Skip to main content
Free resource · NIS2 & DORA

Managed SIEM Compliance Evidence Checklist: NIS2 and DORA

A SIEM can detect every incident and still leave gaps in the evidence an auditor will ask for. This checklist helps you find those gaps before a review does.

  • NIS2 and DORA evidence requirements checklists
  • Log retention and evidence verification worksheet
  • Evidence readiness scoring and gap inventory
— 01 · The challenge

SIEM evaluations focus on detection. Audits focus on documentation.

Neither NIS2 nor DORA requires a specific SIEM platform. Both require you to demonstrate what your monitoring produced during an incident.

What your SIEM is evaluated on
What auditors actually request
Log collection
Incident timelines
Alert generation
Investigation records
Threat identification
Impact assessments
Detection speed
Evidence exports
— 02 · Inside the download

What's inside the Managed SIEM Compliance Evidence Checklist

NIS2 evidence requirements checklist

Assess whether your SIEM supports log retention, incident documentation, and reporting evidence requirements under NIS2.

DORA evidence requirements checklist

For financial entities in scope: ICT incident classification, investigation records, business impact documentation, and audit trail requirements.

Log retention & verification worksheet

Map current retention periods against regulatory requirements across endpoint, authentication, firewall, cloud, application, and email logs.

Compliance evidence gap inventory

Document and prioritize gaps by evidence area, business impact, and owner — not every gap carries the same risk.

Evidence readiness scoring worksheet

Score your evidence readiness across both frameworks and get a rating: High risk, Developing, Established, or Audit-ready.

Readiness rating & improvement guide

Interpret your score and identify priority actions before the next audit cycle.

Your SIEM detected the incident. Could you prove it six months later?

The security controls worked. Find out if the paper trail would too — before a review asks the same question.

Download the checklist
— 03 · Detection ≠ evidence

Detection capability and evidence capability measure different things

A managed SIEM optimized for one is not automatically capable of the other. A SIEM can score well on every metric on the left and still fail an audit on the right.

What detection capability measures
What evidence capability measures
Alert generation from security events
Incident timeline reconstruction
Threat identification speed
Investigation record completeness
Log collection coverage
Evidence retrieval speed
Response time to active threats
Audit trail availability
Rule and use case coverage
Classification consistency
— 04 · Why it matters

Why evidence readiness matters under NIS2 and DORA

NIS2 notification timeline

Significant incidents require an early warning within 24 hours and a detailed notification within 72 hours — grounded in incident timelines, impact assessments, and response actions.

DORA incident classification

Financial entities must classify ICT incidents using documented criteria. Undocumented or inconsistent classification is a finding on its own.

Investigation records

Both frameworks expect investigation activities to be documented and retained. A well-functioning SOC that keeps no investigation records still fails the evidence standard.

Audit trail requirements

DORA mandates audit trails for critical systems and administrative actions. NIS2 expects authentication and access activity to be logged and searchable.

— 05 · FAQ

Frequently asked questions

What is compliance evidence in a managed SIEM context?

The records an auditor will actually ask for: incident timelines, investigation notes, containment decisions, recovery actions, and proof that logs were retained according to policy. Detection alerts are not evidence — documentation of what happened after the alert is.

Does NIS2 require a specific SIEM platform?

No. It requires outcomes: monitoring, incident detection, and records that support regulatory reporting. How you get there is your call. A managed SIEM is the most common way organizations produce that evidence.

What does DORA require for ICT incident documentation?

Classification using documented criteria, investigation records, business impact documentation, and audit trails for critical systems. The practical gap most organizations discover is that the records exist somewhere but can't be produced quickly when requested.

What's the difference between detection readiness and evidence readiness?

Detection readiness is your ability to identify threats. Evidence readiness is your ability to prove what happened. A SIEM can score well on the first and still fail an audit on the second.

How long does this assessment take?

30 to 45 minutes for the checklists and scoring. Longer if pulling a real incident record for the evidence availability test reveals that the documentation is harder to locate than expected — that delay is itself a useful finding.

— 06 · Beyond the checklist

Evaluating a managed SIEM provider?

Most evaluations test detection. Few test evidence production. Q-Sec helps organizations add an audit-readiness dimension to their SIEM strategy, before, during, and after a provider evaluation.

Talk to Q-Sec