{"id":4074,"date":"2026-07-28T09:15:00","date_gmt":"2026-07-28T07:15:00","guid":{"rendered":"https:\/\/www.lablogic.pl\/?p=4074"},"modified":"2026-09-13T22:48:55","modified_gmt":"2026-09-13T20:48:55","slug":"what-should-a-nis2-gap-analysis-contain","status":"publish","type":"post","link":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/","title":{"rendered":"What should a NIS2 gap analysis contain?"},"content":{"rendered":"\n<p class=\"ll-art-meta wp-block-paragraph\"><a href=\"https:\/\/www.lablogic.pl\/en\/michal-rutkowski\/\"><strong>Micha\u0142 Rutkowski<\/strong><\/a> \u2022 for boards and senior management \u2022 published July 28, 2026 \u2022 updated August 19, 2026 \u2022 9 min read<\/p>\n\n\n\n<div class=\"wp-block-columns ll-art-shell is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column ll-art-rail is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-railinner is-layout-constrained wp-block-group-is-layout-constrained\">\n\n\n\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column ll-art-main is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-answer is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 id=\"krotka-odpowiedz\" class=\"wp-block-heading\">Short answer<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A NIS2 gap analysis (also called a gap assessment) has to let the board take three decisions. What the organisation must meet, where it falls short and in what order it closes the difference. Every gap should therefore be tied to a specific obligation under the Polish Act on the National Cybersecurity System (KSC), described together with what was checked, and completed by naming the evidence with which the organisation will demonstrate that the gap is closed. The act does not require a gap analysis and does not prescribe its form, so one thing decides the value of the document. It is whether an implementation plan can be built from it and its findings shown during supervision.<\/p>\n<\/div>\n\n\n\n<h2 id=\"dlaczego\" class=\"wp-block-heading\">Why the question comes up at all<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A gap analysis is usually the first piece of work a board buys in once it has established that the organisation falls under the act. A few weeks later an extensive report arrives at a board meeting, with a numerical score and a declaration of compliance somewhere in the tens of per cent. The board cannot approve either the scope of work or the budget on that basis, and the person running the topic cannot allocate tasks, because they do not know who would carry them out.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reason is simple. The act does not know the concept of a gap analysis and describes neither its method nor its result. That left a definitional gap which every provider fills in its own way \u2014 some measure the organisation against the catalogue of statutory obligations, others against an industry standard, others still against their own checklist. The three results look alike and mean different things.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The act does say plainly what the organisation may be asked about. The competent authority for cybersecurity may request evidence that the requirements referred to in Article 8(1) have been implemented, and its supervision of essential entities is preventive in character, not only after the fact. That settles what is genuinely needed in a gap analysis. Not a score, but knowledge of what the organisation has today and what it lacks in order to answer such a request.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then there is the calendar. Entities that met the qualification criteria on April 3, 2026 implement the obligations under Chapter 3 of the act within twelve months, and the first audit of an essential entity falls due within twenty-four months of that date. An entity that meets the criteria later has the same twelve and twenty-four months, counted from the day it meets them. A gap analysis is supposed to translate that calendar into tasks. If it does not, it remains a description of the state of the organisation.<\/p>\n\n\n\n<h2 id=\"co-ustalic\" class=\"wp-block-heading\">What to establish before deciding<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Against which baseline was the organisation measured<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is the first question worth asking once the result arrives, and the only one that invalidates everything else. A gap analysis measured against an industry standard shows the maturity of the information security management system, but it does not answer the question whether the organisation performs its statutory obligations. The two sets overlap but they are not the same.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The act itself marks out the proper baseline. The provision on the liability of the head of the entity (Article 8c(1)) lists the obligations that person answers for, and that list is the closest statutory equivalent of the scope of the analysis. Beyond the information security management system it covers registration obligations, incident handling and reporting, and security documentation. It also covers three things that are remembered least often. Designating people for contact with the entities of the national cybersecurity system, verifying the clean criminal record of staff admitted to the relevant tasks, and the audit. An analysis that covered only the technical measures in Article 8 describes a single provision, not the scope of the entity\u2019s obligations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second dimension is even easier to miss.