NIS2 · Evidence

Proof that arises in operation — not in a project.

§ 30 Abs. 1 Satz 3 BSIG requires the implementation to be documented. Assemble that only on request and you lose days. Produce it continuously and you export it as a PDF.

The sequence

From operation to audit report in three steps

What separates this from a spreadsheet is not the content but the fact that nobody has to maintain it.

01

The data arises anyway

Agent and agentless checks capture patch level, inventory, backup state and access during normal operation — with timestamp and history.

02

Pick a report

Take a ready-made template or build your own from around 40 widgets. Set the period and scope by customer or site.

03

Send on a schedule

As a PDF in your own branding, to a fixed recipient list, with a dispatch history per run. Or on demand for a given date.

Templates

Six reports that hold up to audit questions

Out of 17 templates that ship with the product — these are the ones asked for in connection with NIS2.

Patch compliance

Patch level across the managed estate for a chosen period, by customer or site. Covers the evidence question on § 30 Abs. 2 Nr. 5 BSIG.

Detailed patch report

Individual updates per device with status and time — for the case where the summary is not enough.

Backup status

State of backup runs across vendor boundaries, including failed jobs.

User audit

Local accounts across the estate: inactive accounts, enabled default administrators, password age.

Incident report

Incidents, warnings and affected devices over a period, with a timeline.

SLA report

Time-weighted availability, mean time to resolution, SLA incidents.

Mapping

Requirement, source, proof

So that in a customer conversation you do not have to point at a brochure, but at the statutory text.

A complete, current inventory of all systems

DVO (EU) 2024/2690, Anhang 12.4

Hardware, software, services and accounts are recorded continuously. The inventory history shows by comparison what changed on which device and when — including the end of operating system support.

Vulnerability and patch management, with a reason where a patch is not applied

§ 30 Abs. 2 Nr. 5 BSIG, DVO Anhang 6.6

Patch level per endpoint with a timestamp, documented approvals naming the decision-maker, exclusions with a stored justification. As a PDF report for a given date.

Logging, in particular of privileged access

DVO Anhang 3.2

Every remote session appears in the device log with person, time and action. Changes to permissions and settings appear in the change log across 26 object types.

Backup and documented recovery testing

§ 30 Abs. 2 Nr. 3 BSIG, DVO Anhang 4.2

Cross-vendor monitoring of backup runs with a status report and notification of failed jobs. The recovery test itself is yours to carry out — octoja evidences the state, not the exercise.

Multi-factor authentication and access control

§ 30 Abs. 2 Nr. 10 BSIG, DVO Anhang 11.2–11.7

Two-factor per account, single sign-on, 17 separate device action rights and an access overview that resolves who may reach which device, and why.

Incident detection for the 24-hour early warning

§ 32 BSIG, DVO Anhang 3.2.4

Alerting with service hours per channel — by phone to the on-call engineer at night. Every alert carries a timestamp, which is what makes the reporting deadline evidenceable.

Protection against malware, detection of unapproved software

DVO Anhang 6.9

Protection status of common antivirus and EDR products, plus a software inventory across the entire estate.

Configuration and change management

DVO Anhang 6.3 und 6.4

Configuration packages as a baseline, checks for deviation in directory permissions, files and registry values.

Traceability

Who, when, what — logged without anyone doing anything

Access

Every remote session with person, time and action. Where the user's consent was overridden, the justification sits alongside it — without a dedicated right it would not have been possible.

Changes

26 object types in the change log, each with a before-and-after comparison. The entries arise in the processing path and cannot be bypassed.

Approvals

Patch cycles carry the approval type, the decision-maker, a timestamp and a note — manual, automatic, inherited or as an emergency cycle.

Boundary

What you still have to do yourself

These points cannot be satisfied out of a piece of software. We name them so you do not walk into a gap during a customer conversation.

Risk analysis and an information security management system
Training and management liability under § 38 BSIG
Personnel security and background checks
Cryptography concepts and physical security
Registration with the BSI, and the reporting itself

This page is an orientation, not legal advice. What governs is the BSIG as amended by the NIS2 implementation act and Implementing Regulation (EU) 2024/2690.

Produce the report with your own data

Request trial access, roll the agent out to a few devices, pull the patch compliance report. After that you know whether it carries your audit questions.