We've been told NIS2 applies to us. Will an auditor accept what we've done?

We’ve started putting security measures in place for NIS2, but there’s no “NIS2 certificate” I can point at. How do we know a regulator or a customer will accept what we’ve done?

NIS2 isn’t a certificate you earn. It’s a set of duties you have to be able to demonstrate you’re meeting. So “will it be accepted?” comes down to: can you show, on request, that you have the risk-management measures Article 21 asks for, and that you can report a significant incident on the clock (Article 23)?

The practical test auditors and customers apply is evidence, not paperwork volume: a current risk assessment, the measures that treat those risks, and records that you actually operate them. If you’re already building an ISO 27001-style management system, most of that evidence is the same. NIS2 largely sits on top of it rather than being a separate pile of work.

If you’re unsure whether a specific measure “counts”, post it here with the risk it’s meant to treat. People who’ve been through a NIS2 conversation with their competent authority can tell you if it’s the right shape.