<\/p>\n\n\n\n<div class=\"wp-block-group ll-art-zdanie is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<p class=\"wp-block-paragraph\">Remember<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The baseline is not the same for all entities covered by the act, and it is settled by <a href=\"https:\/\/www.lablogic.pl\/en\/does-every-organization-fall-under-nis2\/\">the criteria for qualifying an entity<\/a>.<\/p>\n\n<\/div>\n\n\n\n<figure class=\"wp-block-table ll-art-table\"><table><thead><tr><th>Type of entity<\/th><th>What the risk-management measures are measured against<\/th><\/tr><\/thead><tbody><tr><td>An essential or important entity to which Article 8(1) applies<\/td><td>The catalogue in Article 8(1), including the technical and organisational measures listed in point 2(a)\u2013(n)<\/td><\/tr><tr><td>An important entity that is a public entity, and the universities indicated in Article 8(3) in respect of their public tasks<\/td><td>Article 8(1) does not apply; the simplified system in Annex 4 to the act applies instead, together with a review at least once a year and documentation of the actions taken<\/td><\/tr><tr><td>Digital entities listed in Article 8b(1), including providers of cloud services, data centres and managed services<\/td><td>Additionally the measures in Commission Implementing Regulation (EU) 2024\/2690, which applies directly<\/td><\/tr><tr><td>Electricity sub-sector entities identified as having a high or critical impact<\/td><td>The identification is made by the minister responsible for energy (Article 52a(2)), not by the entity itself. The measures in Commission Delegated Regulation (EU) 2024\/1366 \u2014 the network code on cybersecurity aspects of cross-border electricity flows \u2014 apply in addition<\/td><\/tr><tr><td>The banking sector and financial market infrastructure<\/td><td>Article 8i disapplies the provisions on the information security management system and on reporting significant incidents. What remains includes qualification and entry in the register, risk assessment together with basic cyber hygiene practices, and the liability of the head of the entity under Articles 8c\u20138f<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If the result does not open by settling which of these arrangements applies to the organisation, the pages that follow describe somebody else\u2019s obligations.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What was in scope and what fell outside it<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The act ties obligations to the information system used in processes that affect the provision of the service. That wording calls for a decision, and the decision should be visible in the document. It should state which services were treated as covered, which systems were assigned to them and on what basis. In a group of companies there is a second determination to make, because qualification and obligations are established separately for each company \u2014 an analysis covering \u201cthe group\u201d leaves the individual entities without a result of their own.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What was not covered matters just as much. Excluding some systems, branches or processes is often justified but it has to be named. A result in which the boundary of the review is invisible turns from a document into guesswork at the authority\u2019s or the auditor\u2019s first question.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How a single gap is described<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A usable description of a gap has three layers and separates them clearly. The first is the required state together with a reference to the provision it follows from. The second is the state found together with the basis for that finding. That basis covers which document was reviewed, which record or configuration was checked and who was interviewed. The third is the difference and its consequence for the organisation, that is, what will happen or what cannot be demonstrated as long as the gap stays open.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second layer is the one most often missing. The sentence \u201cthe incident reporting procedure is incomplete\u201d, without saying which version of the document was reviewed and what was not found in it, is an opinion rather than a finding. Six months on nobody will verify or defend it, and whoever inherits the task will start by repeating the work.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every gap also needs an owner. Not a department, but a role that can take a decision and answer for its consequences. A gap booked to \u201cIT\u201d in an organisation where the business lines decide priorities will not be closed, because its owner has no mandate to change the process.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Where the order of actions comes from<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Priorities are where a gap analysis differs most from a list of shortcomings. A sensible order follows from the risk to the provision of the service, the statutory deadline attached to a given obligation and the dependencies between actions. The order of articles in the act and the ease of doing the work are not criteria, even though in practice they shape plans most often.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Deadlines enter in two ways. Existing entities implement the obligations under Chapter 3 of the act by April 3, 2027, and the first audit of an essential entity falls due by April 3, 2028. A separate deadline runs for the application for entry in the register of essential and important entities, which for existing entities the Minister of Digital Affairs set by announcement at October 3, 2026. Administrative fines may be imposed for the first time after two years from the entry into force of the amending act, but what is deferred is the fines, not the obligations. Preventive supervision of essential entities has not been deferred at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Dependencies between actions settle the rest. Business continuity cannot sensibly be described before systems have been inventoried, and suppliers cannot be held to a level of security the organisation is unable to define for itself. A result that does not put this in order leaves the ordering to the board at its meeting.