Last updated: 24 September 2026
Quick answer: A NIS2 compliance checklist covers seven areas: confirm scope and register with your national authority, get management body approval and training, run a risk assessment, implement the ten Article 21 security measures, secure your supply chain, set up 24-hour, 72-hour and one-month incident reporting, and keep evidence that proves all of it works.
The NIS2 Directive has applied across the EU since October 2024, and most Member States now have national implementing laws in force. Not all do: in July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to notify transposition measures. Our NIS2 transposition tracker covers the country picture. For CISOs, the question has shifted from “does this apply to us?” to “can we prove we comply?”
This NIS2 compliance checklist turns the Directive’s requirements into concrete, auditable tasks. It is based on the text of Directive (EU) 2022/2555, but always check your national transposing law, which may add detail or stricter rules.
What does a NIS2 compliance checklist need to cover?
It needs to cover governance, risk management, the ten minimum security measures, supply chain security, incident reporting and registration. These map to Articles 20, 21, 23 and 3 of the Directive, and national authorities will supervise against the same themes.
The Directive applies to entities in the sectors listed in its Annexes I and II. According to the European Commission’s NIS2 FAQs, it uses a size-cap rule so that all medium-sized and large companies in the selected sectors are included, with some entities covered regardless of size. Entities are classed as essential or important, which affects supervision and penalties more than the core obligations.
On 20 January 2026 the Commission also proposed targeted amendments to NIS2, including a new small mid-cap category that would generally be treated as important entities and extra detail in ransomware incident reports. These are proposals still going through the EU legislative process. The checklist below reflects the Directive as it currently applies.
Common mistake: assuming you are out of scope because you are not in a “critical” sector. The Annex II sectors include manufacturing of certain products, food, waste management, postal services and digital providers. Check the annexes line by line.
Step 1: Confirm scope and register
Start by documenting why you are in scope, which sector and subsector you fall under, and whether you are essential or important in each Member State where you operate.
- Map each legal entity against Annex I and Annex II sectors.
- Record headcount, turnover and balance sheet figures used for the size test.
- Identify every Member State where you provide services in scope.
- Register with the competent authority or single point of contact under national law.
Article 3(3) required Member States to establish a list of essential and important entities by 17 April 2025. Under Article 3(4), entities must provide their name, address, contact details including email and IP ranges, sector and subsector, and the Member States where they provide services, and must notify changes within two weeks.
Step 2: Put governance in place
Article 20 makes cybersecurity a board-level responsibility. Management bodies must approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements. Members of management bodies are required to follow training, and entities are encouraged to offer similar training to employees regularly.
- Formal board or management approval of the security risk-management framework, minuted.
- A defined owner for NIS2 compliance, usually the CISO, with a clear reporting line.
- Management body training completed and recorded, with a refresh schedule.
- Regular reporting to management on risks, incidents and measure effectiveness.
In practice: auditors will ask for evidence of approval and oversight, not just a signed policy. Keep board minutes, training records and the reports management actually received.
Step 3: Run a risk assessment
Article 21(1) requires appropriate and proportionate technical, operational and organisational measures to manage risks to network and information systems. That starts with a documented risk assessment.
- Asset inventory covering systems, data, locations and services in scope.
- Risk methodology with defined likelihood and impact criteria.
- A risk register with owners, treatment decisions and target dates.
- Risk acceptance approved at the right level.
If you already run an ISO 27001 information security management system, much of this exists. Reuse your enterprise risk management process rather than building a parallel one.
Step 4: Implement the ten Article 21 measures
Article 21(2) sets out the minimum measures every in-scope entity must address. Use the table as your control checklist and attach evidence to each line.
| Art. 21(2) | Measure | Evidence to hold |
|---|---|---|
| (a) | Policies on risk analysis and information system security | Approved security policy, risk methodology |
| (b) | Incident handling | Incident response plan, logs, post-incident reviews |
| (c) | Business continuity, backup management, disaster recovery and crisis management | BCP and DR plans, backup test results, crisis exercises |
| (d) | Supply chain security | Supplier inventory, assessments, contract clauses |
| (e) | Security in acquisition, development and maintenance, including vulnerability handling and disclosure | Secure development standards, vulnerability management records |
| (f) | Policies and procedures to assess effectiveness of measures | Internal audits, KPIs, test reports |
| (g) | Basic cyber hygiene practices and cybersecurity training | Training records, hygiene baselines |
| (h) | Cryptography and, where appropriate, encryption | Cryptography policy, key management records |
| (i) | Human resources security, access control policies and asset management | Joiner-mover-leaver process, access reviews, asset register |
| (j) | Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communications, where appropriate | MFA coverage report, approved communication tools |
Article 21(4) adds that if you find you do not comply with any of these measures, you must take corrective measures without undue delay. Keep a remediation log.
For some digital entities the detail is set in law. Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 sets technical and methodological requirements for providers including DNS services, cloud computing, data centres, managed service providers, managed security service providers and online marketplaces. ENISA’s technical implementation guidance, published in June 2025, offers practical advice, examples of evidence and mappings for those requirements, and is a useful reference for other sectors too.
