Law & Compliance · 2026-09-20 · 13 min read
NIS2 evidence: there is no certification duty — but there is an evidence power, and the difference decides what you buy

Michael Kaiser
Co-Founder & Head of Systems, Vincency
The market is currently selling NIS2 certificates. The statute knows none. What the BSIG provides instead is quieter and heavier: an evidence power of the BSI — the ability to order audits, to send auditors into your building and to have violations published. Whoever confuses the two either buys papers nobody demands — or misses the preparation for an audit nobody has to announce.
This piece walks the evidence architecture the way the statute built it: the three paths by which the BSI can demand proof — the individual audit order of Section 61(1), the broad evidence demand of paragraph 3 and the critical-facility cycle of Section 39 — the special rules for important entities under Section 62, what an on-site inspection actually looks like, the escalation ladder that can end in public naming, and the fine table of Section 65 for the audit world. For every essential and important entity under Section 28 BSIG, this is the question to answer before the letter arrives.
The three evidence paths — and the fourth for important entities
The first path is the sharpest because it needs no waiting period: under Section 61(1) BSIG the BSI can order individual essential entities to have audits, inspections or certifications carried out by independent bodies — covering the duties of Section 30(1), the incident-reporting duty of Section 32 and even the management training evidence of Section 38(3). This power has existed since the act entered into force on 6 December 2025. Nobody has to wait three years for it.
The second path is the broad one: under Section 61(3) the BSI may demand evidence of the fulfilment of individual or all listed duties from other essential entities — but at the earliest three years after entry into force, i.e. from December 2028, and for licensed hospitals five years. What can be demanded then is not a form but a dossier: the results of audits, inspections or certifications including the security deficiencies uncovered, the underlying documentation, and where deficiencies exist a remediation plan plus proof of their removal. Which entities are selected follows Section 61(4): degree of risk exposure, size, likelihood and severity of potential incidents and their societal and economic effects.
The third path is the fixed rhythm of Section 39 for operators of critical facilities: evidence through security audits, inspections or certifications no later than three years after first or renewed operator status, then every three years — results including deficiencies go to the BSI, which can demand the underlying documentation and a remediation plan. Legacy operators under the former Section 8a carry transitional deadlines, and facilities designated under Section 5(7) of the KRITIS Umbrella Act are exempt.
| Path | Who it hits | When |
|---|---|---|
| Individual audit order — Section 61(1) | Essential entities, one by one | Any time since 6 December 2025 |
| Broad evidence demand — Section 61(3) | Essential entities, selected by risk criteria | At the earliest December 2028; hospitals five years |
| Critical-facility cycle — Section 39 | Operators of critical facilities | Every three years; legacy operators on transition |
| Ex-post suspicion check — Section 62 | Important entities | Only when facts justify the assumption of a breach — then the full Section 61 toolkit applies |
What an on-site inspection looks like
Section 61(5) describes the mechanics without much imagination required: the BSI may verify compliance at essential entities and may use a qualified independent third party to do so. The entity must let the BSI and its agents enter business and operational premises during usual operating hours, present the relevant records, documents and materials, provide information and grant the necessary support. Refusing is not a negotiation position — it is its own offence. Section 65(2) no. 17 makes the refused entry, the withheld document and the denied answer punishable with up to 100,000 euros.
One detail deserves quoting because it shows the statute's calibration: fees and expenses for the inspection are charged only where the BSI acted on indications raising legitimate doubts about compliance — Section 61(5) sentence 4. The routine check is free; the suspicion check is billed to you. The incentive structure is deliberate: the entity that attracts suspicion pays for the verification of it.
The escalation ladder after the audit
What follows a finding is staged. Under Section 61(6) the BSI can order the measures necessary to prevent or remedy an incident or deficiency, together with a suitable remediation plan, proof of remediation and status reporting within a set deadline — in urgent danger even without coordinating with the supervisory authority first. Under paragraph 7 it can issue orders for the implementation of the duties — including the adoption of concrete recommendations formulated in a security inspection. An auditor's recommendation thereby becomes binding law in the individual case.