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What the organisation will use to show a gap is closed<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The last column of a good gap analysis answers the question of how you know a gap is closed. The act divides security documentation into normative and operational, operational documentation being the records evidencing performance of the activities required by the normative documentation, including automatically generated system log entries. That division is worth carrying straight into the result of the analysis, because it settles what has to be produced.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The practical consequence is that the evidence a gap has been closed is rarely the document alone. A policy without records of its application shows intent rather than action and, under supervision, works against the organisation just as its absence would. So if the analysis identifies a gap in the area of backups, the target evidence is the procedure together with the records of restore tests and not the procedure on its own.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What a gap analysis is not<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Three distinctions save the most misunderstandings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A gap analysis is not the audit referred to in Article 15. An essential entity carries out that audit at its own expense at least once every three years, and it may be performed by an accredited body or by at least two auditors meeting the statutory requirements. The act adds a condition of independence. The audit may not be performed by a person who carries out tasks under Article 8 and Articles 9\u201313 in that entity. A copy of the report goes to the competent authority within three working days of receipt. A gap analysis need meet none of those conditions and does not discharge the audit obligation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nor does a gap analysis replace risk assessment. Systematic assessment of the risk of an incident and the management of that risk are a separate, continuous obligation under Article 8(1)(1). A gap analysis may show that the process does not exist \u2014 it does not create it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, the result does not settle matters that remain open outside the organisation, and the most important of them concerns the thresholds for treating an incident as significant. They are set by the Council of Ministers in a regulation (Article 11(4)), except that the regulation in force dates from October 31, 2018, implements the previous directive and sets thresholds for six sectors in the pre-amendment arrangement, by reference to the essential service. It remains in force until new implementing provisions enter into force, and for no longer than twelve months from the entry into force of the amending act. An organisation outside that scope has no threshold to refer to today, and a gap analysis can only note the fact. The risk-management measures for types of entity other than digital ones remain open in the same way \u2014 they are yet to be set by European Commission implementing acts (Article 8b(2)). An honest document lists those points instead of presenting the target state as settled.<\/p>\n\n\n\n<div class=\"wp-block-group ll-art-check is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 id=\"checklista\" class=\"wp-block-heading\">Acceptance checklist for a gap analysis<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To check before accepting the document and before the budget conversation.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The category of the entity and the baseline that follows from it are stated, together with the legal basis.<\/li>\n\n\n\n<li>The scope of the review is described. It names the services, systems and entities covered and excluded, with reasons for the exclusions.<\/li>\n\n\n\n<li>The analysis covers the full catalogue of obligations under Article 8c(1), not only the technical measures.<\/li>\n\n\n\n<li>Every gap carries a reference to the provision the required state follows from.<\/li>\n\n\n\n<li>For every gap it is visible what the finding of fact was based on.<\/li>\n\n\n\n<li>Every gap has an owner identified by a role that can take a decision.<\/li>\n\n\n\n<li>Priorities are justified by risk, deadline or dependency \u2014 not by the order of the provisions.<\/li>\n\n\n\n<li>For every gap the target evidence is named, distinguishing the document from the records of its application.<\/li>\n\n\n\n<li>In the area of incident reporting, the thresholds by which the organisation assesses whether an incident is significant are stated \u2014 or it is noted that no threshold has been set for it today.<\/li>\n\n\n\n<li>Deadlines are tied to the dates that bind this organisation and not given in general terms.<\/li>\n\n\n\n<li>Unresolved points and areas requiring a board decision are listed.<\/li>\n\n\n\n<li>The document contains a concise decision summary that can be presented at a meeting without reading the whole of it.<\/li>\n<\/ul>\n<\/div>\n\n\n\n<h2 id=\"bledy\" class=\"wp-block-heading\">Most common mistakes<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>A score instead of a conclusion.<\/strong> A declaration of compliance somewhere in the tens of per cent does not say what to do first, and under supervision it means nothing.<\/li>\n\n\n\n<li><strong>Measuring against a standard instead of against the act.