Much of this work overlaps with ISO 27001, NIST CSF and DORA. Mapping controls once and reusing evidence saves significant effort. To see how that works in practice, start your 14-day free trial and run a NIS2 assessment against your existing controls.
Step 5: Secure your supply chain
Supply chain security is measure (d), and Article 21(3) spells out what “appropriate” means. Entities must take into account the vulnerabilities specific to each direct supplier and service provider, the overall quality of their products and cybersecurity practices, including secure development, and the results of EU coordinated risk assessments of critical supply chains.
- Inventory of direct ICT suppliers and service providers, ranked by criticality.
- Security due diligence before onboarding and at regular intervals.
- Contract clauses on security requirements, incident notification and audit rights.
- Exit and substitution plans for critical providers.
A structured vendor and third-party risk management process keeps assessments, contracts and follow-ups in one place instead of scattered spreadsheets.
Step 6: Build a NIS2 incident reporting process
Article 23 requires entities to notify their CSIRT or competent authority of any significant incident. An incident is significant if it has caused or can cause severe operational disruption or financial loss, or has affected or can affect others by causing considerable material or non-material damage.
| Stage | Deadline | Content |
|---|---|---|
| Early warning | Within 24 hours of becoming aware | Whether the incident is suspected to be unlawful or malicious, and possible cross-border impact |
| Incident notification | Within 72 hours of becoming aware | Update, initial assessment of severity and impact, indicators of compromise where available |
| Intermediate report | On request | Relevant status updates |
| Final report | No later than one month after the notification | Detailed description, root cause, mitigation measures, cross-border impact |
| Progress report | If the incident is ongoing at the final report deadline | Status, with a final report within one month of handling the incident |
- Documented criteria for deciding whether an incident is significant.
- Named people authorised to submit notifications, with backups.
- Pre-filled templates for each reporting stage.
- A process to inform recipients of your services where required.
- Alignment with GDPR 72-hour breach notification where personal data is involved.
Tools for incident and data breach management with built-in timers make it much easier to hit each deadline. For a deeper walkthrough, see our NIS2 compliance guide.
Step 7: Maintain evidence and prepare for supervision
Supervision under NIS2 is evidence-driven. Essential entities face proactive supervision, including inspections and audits, while important entities are mainly supervised after the fact, for example following an incident or complaint.
- Central evidence repository linked to each Article 21 measure.
- Internal audit or effectiveness review at least annually.
- Version-controlled policies with approval history.
- A tracked remediation plan with owners and dates.
What are the penalties for NIS2 non-compliance?
The Commission’s FAQs state that essential entities can face maximum fines of at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher, and important entities maximum fines of at least EUR 7 million or 1.4%. Member States set the exact rules in national law, and the Directive also provides for personal accountability of senior management.
Key takeaways
- NIS2 compliance rests on seven workstreams: scope, governance, risk, the ten measures, supply chain, incident reporting and evidence.
- Management bodies must approve and oversee measures and complete training, so board evidence matters.
- Incident reporting runs on a 24-hour, 72-hour and one-month cascade.
- Implementing Regulation 2024/2690 sets detailed rules for many digital providers.
- Reuse ISO 27001 and other framework work to avoid duplicating effort.
Frequently asked questions
When did NIS2 compliance become mandatory?
Member States had to transpose the Directive by 17 October 2024 and apply the measures from 18 October 2024. In practice, your obligations start when your national transposing law takes effect. Several Member States transposed late, and in July 2026 the Commission referred four of them to the Court of Justice. Check the law and registration deadlines in each country where you operate.
Is ISO 27001 certification enough for NIS2?
ISO 27001 covers much of what Article 21 requires, particularly risk management, policies and many technical controls. It is not a full substitute. You still need NIS2-specific incident reporting, management body training and approval, registration, and any sector or national requirements. Treat your ISMS as the foundation and add the gaps.
Who must approve NIS2 security measures?
Article 20 requires the management body of the entity to approve the cybersecurity risk-management measures and oversee their implementation. Management body members can be held liable for infringements and are required to follow training. The CISO usually prepares the measures and reports on them, but formal approval sits with the board or equivalent.
Do NIS2 supply chain rules apply to all suppliers?
Article 21 focuses on direct suppliers and service providers, especially those with access to or influence over your network and information systems. You should assess each according to its criticality and specific vulnerabilities. Low-risk suppliers can be handled with lighter checks, but you should be able to explain how you ranked them.
How is a NIS2 incident different from a GDPR breach?
A NIS2 significant incident is judged by its impact on services, financial loss or damage to others, whether or not personal data is involved. A GDPR personal data breach concerns personal data only. One event can trigger both regimes, with different recipients and timelines, so your incident process should check both at the start.
Conclusion: turn the checklist into a programme
NIS2 is not a one-off project. The checklist above gives you a defensible structure, but the real test is whether you can show a supervisor current evidence for every measure, a board that understands its role and an incident process that runs on time. Build it once, map it to your other frameworks and keep it alive with regular reviews. Enactia’s AI-powered GRC platform brings NIS2 assessments, policies, risks, vendors and incidents into one place.
To discuss your NIS2 programme, contact us or book a demo or start your 14-day free trial.
This article is for general information and is not legal advice.
