Get Demo
↑

NIS2 Gap Assessment Template

Template fields to score Directive (EU).

Published: September 2026 Compliance · NIS2 8–12 min read

A NIS2 gap assessment should map current controls to Directive obligations — not only to ISO 27001. Use the fields below as a working template.

Related: NIS2 hub · Checklist · CyberSilo readiness assessment.

Scoring tip: Rate each Article 21 category as Compliant / Largely / Partial / Non / N/A, then capture evidence URL, owner, and remediation due date.

Suggested Template Columns

Field
Purpose
Directive reference
Art 20 / Art 21(2)(a–j) / Art 23 step
Current control
What exists today
Evidence
Policy, log, test, contract clause
Gap
Missing or weak element
Risk
Impact if unremediated
Remediation
Action, owner, due date

Workshop Agenda (Half Day)

  1. Confirm essential vs important classification hypotheses
  2. Walk all 10 Article 21 categories
  3. Tabletop a significant incident against 24h / 72h / one-month clocks
  4. Prioritise remediation by supervisory exposure

How CyberSilo Helps

Run the Gap Assessment with Living Evidence

CyberSilo readiness engagements populate this structure inside CSA.

Frequently Asked Questions

Is a gap assessment the same as certification?

No. NIS2 is supervisory compliance, not an ISO-style certificate. A gap assessment prepares evidence for authorities and customers.

How often should we refresh it?

At least annually, after major architecture changes, and after significant incidents.

Can ISO 27001 SoA replace this template?

Use SoA as an input, then add explicit NIS2 rows for Article 20/23 and any uncovered Article 21 themes.

NIS2 hub · Article 21 · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!