<\/strong> The result is often valuable in substance, but it does not answer the question whether the statutory obligations have been performed.<\/li>\n\n\n\n<li><strong>Leaving out obligations from outside Article 8.<\/strong> Registration obligations, designating at least two contact people, documentation and incident reporting drop out of the analysis most often, and it is precisely those that have the nearest deadlines.<\/li>\n\n\n\n<li><strong>Treating a gap analysis as the Article 15 audit.<\/strong> An essential entity that considers the matter closed discovers the error only when the audit falls due.<\/li>\n\n\n\n<li><strong>Gaps without an owner.<\/strong> The document then describes the state of the organisation but triggers no action.<\/li>\n\n\n\n<li><strong>Postponing the work because fines have been deferred.<\/strong> The deadlines for performing the obligations run independently of the date from which fines may be imposed.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"wnioski\" class=\"wp-block-heading\">Conclusions and next steps<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The value of a gap analysis is measured by how many decisions can be taken on its basis without additional work. A document in which every gap has a legal basis, an established finding of fact, an owner and target evidence turns into an implementation plan without being rewritten. A document with a score requires that work to be done all over again, usually in-house and without a budget.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The sequence after accepting the result is short. First the board settles what the analysis could not settle. These are the accepted level of risk, the split of work between the in-house team and the provider, and the resources. Then the gaps have to be grouped into tasks with deadlines tied to April 3, 2027, with those that condition the others set apart \u2014 the inventory of systems, the naming of process owners and the incident escalation path. Finally the review rhythm is set, because a gap analysis describes the state on the day of the review and the organisation keeps changing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If, after reading the result, you cannot answer the question of what the organisation would show the authority in response to a request for evidence that the requirements have been implemented, the analysis needs completing before implementation starts.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Related materials<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/does-every-organization-fall-under-nis2\/\">Does every organization fall under NIS2?<\/a><\/strong> \u2014 qualification criteria, size thresholds and the split into essential and important entities; the determination the baseline of a gap analysis depends on.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/\">Where should the board begin preparing for NIS2?<\/a><\/strong> \u2014 the decisions that have to be taken before a gap analysis makes sense.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/what-should-nis2-training-for-the-board-cover\/\">What should NIS2 training for the board cover?<\/a><\/strong> \u2014 the scope of the head of the entity\u2019s responsibility and how to document it.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/how-and-when-to-apply-for-entry-in-the-ksc-register\/\">When and how to apply for entry in the register of essential and important entities<\/a><\/strong> \u2014 deadlines, the data required and the declaration of the head of the entity.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/\">What risk management measures must an essential entity implement?<\/a><\/strong> \u2014 choosing measures in line with the assessed risk and the evidence the authority may request.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-sources\">\n<li>Act of July 5, 2018 on the National Cybersecurity System, consolidated text (as at July 7, 2026) \u2014 ISAP, Chancellery of the Sejm: <a href=\"https:\/\/isap.sejm.gov.pl\/isap.nsf\/DocDetails.xsp?id=WDU20180001560\" target=\"_blank\" rel=\"noreferrer noopener\">isap.sejm.gov.pl<\/a> (in Polish; accessed August 19, 2026)<\/li>\n\n\n\n<li>Act of January 23, 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252) \u2014 transitional provisions, Journal of Laws: <a href=\"https:\/\/dziennikustaw.gov.pl\/D2026000025201.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">dziennikustaw.gov.pl<\/a> (in Polish; accessed August 19, 2026)<\/li>\n\n\n\n<li>Regulation of the Council of Ministers of October 31, 2018 on the thresholds for treating an incident as significant (Journal of Laws 2018, item 2180) \u2014 ISAP: <a href=\"https:\/\/isap.sejm.gov.pl\/isap.nsf\/DocDetails.xsp?id=WDU20180002180\" target=\"_blank\" rel=\"noreferrer noopener\">isap.sejm.gov.pl<\/a> (in Polish; accessed August 19, 2026)<\/li>\n\n\n\n<li>Commission Implementing Regulation (EU) 2024\/2690 of October 17, 2024 \u2014 EUR-Lex: <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:32024R2690\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a> (accessed August 19, 2026)<\/li>\n\n\n\n<li>Commission Delegated Regulation (EU) 2024\/1366 of March 11, 2024 establishing a network code on sector-specific rules for cybersecurity aspects of cross-border electricity flows \u2014 EUR-Lex: <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/ALL\/?uri=CELEX:32024R1366\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a> (accessed August 19, 2026)<\/li>\n\n\n\n<li>Announcement of the Minister of Digital Affairs of April 8, 2026 on the timetable for submitting applications for entry in the register of essential and important entities (Official Journal of the Minister of Digital Affairs, item 7) \u2014 Ministry of Digital Affairs: <a href=\"https:\/\/www.gov.pl\/web\/cyfryzacja\/du-mc-poz-7\" target=\"_blank\" rel=\"noreferrer noopener\">gov.pl<\/a> (in Polish; accessed August 19, 2026)<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-group ll-art-cta is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading ll-nietoc\">Let us see what the analysis says about your organisation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you already have the document but it is unclear what follows from it for the scope of work and the budget, it is worth going through it for legal bases, owners and evidence. Support with NIS2 and KSC readiness covers establishing the scope of obligations, the gap analysis and a plan of actions that can be sustained and demonstrated during an audit.