For thirty years, the revenue of a cybersecurity audit practice has been governed by one equation: auditors multiplied by billable days. Demand was rarely the constraint. Qualified capacity was.
NIS2 just broke that market open - and it did so country by country, because audit markets are national. The directive is European, but every member state transposed it into its own law, with its own supervisory authority, its own rules on who may audit, its own audit cycle, and its own deadlines. A firm does not compete for Europe. It competes for its own country's wave.
This briefing explains what that wave looks like at EU level, why national auditor pools cannot serve it with traditional delivery, and what changes when the delivery model changes. Where we go into detail, we use Czechia and Slovakia as worked examples - two markets where the numbers are publicly traceable and the waves are arriving now.
Legal basis: HU Act XXIII/2023 · SK Act 366/2024 · CZ Act 264/2025 and Decree 409/2025 · HR OG 14/24 and 135/24 · PL KSC Act Art. 15 · BE Royal Decree 2024 and CCB conformity assessment scheme · DE §39 BSIG · AT NISG 2026 · RO DNSC order pending
A market that did not exist two years ago
Across the EU, well over 100,000 organizations are now legally obligated entities under national NIS2 transpositions - a step change from the roughly 20,000 covered by the original NIS regime. Not all of them face a mandatory external audit; regimes differ by country. But in the member states where the law prescribes a standing external audit by registered or certified auditors, the audit market created is measured in tens of thousands of organizations - most of which have never bought a cybersecurity audit before.
As of late July 2026, six member states prescribe a standing external audit for at least part of their in-scope population: Belgium, Croatia, Czechia, Hungary, Poland and Slovakia. Germany and Austria require independent verification for a defined subset of entities or on request from the authority. Romania has the obligation in primary law with the periodicity still to be set. The rest run supervisory or self-declaration models, or are still settling their secondary legislation.
The two worked examples show the pattern.
Czechia. The new Cybersecurity Act (Act No. 264/2025 Coll.) brought an estimated 6,000-10,000 organizations into scope, against roughly 400 under the previous law. More than 4,800 had registered with the national authority by February 2026 - which also means thousands had not, a backlog signal in itself. Organizations under the higher-obligations regime face a recurring external audit on a biennial cycle.
Slovakia. Act No. 366/2024 Coll. was originally expected to cover 5,000-6,000 organizations. The national authority now expects registrations closer to 14,000. Essential entities must complete their first audit by a certified cybersecurity auditor within 24 months of registration - a rolling deadline that started ticking in early 2025, which means demand arrives continuously rather than in one spike.
Two features of this new market deserve emphasis, and they repeat across the EU. First, novelty: the overwhelming majority of newly obligated organizations have no incumbent audit relationship for cybersecurity. There is no incumbent to displace. Second, recurrence: every mandatory regime prescribes a repeat cycle, typically every two to three years. The first wave is not a one-off project. It is the client-acquisition round for a permanent, recurring line of business.
The capacity wall
A thorough, full-coverage NIS2 audit decomposes into four streams of work: reading the documentation set, interviewing process owners, evaluating technical evidence, and writing a report with a documented conclusion for every control in the applicable catalog. Modeled bottom-up, that is about 6 person-days for a small entity, 15 for a medium one, and over 30 for a large one - roughly 11 person-days on a weighted market average. For reference, the IAF MD5 audit-time tables used in ISO 27001 certification prescribe 5, 9 and 13 days at comparable headcounts, and those assume sampling. National NIS2 methodologies typically expect per-control assessment across the full catalog.
Multiply 11 days across a national wave and the arithmetic turns unforgiving. Serving Slovakia's likely first wave within its rolling 24-month windows would consume more dedicated auditor capacity than the certified pool holds. Czechia's higher-obligations tier alone represents thousands of audit-days every two years. Scale that logic to the larger member states and the numbers reach the hundreds of full-time auditors per country - against national registers that in several cases were created from zero in 2024-2025. Registration backlogs across the EU tell the same story from the demand side: in Germany, roughly 11,500 of an estimated 29,500 obligated entities had registered with the federal authority by the 6 March 2026 deadline, a rate under 40 percent.
The market is not demand-constrained. It is capacity-constrained, country by country. And organizations under deadline pressure hire the firm that can start, not the firm with the nine-month waiting list.
Three ways to deliver the same audit
Audit41 is an AI audit system built on a methodology validated across 600+ live audit engagements. It ingests the full documentation set, conducts and evaluates structured interviews, evaluates technical evidence, and drafts the report itself: a per-control result with a documented justification, control by control, against the applicable national catalog. Where evidence is incomplete, it generates specific follow-up requests. It currently operates across localized NIS2 national frameworks, ISO 27001, NIST SP 800-53 and ISO 9001, with further frameworks in build.
That changes the auditor's role, not the auditor's authority. Three delivery modes:
Human-only - the baseline every firm knows. About 11 person-days per audit on the weighted average.
Hybrid - the AI performs the document review, evidence evaluation, interview program and report drafting. The auditor holds a small number of targeted supplementary interviews with key individuals, validates the per-control results, and finalizes the report. Auditor effort falls to roughly a quarter of the baseline - while the auditor still sits down personally with every client where it matters.
Full AI - the system runs end to end. The auditor receives a complete assessment - every control scored and justified, every gap flagged - and performs a structured review before signing. Between half a day and two days of auditor time per audit.
On quality, the objection every auditor raises first: the system does not sample. It reads every page of every policy, traces every control to its evidence, and documents a justification for every conclusion - a level of coverage human economics have never permitted. Professional judgment is not removed from the process. It is concentrated where it carries the most value: the critical review and sign-off of a fully documented assessment.
What this means for a firm
Run the numbers for a 50-auditor practice at 170 billable days per auditor per year. Human-only, it delivers roughly 700 audits a year - a fraction of most national waves, with the rest turned away. In hybrid mode the same practice delivers around 3,000. The bottleneck moves from delivery capacity to sales and scheduling - a far better problem to have. The same arithmetic scales down: a five-auditor boutique moves from roughly 70 audits a year to several hundred, which in a smaller member state can be a meaningful share of the entire national wave.
The commercial logic follows. NIS2 audits are priced against the human-effort benchmark that clients understand. A firm whose delivery cost sits at a fraction of that benchmark converts the difference into margin, or shades price to win volume and converts it into share. Both strategies are available only to firms that possess the capacity in the first place.
And the advantage is temporary. Within a few years, AI-assisted delivery will be the market's cost baseline. The remaining differentiator will be the installed client base accumulated during the first wave - clients whose document map, system inventory and findings history the incumbent already holds, structured and machine-readable, making every recurring audit cheaper to deliver than the first. The window in which superior capacity buys permanent market share is the first-wave window. It does not reopen.
Where to start
We work with audit and consulting firms as delivery partners, not competitors. If your firm is registered or preparing to register as a cybersecurity auditor in any NIS2 member state, the conversation takes thirty minutes: your national wave, your current capacity, and what changes when the delivery mode changes.