office@safebyte.io București, România ISO 27001:2023 · ISO 9001:2023
Audit and compliance

NIS / NIS2 security audit

NIS2 shifted security accountability to senior management and requires risk-proportionate measures, plus incident reporting within 24 and 72 hours. The audit shows where you stand against Article 21 and what separates you from compliance. SafeByte is DNSC authorised.

Deutsch: această pagină nu e încă tradusă. Textul de mai jos e în English.

NIS / NIS2 security audit

NIS2 is not a certification you obtain and hang on the wall — it is a supervisory regime that applies to operators of essential and important services in energy, water, manufacturing, healthcare, digital infrastructure and other sectors. Two things set it apart from everything before: it shifts accountability to senior management (who approve, oversee and can be held personally liable) and imposes a strict incident reporting cadence. The audit shows honestly where you stand and what separates you from compliance.

Since 24 August 2021, SafeByte Consulting has been authorised by the Romanian authorities to conduct security audits in this context.

What the audit verifies

The minimum measures in Article 21, evaluated proportionally to your size and risk: risk analysis and security policies; incident handling; business continuity, backup and crisis management; supply chain security; security in acquisition, development and maintenance, including vulnerability management; cyber hygiene and training; cryptography; access control, asset management and multi-factor authentication.

We also check two things organisations discover late:

  • Reporting (Art. 23) — are you ready for an early warning within 24 hours, notification within 72 hours and a final report within one month? Usually the process exists on paper, but has never been exercised under pressure
  • Management accountability (Art. 20) — is there evidence that management approves and oversees the measures, not just signs off on them?

How it works and what you get

We start from scope, perform a gap analysis against Article 21, test controls (design and operating effectiveness), collect evidence and deliver the report with a roadmap. The specific framework (NIS, NIS2 and national transposition acts) is confirmed together at the start — it is the basis of the audit, not assumed. You receive the gap analysis, a governance evidence package and a prioritised remediation roadmap.