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.lablogic.pl\/en\/nis2-ksc\/\">NIS2 and KSC readiness support<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A gap analysis has to let the board take three decisions. What the organisation must meet, where it falls short and in what order it closes the difference. The act does not prescribe the form, so one thing decides its value.<\/p>\n","protected":false},"author":2,"featured_media":5568,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ll_stan_prawny":"August 2026","footnotes":""},"categories":[74],"tags":[],"class_list":["post-4074","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-nis2"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"A NIS2 gap analysis must enable three board decisions. See what it should contain. The legal basis of each gap, an owner, target evidence and the statutory deadline.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Micha\u0142 Rutkowski\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"A gap analysis must enable three decisions\" \/>\n\t\t<meta property=\"og:description\" content=\"Every gap needs a legal basis, an owner, target evidence and a deadline.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t\t<meta property=\"article:section\" content=\"NIS2 and KSC\" \/>\n\t\t<meta property=\"article:tag\" content=\"nis2\" \/>\n\t\t<meta property=\"article:tag\" content=\"ksc\" \/>\n\t\t<meta property=\"article:tag\" content=\"gap analysis\" \/>\n\t\t<meta property=\"article:tag\" content=\"compliance\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-07-28T07:15:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-13T20:48:55+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"A gap analysis must enable three decisions\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Every gap needs a legal basis, an owner, target evidence and a deadline.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-nis2-gap-analysis-contain\\\/#article\",\"name\":\"NIS2 gap analysis \\u2014 what the final report should contain\",\"headline\":\"What should a NIS2 gap analysis contain?\",\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1.jpg\",\"width\":1200,\"height\":630,\"caption\":\"A score is not an implementation plan \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"datePublished\":\"2026-07-28T09:15:00+02:00\",\"dateModified\":\"2026-09-13T22:48:55+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-nis2-gap-analysis-contain\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-nis2-gap-analysis-contain\\\/#webpage\"},\"articleSection\":\"NIS2 and KSC, Optional\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-nis2-gap-analysis-contain\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"position\":1,\"name\":\"LabLogic\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/#listItem\",\"name\":\"NIS2 and KSC\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/#listItem\",\"position\":2,\"name\":\"NIS2 and KSC\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-nis2-gap-analysis-contain\\\/#listItem\",\"name\":\"What should a NIS2 gap analysis contain?\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"name\":\"LabLogic\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-nis2-gap-analysis-contain\\\/#listItem\",\"position\":3,\"name\":\"What should a NIS2 gap analysis contain?\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/#listItem\",\"name\":\"NIS2 and KSC\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\",\"name\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"email\":\"m.rutkowski@lablogic.pl\",\"telephone\":\"+48586231777\",\"foundingDate\":\"2004\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cropped-lablogic-site-icon-512.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-nis2-gap-analysis-contain\\\/#organizationLogo\",\"width\":512,\"height\":512},\"image\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-nis2-gap-analysis-contain\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"additionalType\":\"https:\\\/\\\/schema.org\\\/ProfessionalService\",\"legalName\":\"LabLogic Consulting Micha\\u0142 Rutkowski\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"ul. Wolno\\u015bci 15\",\"postalCode\":\"81-327\",\"addressLocality\":\"Gdynia\",\"addressRegion\":\"pomorskie\",\"addressCountry\":\"PL\"},\"vatID\":\"PL9580972114\",\"taxID\":\"9580972114\",\"areaServed\":{\"@type\":\"Country\",\"name\":\"Poland\"},\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"founder\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"hasOfferCatalog\":{\"@type\":\"OfferCatalog\",\"name\":\"Services\",\"itemListElement\":[{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"External Data Protection Officer (DPO)\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/external-dpo\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"NIS2 and KSC implementation support\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/nis2-ksc\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"Incident and data breach response\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/incident-response\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"GDPR and NIS2 training\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/training\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"AI Act: roles, obligations and preparation\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/ai-act\\\/\"}}]}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/\",\"name\":\"Micha\\u0142 Rutkowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-nis2-gap-analysis-contain\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Micha\\u0142 Rutkowski\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"jobTitle\":\"Data Protection Officer (DPO), NIS2\\\/KSC and cybersecurity advisor\",\"description\":\"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.