The classic trap
This recital sets a principle of operational proportionality for ILR inspections: the authority must minimise the business impact of its supervisory tasks, but this presupposes that the supervised entity can produce evidence quickly, without halting operations. In practice, essential entities that have not prepared their artefacts (IT mapping, logs, procedures, incident registers) face long, intrusive and disruptive inspections. The ILR does not sanction the recital itself, but it sanctions the inability to respond fast, and that slowness becomes your economic problem, not theirs.
What this recital actually changes for you
- A prepared entity faces a short, targeted inspection; an unprepared one endures weeks of follow-up requests.
- The ILR can run security scans (external attack-surface scans) without necessarily coordinating with your IT team: if your monitoring is not ready, you will discover the findings at the same time as the regulator.
- The expected impact minimisation from the authority assumes in return that you have a single response desk (a pre-built inspection file) to avoid mobilising your whole IT department at every request.
- The 'this disrupts our business' argument does not hold if you have anticipated nothing: it is precisely your lack of preparation that prolongs the audit.
The standing inspection file: your best economic defence
The winning approach is not to endure the inspection but to permanently maintain an ILR-ready file: security policy, asset mapping for annexes I/II, incident register, test evidence, critical supplier contracts, business continuity plan, article 20 board training records. If you hand over this file at D+2, the on-site inspection lasts 1 day instead of 3 weeks.
How Luxgap automates this risk
Our Luxgap Inspection-Ready Vault maintains a permanent NIS 2 inspection vault ready to be handed to the ILR in under 48 hours, turning a potentially paralysing audit into an administrative formality. The tool continuously pulls evidence from Microsoft Defender, Azure Sentinel, CrowdStrike, Wazuh, your DMS (M365 / SharePoint), your ITSM (ServiceNow, GLPI) and your supplier register (Odoo, SAP Ariba) to automatically reconstruct the file required under article 32 of the directive.
- Compiles in real time a structured inspection file aligned with the ILR audit grid, with table of contents, cross-references to NIS 2 articles and cryptographic timestamping of every piece of evidence.
- Detects missing or outdated artefacts (policy unreviewed for 12 months, expired board training, old continuity test) and alerts before the ILR discovers it.
- Generates a 2-page executive briefing for the board, ready to be handed to inspectors at the opening of the audit, which demonstrates cyber maturity and shortens inspection duration.
- Produces a sealed PDF export, enforceable against the ILR, that materialises your preparedness level at a given date and reverses the burden of proof.
- Runs a quarterly mock inspection based on ENISA guides and the ILR checklist to measure your actual response time.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request your demonstration and our teams run a free mock inspection within 48 hours on your real perimeter, to measure how long you would hold today against an ILR audit.