Paragraph 8 is the reputational step: the BSI can order the entity to inform the persons for whom it provides services about the nature of a significant cyber threat — and it can order the entity to make information about its violations public according to BSI specifications. The entity publishes its own shortcomings on order. Beyond that sits the step we covered two days ago: under Section 61(9), continued non-compliance can lead the competent supervisory authority to suspend licences and temporarily bar unreliable managers from their function. And paragraph 11 closes a loop worth knowing: where the BSI, in supervising, finds a breach that may constitute a GDPR-reportable personal data violation, it informs the data protection authorities without delay — the supervisor feeds the second supervisor.
Does the ISO 27001 certificate count? — the honest answer
The statute names no standard, no scheme and no certificate. Its instruments are audits, inspections and certifications by independent bodies — a certificate is one permissible evidence form, not the only one and not a prescribed one. What counts as suitable is set by the BSI through public notice under Section 61(2); until such notices specify schemes, the individual case decides.
The practical reading is twofold. An ISO 27001 certificate is a useful vehicle: it proves an audited management system, and auditors can read it. But it is not a legal free pass — it attests the system within its scope, not the complete implementation of every Section 30 measure, and the audit that Section 61 orders goes where the order points, not where the certificate ends. Conversely, anyone selling an "NIS2 certificate" sells a marketing product — there is nothing in the statute by that name. The question worth paying for is not "which certificate" but "which evidence can I produce tomorrow".
What disobedience costs — the fine table of the evidence world
The catalogue prices the audit offences in three tiers — and the pattern matters: the order itself is the cheap violation; what it uncovers runs in the top bracket.
| Conduct | Frame | Provision |
|---|---|---|
| Ignoring a Section 61 order (evidence demand, measure orders, implementation orders, publication order) | Up to 500,000 € | Section 65(2) no. 1 lit. c, (5) no. 5 |
| Refusing entry, withholding documents, denying information during an inspection | Up to 100,000 € | Section 65(2) no. 17, (5) no. 6 |
| Critical-facility evidence not produced, late or incomplete | Up to 1,000,000 € | Section 65(1), (2) no. 10, (5) no. 4 |
| The underlying Section 30 breach the audit uncovers — including the missing documentation of it | Up to 10M € / 7M €; 2 % / 1.4 % of turnover above 500M € | Section 65(2) nos. 2–3, (5) no. 1, (6)–(7) |
Two quiet rows deserve attention. The first is Section 65(2) no. 3: failing to document the implementation of Section 30 correctly or completely sits in the same top bracket as failing to implement it — the missing paper trail is priced like the missing measure. The second is structural: Section 65(9) keeps the fine with the entity by excluding the redirection onto the acting officer, and paragraph 10 names the BSI itself as the enforcing authority. The office that audits you is the office that fines you.
Evidence readiness instead of certificate collecting
The management question is not "which certificate do we buy" but "what can we produce tomorrow" — because Section 61(5) imagines precisely that: the inspector who asks for the records during usual business hours. Five positions decide whether that visit is a procedure or a crisis:
| Position | What it must withstand | Anchor |
|---|---|---|
| Documentation of the Section 30 measures | Its absence is a top-bracket offence on its own — Section 65(2) no. 3 | Section 30(1) sentence 3 |
| A producible dossier, not a filing cabinet | Records and documents must be presentable during usual hours | Section 61(5) |
| ISO 27001 as vehicle, not substitute | It documents a management system; the audit checks the Section 30 duties | Section 61(1)–(2) |
| A remediation-plan discipline | Documented deficiencies with a plan beat concealed ones — the statute expects deficiencies to be reported, including to the BSI under Section 39 | Section 61(3), Section 39(1) |
| The KRITIS calendar | Operators of critical facilities count in three-year cycles, starting from operator status | Section 39(1) |
One connection to yesterday deserves emphasis: the report under Section 32 is also the most common trigger of the suspicion check under Section 62. An entity that reports an incident hands the BSI the facts that justify the assumption the statute needs. That is no argument against reporting — the missed report is itself an offence — but it is the strongest argument for evidence readiness: after the incident, somebody will read what you built.
The honest remainder: what the statute does not promise
Three caveats keep the picture straight. First, no guarantee of being audited: an entity that is never selected still carries the full Section 30 duty — the evidence power is an instrument, not the obligation itself. Second, no certificate protects against the incident — and the incident activates the reporting duty, which feeds the suspicion file, which can trigger the audit. Third, the lower fine frames for the audit offences are not a discount on compliance — they price disobedience to orders, while the conduct the orders target runs in the top bracket.
