A NIS2 readiness audit (Gap Analysis) assesses the cybersecurity maturity of an SME in relation to new legal obligations. In Belgium, this approach aligns ideally with the CyberFundamentals (CyFun) framework of the Belgian Centre for Cybersecurity (CCB) and takes place in five phases.

1. Framing and Scope

  • Identify critical business processes and sensitive company data.
  • Map all physical and virtual assets: servers (e.g., Proxmox clusters), workstations, network equipment and containers (e.g., Docker environments).
  • Involve management to validate their understanding of the legal and financial responsibilities implied by the directive.

2. Documentary Review and Governance

  • Check for the presence and updating of an Information Systems Security Policy (ISSP).
  • Analyze Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP).
  • Control HR security procedures, including access management upon the arrival or departure of an employee and awareness training.
  • Reviewing IT subcontractor contracts to ensure the presence of security clauses and service level agreements (SLAs) is a central point of NIS2.

3. Technical Evaluation of the Infrastructure

  • Access controls: Validate the systematic deployment of multi-factor authentication (MFA) or hardware (such as FIDO2/YubiKey keys) on remote and administrator access.
  • Network and domain security: Evaluate network segmentation (isolation of guest, IoT and production flows via VLANs on UniFi type equipment), firewall filtering and DNS zone hardening (SPF, DKIM and DMARC configurations via managers like Cloudflare).
  • Vulnerability management: Check the frequency and automation of security updates on operating systems (Linux/Windows) and web applications.
  • Backups: Ensure the existence of immutable, encrypted backups isolated from the production network, supplemented by regular restoration tests.

4. Audit of Incident Detection and Management

  • Verify the existence of an incident notification procedure capable of meeting strict deadlines (early alert to the CCB within 24 hours).
  • Analyze the centralization and retention of logs (logging) to investigate a compromise.

5. Remediation Plan (Roadmap)

  • Classify the observed discrepancies between the current situation and the NIS2 requirements by criticality.
  • Prepare a costed and prioritized technical and organizational action plan for management.

Categories: