An auditor does not want to read policy, they want to see evidence that the policy runs. These guides translate NIS2 art. 21, ISO 27001 Annex A and the CRA into concrete server tasks and show how to collect evidence that still holds up six months later. We describe how to collect evidence, not whether you are compliant — that remains a legal assessment.
From 1 January 2027 AWS validates MSP partners only against Validation Checklist 8.0: 24 new and 27 rewritten controls, with GenAI observability, toil measurement and AI governance as new blocks. This is the method to know where you stand in one afternoon: which controls you already cover with existing systems, which need a time series you must start today, and which are purely organisational. With two scripts (AI-dependency inventory and toil baseline) and a fill-in worksheet.
Control A.8.8 requires you to identify, assess and address vulnerabilities in a timely way. Most organisations prove that with a policy and a screenshot of a scanner. An auditor wants to see the chain: when the CVE became known, when you saw it, what you decided, when it was closed. This is how to pull those four timestamps automatically from your servers and turn them into a metric — MTTR per severity — you can show every quarter.
ISO 27001 A.5.18 and NIS2 Art. 21(2)(i) require you to periodically check who has access and whether that's still right. In practice that becomes an afternoon of spreadsheets, or it doesn't happen. This script turns the review into an hour: it lays the technical inventory (servers, sudo, keys, IdP accounts) next to the HR list, flags every deviation, and produces the signed report an auditor accepts.
No policy, no intentions: an auditor wants artefacts with a date. These are the twelve that come up in virtually every CyFun or NIS2 audit, with the command that produces each one, and an evidence-pack.sh that puts everything in one signed archive that can still be verified six months later.
NIS2 Article 21(2) lists ten measures in legal language. This is the translation into what you do on your servers on Monday — per measure the command, the file or the script that produces the evidence. With the Belgian context: the law of 26 April 2024, the CCB, CyberFundamentals and the registration duty.