Proof that arises in operation — not in a project.
§ 30 Abs. 1 Satz 3 BSIG requires the implementation to be documented. Assemble that only on request and you lose days. Produce it continuously and you export it as a PDF.
From operation to audit report in three steps
What separates this from a spreadsheet is not the content but the fact that nobody has to maintain it.
The data arises anyway
Agent and agentless checks capture patch level, inventory, backup state and access during normal operation — with timestamp and history.
Pick a report
Take a ready-made template or build your own from around 40 widgets. Set the period and scope by customer or site.
Send on a schedule
As a PDF in your own branding, to a fixed recipient list, with a dispatch history per run. Or on demand for a given date.
Six reports that hold up to audit questions
Out of 17 templates that ship with the product — these are the ones asked for in connection with NIS2.
Patch compliance
Patch level across the managed estate for a chosen period, by customer or site. Covers the evidence question on § 30 Abs. 2 Nr. 5 BSIG.
Detailed patch report
Individual updates per device with status and time — for the case where the summary is not enough.
Backup status
State of backup runs across vendor boundaries, including failed jobs.
User audit
Local accounts across the estate: inactive accounts, enabled default administrators, password age.
Incident report
Incidents, warnings and affected devices over a period, with a timeline.
SLA report
Time-weighted availability, mean time to resolution, SLA incidents.
Requirement, source, proof
So that in a customer conversation you do not have to point at a brochure, but at the statutory text.
A complete, current inventory of all systems
DVO (EU) 2024/2690, Anhang 12.4
Hardware, software, services and accounts are recorded continuously. The inventory history shows by comparison what changed on which device and when — including the end of operating system support.
Vulnerability and patch management, with a reason where a patch is not applied
§ 30 Abs. 2 Nr. 5 BSIG, DVO Anhang 6.6
Patch level per endpoint with a timestamp, documented approvals naming the decision-maker, exclusions with a stored justification. As a PDF report for a given date.
Logging, in particular of privileged access
DVO Anhang 3.2
Every remote session appears in the device log with person, time and action. Changes to permissions and settings appear in the change log across 26 object types.
Backup and documented recovery testing
§ 30 Abs. 2 Nr. 3 BSIG, DVO Anhang 4.2
Cross-vendor monitoring of backup runs with a status report and notification of failed jobs. The recovery test itself is yours to carry out — octoja evidences the state, not the exercise.
Multi-factor authentication and access control
§ 30 Abs. 2 Nr. 10 BSIG, DVO Anhang 11.2–11.7
Two-factor per account, single sign-on, 17 separate device action rights and an access overview that resolves who may reach which device, and why.
Incident detection for the 24-hour early warning
§ 32 BSIG, DVO Anhang 3.2.4
Alerting with service hours per channel — by phone to the on-call engineer at night. Every alert carries a timestamp, which is what makes the reporting deadline evidenceable.
Protection against malware, detection of unapproved software
DVO Anhang 6.9
Protection status of common antivirus and EDR products, plus a software inventory across the entire estate.
Configuration and change management
DVO Anhang 6.3 und 6.4
Configuration packages as a baseline, checks for deviation in directory permissions, files and registry values.
Who, when, what — logged without anyone doing anything
Access
Every remote session with person, time and action. Where the user's consent was overridden, the justification sits alongside it — without a dedicated right it would not have been possible.
Changes
26 object types in the change log, each with a before-and-after comparison. The entries arise in the processing path and cannot be bypassed.
Approvals
Patch cycles carry the approval type, the decision-maker, a timestamp and a note — manual, automatic, inherited or as an emergency cycle.
What you still have to do yourself
These points cannot be satisfied out of a piece of software. We name them so you do not walk into a gap during a customer conversation.
This page is an orientation, not legal advice. What governs is the BSIG as amended by the NIS2 implementation act and Implementing Regulation (EU) 2024/2690.
Produce the report with your own data
Request trial access, roll the agent out to a few devices, pull the patch compliance report. After that you know whether it carries your audit questions.