\",\"email\":\"m.rutkowski@lablogic.pl\",\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"worksFor\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-nis2-gap-analysis-contain\\\/#webpage\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-nis2-gap-analysis-contain\\\/\",\"name\":\"NIS2 gap analysis \\u2014 what the final report should contain\",\"description\":\"A NIS2 gap analysis must enable three board decisions. See what it should contain. The legal basis of each gap, an owner, target evidence and the statutory deadline.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-nis2-gap-analysis-contain\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1.jpg\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-nis2-gap-analysis-contain\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"A score is not an implementation plan \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-nis2-gap-analysis-contain\\\/#mainImage\"},\"datePublished\":\"2026-07-28T09:15:00+02:00\",\"dateModified\":\"2026-09-13T22:48:55+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"name\":\"Micha\\u0142 Rutkowski - LabLogic\",\"alternateName\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"NIS2 gap analysis \u2014 what the final report should contain","description":"A NIS2 gap analysis must enable three board decisions. See what it should contain. The legal basis of each gap, an owner, target evidence and the statutory deadline.","canonical_url":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/#article","name":"NIS2 gap analysis \u2014 what the final report should contain","headline":"What should a NIS2 gap analysis contain?","author":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"publisher":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1.jpg","width":1200,"height":630,"caption":"A score is not an implementation plan \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"datePublished":"2026-07-28T09:15:00+02:00","dateModified":"2026-09-13T22:48:55+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/#webpage"},"isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/#webpage"},"articleSection":"NIS2 and KSC, Optional"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","position":1,"name":"LabLogic","item":"https:\/\/www.lablogic.pl\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/#listItem","name":"NIS2 and KSC"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/#listItem","position":2,"name":"NIS2 and KSC","item":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/#listItem","name":"What should a NIS2 gap analysis contain?"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","name":"LabLogic"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/#listItem","position":3,"name":"What should a NIS2 gap analysis contain?","previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/#listItem","name":"NIS2 and KSC"}}]},{"@type":"Organization","@id":"https:\/\/www.lablogic.pl\/en\/#organization","name":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","url":"https:\/\/www.lablogic.pl\/en\/","email":"m.rutkowski@lablogic.pl","telephone":"+48586231777","foundingDate":"2004","logo":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/cropped-lablogic-site-icon-512.png","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/#organizationLogo","width":512,"height":512},"image":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/#organizationLogo"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"additionalType":"https:\/\/schema.org\/ProfessionalService","legalName":"LabLogic Consulting Micha\u0142 Rutkowski","address":{"@type":"PostalAddress","streetAddress":"ul. Wolno\u015bci 15","postalCode":"81-327","addressLocality":"Gdynia","addressRegion":"pomorskie","addressCountry":"PL"},"vatID":"PL9580972114","taxID":"9580972114","areaServed":{"@type":"Country","name":"Poland"},"knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"founder":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"hasOfferCatalog":{"@type":"OfferCatalog","name":"Services","itemListElement":[{"@type":"Offer","itemOffered":{"@type":"Service","name":"External Data Protection Officer (DPO)","url":"https:\/\/www.lablogic.pl\/en\/en\/external-dpo\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"NIS2 and KSC implementation support","url":"https:\/\/www.lablogic.pl\/en\/en\/nis2-ksc\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"Incident and data breach response","url":"https:\/\/www.lablogic.pl\/en\/en\/incident-response\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"GDPR and NIS2 training","url":"https:\/\/www.lablogic.pl\/en\/en\/training\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"AI Act: roles, obligations and preparation","url":"https:\/\/www.lablogic.pl\/en\/en\/ai-act\/"}}]}},{"@type":"Person","@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author","url":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/","name":"Micha\u0142 Rutkowski","image":{"@type":"ImageObject","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","width":96,"height":96,"caption":"Micha\u0142 Rutkowski"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"jobTitle":"Data Protection Officer (DPO), NIS2\/KSC and cybersecurity advisor","description":"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.","email":"m.rutkowski@lablogic.pl","knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"worksFor":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/#webpage","url":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/","name":"NIS2 gap analysis \u2014 what the final report should contain","description":"A NIS2 gap analysis must enable three board decisions. See what it should contain. The legal basis of each gap, an owner, target evidence and the statutory deadline.