes against the rules in force for your organisation.
More in Basics & Compliance