9 Essential Netwrix Auditor Reports for NIS2 Compliance Audits

NIS2 raises the standard for what can be considered adequate cybersecurity across a large part of the European economy. Organizations operating in energy, transport, finance, healthcare, digital infrastructure, or other sectors classified by the directive as critical can no longer treat formal cybersecurity risk management as optional. The focus has shifted toward how quickly those organizations can demonstrate that the required controls are actually in place and functioning.

Why NIS2 matters right now

NIS2 is the second iteration of the EU Directive on Security of Network and Information Systems. NIS2 took effect on January 16, 2023, while organizations covered by the directive were required to meet its compliance obligations by October 17, 2024. Since that deadline has already expired, regulatory attention has moved beyond preparation. Organizations are now expected to provide evidence showing how the requirements are being met in practice.

The directive divides organizations within its scope into two categories. Essential Entities encompass organizations across sectors such as energy, transport, finance, public administration, healthcare, space, water supply, and digital infrastructure. Important Entities include postal services, waste management, chemicals, research, food production and distribution, digital providers, and manufacturing.

Both categories fall under Article 21, which calls for suitable technical, operational, and organizational safeguards covering risk analysis, incident management, business continuity, access control, and vulnerability management. Compliance therefore requires more than written policies. Auditors need evidence that the relevant controls operate as intended.

This is where a common gap appears. Security policies may define the required approach, while Article 21 requires practical proof of who has access, what actions those users performed, and whether suspicious or unauthorized activity would be detected. Netwrix Auditor helps close this gap by gathering audit data from both on-premises systems and cloud environments. It then converts that data into reports that can answer these questions without requiring administrators to reconstruct the necessary evidence manually after an incident or during an audit.

The nine reports below follow the same general sequence that can be used during an audit or security investigation. The process begins by identifying who holds significant privileges in the environment. It then moves to reviewing how those privileges are used, before confirming that important changes can be traced and that unwanted changes or data loss can be addressed.

Start with who holds power

Effective monitoring begins with understanding which accounts are capable of making significant changes in the environment. The following three reports help map the access surface that would typically attract attention during both compliance reviews and security investigations.

Administrative Group Members identifies members of highly privileged groups, including Domain Admins, Enterprise Admins, and Account Operators. Nested group membership is also included. As a result, the report can reveal cases in which an account has been added to a privileged group such as Domain Admins without appropriate authorization or oversight.

Administrative Group Members lists

Account Permissions provides visibility into the permissions assigned to specific files and folders. It shows access granted both directly and through group membership, while also highlighting permissions assigned to Everyone and Authenticated Users. This makes it possible to assess whether least-privilege principles are actually reflected in existing access rights rather than only documented in policy.

Overexposed Files and Folders extends this analysis by showing which sensitive files and folders can be accessed by particular users or groups. It determines exposure by assessing folder-level and share-level permissions together. This provides visibility not only into which identities have access, but also into the information that becomes exposed because of those permissions.

Then watch what they do with it

Granting access without maintaining oversight creates exactly the kind of visibility gap that NIS2 monitoring requirements are intended to address. The next four Netwrix Auditor reports provide information about user behavior after accounts and permissions have already been established.

User Account Changes tracks key account lifecycle events, including the creation, modification, and deletion of user accounts. It provides a baseline audit trail that can help identify accounts that were created, changed, or granted additional privileges without proper authorization.

All Logon Activity consolidates interactive and non-interactive logons into a single view and includes both successful and failed authentication attempts. This information can serve as important evidence for access-control and monitoring requirements. It is also commonly relevant during investigations when suspicious activity or a security incident needs to be reconstructed.

All User Activity by User expands the available context by presenting session-level activity associated with individual accounts across the environment. This creates a broader view of user behavior that can support both incident investigations and ongoing risk analysis.

All Changes by User

All Changes by User provides an even broader consolidated view. It groups changes made throughout the IT infrastructure according to the person responsible for them. This makes it possible to determine who changed what and when without relying on several separate reports.

Finally, demonstrate what changed and confirm that recovery is possible

Article 21 is not limited to preventive controls. It also requires organizations to maintain visibility into changes and support recovery when information or configurations are lost or altered. The final two Netwrix Auditor reports help provide evidence in these areas.

All Group Policy Changes by Group records changes made to Group Policy Objects, including modifications to settings, links, and permissions. It also identifies the workstation from which the change originated. This helps ensure that unauthorized policy modifications do not remain unnoticed.

Group Policy can influence password requirements, software restrictions, and many other elements of an organization’s overall security configuration. Maintaining a clear history of these changes is therefore particularly important.

All Group Policy Changes by Group

Files and Folders Deleted captures information about removed files and folders, including their associated attributes. This information can support recovery activities as well as investigations associated with the business continuity and incident-handling requirements established by NIS2.

Taken together, these nine reports provide evidence around three central audit questions: which identities are capable of taking significant actions, what actions they performed, and whether those activities can be traced and reversed when necessary.

Beyond Auditor: a broader NIS2 toolkit

Netwrix Auditor helps bridge this gap by gathering audit data across both on-premises infrastructure and cloud-based environments. The directive also requires organizations to protect sensitive information, strengthen authentication, and maintain appropriate control over access. Other Netwrix solutions can support those areas.

Netwrix Data Classification helps identify and classify sensitive information across the environment. This makes it easier to determine which data requires stronger protection.

Netwrix Password Policy Enforcer supports stronger authentication controls of the type explicitly addressed in Article 21.

Netwrix Directory Manager helps maintain consistent and deliberate group membership and access policies across Active Directory and Entra ID. This can reduce the gradual accumulation of unnecessary or unmanaged access rights.

When these products are used together, essential and important entities gain broader capabilities for addressing NIS2 requirements related to evidence, access control, data protection, authentication, and timely incident response.

NIS2 establishes an ongoing expectation that organizations maintain visibility into activity within their environments and can produce supporting evidence when required. The reports described above provide a strong starting point. Their greatest value, however, comes from incorporating them into regular security and compliance processes rather than collecting the necessary evidence only shortly before an audit.

Request a Demo of Netwrix Auditor



    Subscribe to news