Checklist

NIS2 checklist: the eight steps, and the evidence behind each one

A NIS2 checklist runs in eight steps, from working out whether you are in scope through to registering with your national authority, and every step needs evidence a supervisor can actually read. The second half is where it usually breaks down. The measures exist, the file does not.

Key takeaway: ticking a checklist is not the same as complying. Every tick needs an artefact with a date, an owner and a review record. Work the eight steps below top to bottom, mark each item done, in progress or not applicable, and treat everything still open after your first pass as a gap that goes to your next board meeting.

Step 1: are you in scope?

Get this wrong and nothing downstream holds. Map the organization against the 18 sectors in Annexes I and II, and include subsidiaries, joint ventures and EU establishments of non-EU parents. Then test the thresholds: 50 employees or 10 million euro turnover, and 250 employees or 50 million euro. Use the European SME definition and count linked and partner enterprises.

One category is covered regardless of headcount or turnover: DNS providers, top level domain registries, cloud providers, data centres and CDN providers. Record your applicability conclusion in writing and set out the reasoning. Supervisors ask for it.

Step 2: Essential or Important?

That classification decides two things: your supervisory regime and your fine ceiling. Essential Entities sit under proactive supervision and face up to 10 million euro or 2 percent of global turnover. Important Entities sit under reactive supervision and face up to 7 million euro or 1.4 percent. Decide this per legal entity in scope, not for the group as a whole.

Step 3: where do you stand today?

Assess your position before you introduce new measures. A gap analysis maps every network and information system with its dependencies and data flows, puts existing policy next to the ten minimum measures, tests whether you can detect, report and recover inside the deadlines, examines supplier contracts and how you verify them, and checks whether the board is exercising oversight and has taken training. If you hold ISO 27001, point the analysis at the places where NIS2 goes further.

Step 4: what does Article 21 require?

Article 21 sets out ten minimum risk management measures. Proportionality applies, but every measure has to be covered explicitly. "We do not do that" is not an answer.

  1. Risk analysis methodology and information system security policy, approved, versioned, reviewed annually.
  2. Incident handling that works: detect, contain, eradicate, recover, with playbooks for your five most likely scenarios.
  3. Business continuity, backup management, disaster recovery and crisis management, including a tested restore.
  4. Supply chain security, aimed at your direct suppliers and service providers.
  5. Security in acquisition, development and maintenance of systems, including vulnerability handling and patch windows.
  6. Policies and procedures to assess the effectiveness of your measures.
  7. Basic cyber hygiene and role-based training, including phishing simulations and training for privileged users.
  8. Cryptography and encryption policy, at rest, in transit, and for key management.
  9. Human resources security, asset management and access control, with joiner, mover and leaver processes.
  10. Multi-factor authentication and secured communications, with phishing-resistant factors for administrators.

Step 5: can you meet the reporting deadlines?

Article 23 sets three moments and they are fixed. What you need is not only knowledge of the deadlines but the machinery behind them: a written definition of "significant incident" for your entity, templates ready to go, a named owner, and a contact roster you test every quarter outside office hours.

24 hours

Early warning

To the CSIRT or competent authority, once you become aware of the incident.

72 hours

Incident notification

With an initial assessment of severity and impact, including cross border effects.

1 month

Final report

With root cause, measures taken and lessons learned, signed off by the incident owner.

Step 6: do you have your supply chain in view?

Article 21(2)(d) extends your obligations to suppliers. You need a complete supplier inventory classified by criticality, covering at minimum ICT, cloud, service providers and anyone with privileged access. Alongside it, an assessment methodology with clear evidence requirements, contract clauses on security, incident reporting and audit rights, ongoing monitoring with a fixed reconfirmation, and an exit plan for critical suppliers.

Watch one classic finding: procurement and security often keep two lists with two definitions of critical. That produces two different answers to the same supervisory question.

Step 7: is the board behind it, demonstrably?

Article 20 makes the management body personally accountable. Four things go with it: approve the risk management measures, oversee their implementation, take cybersecurity training, and accept liability for breaches of Article 21. Formally appoint a named member of the management body as NIS2 owner and minute it. Keep attendance and content for the training: a session without an attendance list is treated as a session that did not happen.

Step 8: are you registered?

Entities in scope register with their national competent authority, providing name and legal form, address and contact details, sector and subsector, the member states where they operate, IP ranges and a contact person. There is no EU-wide registration window and no EU-wide date for first checks: each member state sets its own in national law. In the Netherlands the registration duty applies from 15 August 2026, when the Cyberbeveiligingswet enters into force. Verify the date with your own national authority, because registering late is an infringement in its own right.

When is an item genuinely ticked off?

Under supervision what counts is not what you do but what you can show. A good test costs an afternoon: have someone who did not build the file ask for ten random artefacts and time how long each takes to produce. Anything over ten minutes earns an index entry. Record every gap you already know about, with an owner, a date and a plan. Declared gaps are managed risk. Discovered gaps are findings.

Frequently asked questions

What are the steps in a NIS2 checklist?

Eight: determine whether NIS2 applies to you, establish whether you are an Essential or Important Entity, run a gap analysis, put the ten Article 21 measures in place, build your incident reporting process, address supply chain security, make board accountability real, and register with your national authority.

Does NIS2 apply to my organization?

As a rule it applies to medium and large organizations in the 18 covered sectors. Medium means 50 employees or more, or annual turnover above 10 million euro. Large means 250 employees or more, or turnover above 50 million euro. DNS providers, top level domain registries, cloud providers, data centres and CDN providers are covered regardless of size.

What is the difference between an Essential and an Important Entity?

Essential Entities are under proactive supervision and face fines up to 10 million euro or 2 percent of global turnover. Important Entities are under reactive supervision and face up to 7 million euro or 1.4 percent. Both have to put the same Article 21 measures in place.

Which reporting deadlines does the checklist cover?

Three, from Article 23. An early warning to the CSIRT or competent authority within 24 hours of becoming aware of a significant incident, a formal notification within 72 hours with an initial assessment of severity and impact, and a final report within one month covering root cause, measures taken and cross border effects.

What does the management body have to do itself?

Article 20 requires the management body to approve the risk management measures, oversee their implementation, take cybersecurity training, and accept liability for breaches of Article 21. A policy signed off only by the IT director is a governance finding, however good the policy is.

How do I know an item is genuinely ticked off?

When you can produce the artefact within ten minutes, with a date, an owner and a review record. A measure you take but cannot demonstrate counts, under supervision, as a measure that is not there.