A complete NIS2 policy stack tells me what management intended. It does not tell me what happened when a control was used or tested. To see the difference, ask your security lead for one current risk decision and the reporting route that carried it towards management. Give them 30 minutes, with no special audit pack prepared in advance.
If the answer is “we can put that together next week”, you have found a traceability problem. That does not prove the control failed. It shows where to investigate.
The pattern appears in Denmark's current NIS2 supervision material. On 2026-05-19, Styrelsen for Samfundssikkerhed, SAMSIK, began a survey-based review of all 98 Danish municipalities. Its six-page questionnaire starts with policies and implementation, then continues into maintenance, documentation and evaluation.
This article turns that pattern into a retrieval drill: choose one evidence trail from five candidates and give it 30 minutes. Passing the drill is not proof of NIS2 compliance or control effectiveness. It tells you whether another person can follow a current decision or action through the records normal work produced.
SAMSIK's review covers municipalities. It does not give us the inspection script that a private SaaS company, managed service provider or manufacturer will face. Different authorities supervise different sectors. A supplier outside direct NIS2 scope may meet similar questions through a customer review instead. I would not copy the questionnaire and call it a private-sector audit programme. I would use it for something narrower: to see how a Danish authority moves from an approved document to questions about what happened afterwards.
Approval is not supervision
Policy work is necessary because it settles decisions that would otherwise remain vague. Policies name owners, set expectations and give teams a common reference point.
The mistake was treating approval as proof of operation.
The Danish NIS2 Act, §§ 6 and 7, requires covered essential and important entities to take appropriate and proportionate technical, operational and organizational measures across ten areas. It separately requires the management body to approve those measures and supervise their implementation.
Consider an access-control policy approved in 2025. The approval records a management decision. It says nothing about whether a role change in 2026 led to the right access being removed, whether privileged accounts were reviewed, or whether an exception was accepted by the right owner. Those facts live elsewhere: in requests, approvals, tickets, reviews and decisions.
The same distinction applies to a supplier outside direct scope. Sending a policy pack may answer the first customer request. It does not show whether the stated controls still operate when the contract comes up for renewal.
Four recurring lenses reveal where the record breaks
Across the SAMSIK questionnaire, I see four recurring operating lenses: implementation, maintenance, documentation and evaluation. SAMSIK does not present them as one formal sequence. They appear in different combinations across the questionnaire.
For this drill, I add another question: can a second person connect the record to a named owner, decision or action? That attribution test is mine, not a separate SAMSIK requirement.
SAMSIK's municipal-supervision FAQ says there is no requirement for a particular format or for a separate document that mirrors every listed requirement. Policies and procedures must cover the substance, work as intended and be documentable.
My narrower takeaway for a mid-market company is simple. You do not need one document per requirement. You do need normal work to leave records that another person can follow.
Can you follow one risk to its acceptance and reporting route?
If I had 30 minutes to test one evidence trail, I would start with a current risk that met the organization's own escalation or reporting threshold.
The municipal questionnaire asks whether risk assessments are documented, whether a treatment plan is maintained, whether named risk owners accept the treatment and residual risk, and whether management receives appropriate reporting. Behind those questions is a chain of accountability, but that does not mean every individual risk needs its own board-paper line.
Suppose a critical customer-facing service still depends on an administrator account without phishing-resistant authentication. I would want to see the assessment, the named owner or delegated acceptance authority, the treatment decision, a deadline and temporary safeguards where applicable, the acceptance of what remains, and the reporting route. If the risk met the threshold for individual management reporting, I would also look for the material in which it appeared.
If those pieces exist but cannot be connected, the organization has stored evidence without creating a usable trail. If the decision depends on personal memory or unowned chat fragments that cannot be tied to an approved decision, the process did not leave a dependable record.
That makes it hard for management to supervise the measure, hard for a control owner to know what was accepted and hard for the next reviewer to distinguish a live decision from an abandoned one.
Can you show what happened when one control was tested?
Incident handling makes the difference visible. SAMSIK asks whether procedures have been implemented to identify, detect, analyse and respond to incidents. It also asks whether monitoring and logging support that work, and whether log files are maintained, documented and analysed.
Pick one recent alert or incident. When was it detected? Who assessed it? What severity was assigned? What action followed? Was there a reporting decision? What changed afterwards?
A completed ticket, a short timeline, a decision log and a follow-up action can show what happened in that case. They do not establish how the control performed across every event or system.
Then inspect one restore. A backup report records that the platform reported a completed job. A dated restore result shows whether the tested procedure met its stated recovery objective for the tested scope and conditions. Without a restore test, you do not know whether the backed-up data or service can be recovered.
Finally, ask why the current test plan covers these systems at this frequency. An annual penetration test may be useful, but “we run one every year” states a schedule, not an effectiveness argument. The useful record connects current risk, test scope, findings and the control changes that followed.
Can a supplier and a privileged account survive a spot check?
A supplier register is easy to mistake for supplier-risk evidence. It may be accurate and still answer only one question: who do we buy from?
For one critical provider, can the company connect the service to a risk assessment, the controls it decided to require, the relevant contract terms, the latest assurance review and any open issue? If the contract predates the risk model, or the assessment came from a generic template that says little about the actual service, those records cannot yet be linked into one decision trail.
SAMSIK's questions ask whether supplier procedures have been implemented, whether risks for specific suppliers and service providers are identified and assessed, and whether agreements address supply-chain and cybersecurity requirements.
Access control produces the same kind of gap. Test the policy against one joiner, one role change and one leaver from the last quarter. Then inspect one active privileged account. Can you follow the request, approval, current status and latest review? For a disabled account or departed user, can you also show removal? Do the records agree with the systems and services the company actually uses?
This is where an old asset inventory becomes an operational problem. Nobody can make a reliable access or supplier decision about a service the organization has not identified.
How current should NIS2 operating evidence be?
An evidence record is not current merely because someone changed the date. Its age should make sense for the risk, the control and what has changed since the last review.
Access removal should follow the role change or departure that triggered it. A supplier assessment may remain useful until a scheduled review or a material change in the service, the threat picture or the contract. A risk acceptance should still rest on assumptions that hold. A restore record should match the recovery-testing cadence the business decided it needed.
Ask whether the record still supports the decision or control today. A named owner should be able to answer without changing the evidence after the question arrives.
Choose one evidence trail and set the timer
Thirty minutes is my diagnostic window, not a legal threshold or a compliance pass mark. Select one critical service or sample, then choose one of these five evidence trails. Use the records where they normally live. Do not assemble a new audit pack for the exercise.
Risk decisions. One risk from assessment through treatment, acceptance authority and the appropriate management-reporting route.
Incidents. One recent incident or alert from detection through decision and follow-up.
Effectiveness. A dated result for one named measure and service, including the expected outcome, tested scope, exclusions, observed result and resulting action.
Suppliers. The risk decision, security terms, latest review and open issues for one critical supplier.
Privileged access. For an active account, the request, approval, current status and latest review. For a disabled account, add the removal record.
For the selected trail, note the retrieval time, last update, named owner and the decision or action it supports. Then compare at least one key statement with the authoritative source system or observed result.
A complete trail clears only the retrieval and traceability screen. It does not prove compliance or that the control is effective across its full scope. A missing link is a record or retrieval problem. A source-system result that contradicts the record may point to a control problem.
If the trail takes a week to reconstruct, fix the missing owner, record, review or retrieval route. Do not commission another policy to hide the break.
The useful question from Denmark's public supervision material is what comes after approval: can you show what happened?
If the drill exposes several breaks and you need an independent view of what matters first, you can book a 30-minute scoping call.