← Back to news 26.06.2026

NIS2: The first audit evidence is due, and why it shouldn't be a deadline

Around 30 June 2026 the first NIS2 evidence becomes due for many affected entities. Scrambling for proof at the deadline doesn't solve the real problem. Why evidence should be a state, not a one-off effort.

Germany's NIS2 implementation act has been in force since December 2025. Around 29,500 companies now fall under BSI supervision, up from roughly 4,500. And around 30 June 2026, the first evidence toward the authorities becomes due for many affected entities.

What stands out is what this reveals: by March 2026 only about 11,500 companies had registered, and surveys show that roughly half underestimate whether they are even affected. The biggest hurdle is rarely the technology. It's the evidence.

The mistake: treating evidence as a deadline

If you scramble for proof only when the audit looms, you're documenting a wish, not reality. Screenshots, spreadsheets, hastily maintained tables rarely survive serious scrutiny, and they say nothing about whether the measures actually work day to day. Evidence isn't a deadline. It's a state.

What NIS2 actually requires

  • Risk management & measures: capture and treat risks systematically and prove their effectiveness.
  • Incident reporting & deadlines: report incidents on time, with a traceable process instead of an ad-hoc email.
  • Supply chain security: assess and monitor providers and dependencies.
  • Evidence toward authorities: be able to show at any time that the requirements are not just documented but lived.

How isidaten approaches it

With isidaten, evidence is created where the work happens, instead of being assembled by hand before an audit. A central object base connects assets, risks, measures and incidents into one picture, an asset in the ISMS is the same object in the risk register and in the reporting process. Native integrations feed operational data in automatically, and machine-readable formats (OSCAL) make the state verifiable, not just presentable.

The result is documentation that does two jobs at once: deliver the evidence and make the operational security work easier.

See how this looks for NIS2 on our NIS2 solution page, or directly in a demo.

Matching solution isidaten for NIS2

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.