The classic trap
Recital 125 shapes how the ILR and sector authorities will conduct NIS 2 inspections: with trained technical auditors able to challenge your firewalls, databases, encryption and network segmentation. The classic trap is to prepare a flawless 'paper' file (policies, procedures, registers) that collapses the moment an ILR inspector asks to connect to the bastion, to see 90 days of Sentinel logs or to run an nmap from the LAN. The objectivity required by the recital also means the auditor will not rely on your statements: they will verify directly.
What ILR inspectors will actually check
- Effective firewall configuration, perimeter and internal (permissive rules without justification, ANY/ANY, dormant rules).
- Cryptographic robustness: TLS versions, cipher suites, key management, secret rotation.
- Database hardening: default accounts, encryption at rest, environment segregation.
- Real network map vs declared map (VLANs, micro-segmentation, east-west flows).
- Patch level of hardware and firmware, particularly on OT equipment and network appliances.
- Traceability of privileged access and ability to produce accountability evidence.
In other words, on inspection day, your declared posture will be confronted with your measured posture. The gap between the two is what triggers sanctions.
How Luxgap automates this risk
Our Luxgap Inspection Readiness Mirror continuously reproduces the view an ILR inspector would have on your IS: the tool leverages your Microsoft Defender, Azure Sentinel, CrowdStrike, Wazuh, Fortinet, Palo Alto integrations and your SQL/Oracle databases to produce, at any time, the same report a technical auditor would generate after an on-site inspection. No questionnaire to fill in: the tool fetches evidence where it actually lives.
- Scans your firewalls in real time to detect permissive, dormant or contradictory rules, and surfaces the missing business justification.
- Cryptographically audits your exposed endpoints (TLS, cipher suites, expiring certificates) with a score aligned on ENISA and ANSSI guides.
- Identifies database weaknesses (default accounts, missing TDE, excessive DBA rights) by connecting in read-only mode via dedicated service accounts.
- Rebuilds the actual network map from observed flows and confronts it with your declared schema, flagging every divergence.
- Generates a timestamped, cryptographically sealed inspection file PDF, structured exactly like the deliverable expected by the ILR during a control under the law of 28 July 2023.
- Runs a quarterly mock inspection with objective scoring, to measure the gap between declared and measured posture.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS brick depending on your scope. Request a demonstration and our teams will run a free 48-hour blank audit on your real scope, to show you exactly what an ILR inspector would see tomorrow morning.