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/#website"},"breadcrumb":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/#breadcrumblist"},"author":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"creator":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1.jpg","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/#mainImage","width":1200,"height":630,"caption":"A score is not an implementation plan \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"primaryImageOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/#mainImage"},"datePublished":"2026-07-28T09:15:00+02:00","dateModified":"2026-09-13T22:48:55+02:00"},{"@type":"WebSite","@id":"https:\/\/www.lablogic.pl\/en\/#website","url":"https:\/\/www.lablogic.pl\/en\/","name":"Micha\u0142 Rutkowski - LabLogic","alternateName":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice","og:type":"article","og:title":"A gap analysis must enable three decisions","og:description":"Every gap needs a legal basis, an owner, target evidence and a deadline.","og:url":"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/","og:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1.jpg","og:image:secure_url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1.jpg","og:image:width":1200,"og:image:height":630,"article:section":"NIS2 and KSC","article:tag":["nis2","ksc","gap analysis","compliance"],"article:published_time":"2026-07-28T07:15:00+00:00","article:modified_time":"2026-09-13T20:48:55+00:00","twitter:card":"summary_large_image","twitter:title":"A gap analysis must enable three decisions","twitter:description":"Every gap needs a legal basis, an owner, target evidence and a deadline.","twitter:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1.jpg"},"aioseo_meta_data":{"post_id":"4074","title":"NIS2 gap analysis \u2014 what the final report should contain","description":"A NIS2 gap analysis must enable three board decisions. See what it should contain. The legal basis of each gap, an owner, target evidence and the statutory deadline.","keywords":null,"keyphrases":{"focus":{"keyphrase":"NIS2 gap analysis","score":0,"analysis":[]},"additional":[{"keyphrase":"gap analysis report NIS2","score":0,"analysis":[]},{"keyphrase":"KSC gap analysis","score":0,"analysis":[]},{"keyphrase":"NIS2 compliance assessment","score":0,"analysis":[]},{"keyphrase":"evidence of NIS2 compliance","score":0,"analysis":[]}]},"primary_term":null,"canonical_url":null,"og_title":"A gap analysis must enable three decisions","og_description":"Every gap needs a legal basis, an owner, target evidence and a deadline.","og_object_type":"article","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"NIS2 and KSC","og_article_tags":[{"label":"NIS2","value":"NIS2"},{"label":"KSC","value":"KSC"},{"label":"gap analysis","value":"gap analysis"},{"label":"compliance","value":"compliance"}],"twitter_use_og":true,"twitter_card":"summary_large_image","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":0,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-08-19 18:09:15","updated":"2026-09-13 20:49:49","seo_analyzer_scan_date":null,"focus_keyword":"NIS2 gap analysis","additional_keywords":["NIS2 gap assessment","gap analysis NIS2"],"truseo_locale":null},"spectra_blocks_featured_image_url":{"thumbnail":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1-150x150.jpg","width":150,"height":150},"medium":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1-300x158.jpg","width":300,"height":158},"medium_large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1-768x403.jpg","width":768,"height":403},"large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1-1024x538.jpg","width":1024,"height":538},"full":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-nis2-gap-analysis-contain-en-1.jpg","width":1200,"height":630}},"spectra_blocks_author_info":{"display_name":"Micha\u0142 Rutkowski","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","author_link":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/","description":"Micha\u0142 Rutkowski \u2014 praktyk ochrony danych i cyberbezpiecze\u0144stwa, w\u0142a\u015bciciel LabLogic. Od 2004 roku pracuje na styku technologii, ochrony danych i zarz\u0105dzania ryzykiem. Pe\u0142ni funkcj\u0119 zewn\u0119trznego IOD\/DPO, prowadzi audyty RODO, kwalifikacj\u0119 i wdro\u017cenia NIS2 oraz ustawy o KSC, wspiera organizacje przy incydentach i naruszeniach ochrony danych, szkoli zarz\u0105dy, kadr\u0119 kierownicz\u0105 oraz zespo\u0142y IT i compliance. Pracuje ze \u015brednimi i du\u017cymi organizacjami, w tym z sektora finansowego i bran\u017c regulowanych."},"_links":{"self":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4074","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/comments?post=4074"}],"version-history":[{"count":14,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4074\/revisions"}],"predecessor-version":[{"id":5420,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4074\/revisions\/5420"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media\/5568"}],"wp:attachment":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media?parent=4074"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/categories?post=4074"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/tags?post=4074"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}