Use this NIS2 checklist to organise an entity-specific readiness review: confirm scope under the Directive and applicable national law, establish management-body oversight, implement proportionate Article 21 measures, rehearse Article 23 reporting, and retain evidence of effectiveness. NIS2 is a directive implemented through Member-State law, so the EU text is the baseline rather than the only rulebook.
1. Scope and jurisdiction
- List the legal entities, establishments, services and Member States involved.
- Map each service to the entity types in Annex I or Annex II.
- Apply the Article 2 size rule using the EU SME recommendation, including linked or partner-enterprise analysis where relevant.
- Check Article 2 exceptions that can bring certain entities into scope regardless of size.
- Determine whether sector-specific Union law displaces equivalent NIS2 measures or reporting under Article 4.
- Determine the relevant Member-State jurisdiction rules under Article 26.
- Verify national registration, notification, authority and deadline requirements.
- Record the legal analysis, evidence, owner and review trigger.
Do not reduce scope to “50 employees or EUR 10 million turnover”. The Directive generally captures medium-sized or larger listed entity types and contains important regardless-of-size rules. Essential-versus-important classification is a separate Article 3 analysis, not simply a label chosen by the organisation.
2. Management-body governance
- Give the management body a decision paper explaining scope, material risks, gaps and required resources.
- Obtain approval of the cybersecurity risk-management measures.
- Define how the management body oversees implementation and receives exceptions, incidents and effectiveness results.
- Arrange appropriate cybersecurity training for management-body members.
- Encourage appropriate regular training for employees under the national implementation.
- Record decisions, challenge, resources, accepted risk and follow-up.
Article 20(1) requires Member States to ensure that management bodies of essential and important entities approve the measures taken to comply with Article 21, oversee their implementation and can be held liable for infringements by the entities of Article 21. How that possible management-body liability operates is subject to national implementation, including the Directive's express reservation for national liability rules applicable to public institutions and relevant officials. Article 20 does not itself impose one uniform personal penalty for every director or for every infringement of NIS2.
3. Risk governance and security policy
- Define a risk method, criteria, risk ownership and acceptance authority.
- Inventory priority services, information, systems, facilities and dependencies.
- Assess cyber and all-hazards risks to network and information systems and their physical environment.
- Maintain approved risk-analysis and information-system-security policies.
- Track treatment actions, residual risk, exceptions and evidence.
Article 21 requires appropriate, proportionate measures that take account of risk exposure, entity size, likelihood and severity, and the societal and economic impact of incidents. A control catalogue without this reasoning is incomplete.
4. Article 21 minimum areas
For each area, name an owner, describe implementation, link evidence, test effectiveness and record gaps:
- risk analysis and information-system-security policies;
- incident handling;
- business continuity, backup management, disaster recovery and crisis management;
- supply-chain security for direct suppliers and service providers;
- secure acquisition, development and maintenance, including vulnerability handling and disclosure;
- policies and procedures to assess effectiveness;
- basic cyber hygiene and cybersecurity training;
- cryptography and, where appropriate, encryption;
- human-resources security, access control and asset management; and
- appropriate multifactor or continuous authentication, secured communications and emergency communications.
These headings are not a substitute for the full Directive, national law or sector-specific implementing requirements.
5. Supplier and service-provider security
- Identify direct suppliers and providers that can materially affect covered services.
- Assess access, data, concentration, substitutability, location and incident dependencies.
- Consider supplier-specific vulnerabilities, practices and product quality as Article 21 requires.
- Put proportionate security, notification, cooperation, audit-evidence, subcontracting and exit terms in contracts.
- Monitor material change and unresolved findings.
- Maintain continuity options for critical dependencies.
For a practical programme, connect this work to vendor-risk services.
6. Incident reporting under Article 23
- Define and train the significant-incident assessment process.
- Record when the entity becomes aware and who validates that time.
- For every essential or important entity, prepare a 24-hour early-warning workflow for a significant incident.
- Prepare the ordinary 72-hour incident-notification workflow; for a trust service provider, apply the 24-hour derogation only to a significant incident that affects provision of its trust services.
- Prepare for requested intermediate reports.
- Prepare the one-month final-report workflow, including the ongoing-incident rule.
- Address communications to affected service recipients where required.
- Map national portals, CSIRT or competent authority, credentials and alternates.
- Coordinate NIS2 with GDPR, sector, contract and insurance tracks without conflating thresholds.
- Exercise the reporting workflow under incomplete facts.
Article 23 reporting concerns significant incidents and uses “without undue delay” alongside outside limits. Every reporting essential or important entity remains subject to the 24-hour early warning in Article 23(4)(a). For a trust service provider, the derogation replaces only the ordinary 72-hour incident-notification deadline in point (b), and only for a significant incident that affects provision of its trust services; that incident notification is due within 24 hours. Verify national procedures and current authority instructions.
7. Effectiveness and evidence
- Define measures that show whether controls operate and reduce relevant risk.
- Test detection, response, restore, continuity and crisis decisions.
- Sample access, vulnerability, supplier and training records.
- Track findings to root cause, owner, deadline and retest.
- Report material results and overdue risk to management.
- Preserve current policies, decisions, logs, test results and corrective-action evidence.
Certification against another standard can be useful evidence, but it does not decide NIS2 scope or create legal compliance. Build a traceable gap assessment against the applicable obligations.
Sources and review
This checklist was substantively reviewed on 8 August 2026. It qualifies the size rule, management accountability, Article 21 duties and Article 23 reporting stages and avoids claiming a universal national process.
Robert Lozo, mag. iur., is a Partner at Vision Compliance specializing in EU regulatory compliance. He advises organizations on GDPR, NIS2, AI Act, and financial regulation, delivering audit-ready documentation and compliance roadmaps across regulated industries.