From Paper to Proof · July 2026
Can your clients prove their controls actually work?
Since Germany's NIS2 transposition took effect in December 2025, clients no longer ask only ‘are we secure?’, but ‘can we prove it?’. We held around 100 open, qualitative conversations with German data protection and information security officers to learn how they answer that question, and what it means for your client conversations ahead of the Dutch Cyberbeveiligingswet (15 August 2026).
A technical mapping is an indicator and a prioritisation aid, never an automated compliance proof. Offer it confidently for NIS2; for the GDPR the final legal assessment stays with the DPO.
Download the full report
The complete study: the gap between documentation and proof, why NIS2 maps to technical evidence more readily than the GDPR, why ownership needs a name and a deadline, and practical talking points for your client conversations.
Download report (PDF)No registration required. The report is free to download.
Key findings
- The gap is proof, not technology. Controls are documented once and then rarely re-tested, until accountability quietly disappears in the annual audit cycle.
- NIS2 maps to technical evidence more readily than the GDPR. Offer technical proof confidently for NIS2; for the GDPR it stays a complementary building block, and a finding is never a violation on its own.
- Ownership beats enforcement, but only with a name and a deadline. “IT is responsible” does not hold up with a regulator; every control needs a named, time-stamped owner and a path to senior management.
- This is the MSP opportunity. SMEs cite a lack of specialised expertise (62%) and internal capacity (39%); MSPs close that gap only if they can show, not just claim, that controls work.
About this study
Guardian360 held around 100 open, qualitative conversations with German data protection officers, information security officers and auditors between June and July 2026, validating an approach that links technical security findings to GDPR, NIS2 and ISO 27001 obligations. This is not a representative benchmark: the percentages reflect the responses received and should be read as a qualitative tendency, not as statistically robust figures.
Meet us at TopGolf Oberhausen
This report was prepared for the Cross-border Cybersecurity Networking Event for MSPs and IT system houses (TopGolf Oberhausen, 2 September 2026), organised by the Netherlands government and InnovationQuarter with Passguard, SecuMailer, SecureMe2, DMARC Advisor and Guardian360. Are you an MSP? Join us for an afternoon on NIS2, digital resilience and a round of golf.
Register for the event →Want to show proof, not just documentation?
Guardian360 Lighthouse runs technical scans daily rather than once a year and links every finding to a named, time-stamped recommendation, mapped to ISO 27001, GDPR, NIS2, DORA and OWASP. It is a technical complement to your management system, not a replacement. Leave your details and we will show you how it supports proof of effectiveness, for you and your clients.