Whoever takes one sentence from this piece: there is nothing to buy called NIS2 conformity. There is something to build: the ability to demonstrate, on demand, that the Section 30 measures do not live on paper. The audit does not announce itself as a deadline — it arrives as a letter, and what it finds is the state you have today.
Related service
Turning obligations into systems
This article clarifies the legal position. It gets implemented in software and processes: product inventory, reporting channel, data access, invoice format, update documentation. We take the inventory off mid-sized companies, order the obligations by deadline and effort and, if you wish, implement them.
IT strategy consultingFrequently asked questions about NIS2 evidence
Do I need an NIS2 certificate?
No — the BSIG knows no mandatory certification. What the statute provides is an evidence power of the BSI: Section 61(1) allows orders for audits, inspections or certifications by independent bodies, and Section 39 prescribes a fixed three-year evidence cycle for operators of critical facilities. A voluntary certificate can support this — but nobody can demand an ‘NIS2 certificate’ that the statute does not contain.
Does my ISO 27001 certificate count as NIS2 evidence?
The statute names neither a standard nor a scheme. Section 61(2) BSIG allows the BSI to set technical and organisational requirements for the auditing bodies and requirements for the suitability of evidence by public notice — until then, the individual case decides. An ISO 27001 certificate is a solid building block of evidence readiness, but no free pass: it attests a management system, not the complete implementation of every Section 30 BSIG measure. Whoever takes the certificate for the evidence confuses the instrument with the obligation.
When can the BSI audit us?
For essential entities, at any time in the individual case — Section 61(1) BSIG has been in force since the act entered into force on 6 December 2025. The broad evidence demand against further essential entities is possible at the earliest three years after entry into force, i.e. from December 2028; licensed hospitals have five years. Important entities are audited only ex-post under Section 62 — when facts justify the assumption of a breach of duty, such as a filed incident report.
Do I have to grant auditors access to my premises?
For essential entities: yes. Section 61(5) BSIG obliges the entity to let the BSI and persons acting on its behalf enter business and operational premises during normal operating hours, to present records and documents, to provide information and to grant support. Refusing is a separate regulatory offence — Section 65(2) no. 17, with a frame of up to 100,000 euros.
What does a BSI inspection cost?
It depends on the trigger. Section 61(5) sentence 4 BSIG permits fees and expenses only where the BSI acted on indications raising legitimate doubts about compliance. The routine inspection or evidence demand without suspicion is therefore free of charge — the suspicion-based inspection is not. Not to mention the internal cost of an audit: preparation, documentation, accompaniment.
Can the BSI have my violations published?
Yes — and that is the step most underestimate. Section 61(8) no. 2 BSIG allows an order requiring the entity to make information about violations of its duties public according to specifications set by the BSI. The entity publicises its own violations on order. In addition, paragraph 8 no. 1 can order the notification of potentially affected service recipients. Both orders sit in the fine catalogue — up to 500,000 euros for non-compliance.
Do different rules apply to operators of critical facilities?
Yes, a dedicated cycle. Section 39 BSIG obliges operators of critical facilities to evidence the implementation of the measures at the latest three years after first or renewed operator status and then every three years through security audits, inspections or certifications — the results, including uncovered security deficiencies, go to the BSI, and a remediation plan can be demanded. Legacy operators under the former Section 8a have transitional deadlines. Breaching this evidence duty carries a frame of up to one million euros.
Sources, status and note: All provisions were checked verbatim against the statute texts, retrieved on 20 September 2026: Section 61 BSIG for the audit orders, the evidence demands, the on-site inspection powers, the fee rule, the escalation ladder and the GDPR hand-off in paragraph 11; Section 62 for the ex-post rule covering important entities; Section 39 for the three-year critical-facility evidence cycle and its transitional rules; Section 30 for the measures whose documentation is itself enforceable; Section 28 for the two entity categories; Section 2 for the definitions; and Section 65 for the fine catalogue — no. 1 lit. c and no. 17 of paragraph 2, the 500,000-euro and 100,000-euro frames of paragraph 5 nos. 5 and 6, the one-million frame for Section 39 evidence in paragraph 5 no. 4, the top brackets of paragraphs 5 to 7, the organ-liability exclusion in paragraph 9 and the BSI as enforcing authority in paragraph 10. On the European level, Directive (EU) 2022/2555, Articles 34 and 35 on supervision and enforcement. This is a professional assessment, not individual legal advice; where a choice matters, take counsel.
Related insights