The NIS2 Compliance Checklist for Management Teams
24 concrete measures across 6 categories, mapped to Article 21 of Directive (EU) 2022/2555. Tick what's in place, watch your score update live, and get a prioritized gap list at the end. Nothing is stored โ everything runs in your browser.
1. Governance & Risk Management
Art. 21(1)โ(2)(a) + Art. 20 โ management carries personal accountability.
2. Incident Handling & Reporting
Art. 21(2)(b) + Art. 23 โ detect, respond, and report on the clock.
3. Business Continuity & Crisis Management
Art. 21(2)(c) โ keep operating, and prove you can recover.
4. Supply Chain Security
Art. 21(2)(d) โ your suppliers' weakness is your liability.
5. Access Control & Asset Management
Art. 21(2)(i) โ least privilege, known inventory.
6. Hygiene, Cryptography & Effectiveness
Art. 21(2)(e)(f)(g)(h) โ the remaining named measures.
Next step: several technical items (TLS, HSTS, headers, resilience signals) can be verified automatically. Run the free scanner on your public URL โ it works on any CMS, not just WordPress. Need the documents behind supplier clauses and policies? Browse ComplianceDocs templates.
Frequently asked questions
Who must comply with NIS2?
Essential and important entities across 18 sectors โ energy, transport, banking, financial-market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing, digital providers and research โ generally 50+ employees or โฌ10M+ turnover while providing services in the EU. Suppliers to these entities are pulled in via Article 21(2)(d) contract requirements even when individually below the size threshold.
What exactly does Article 21 require?
Ten minimum measures: risk-analysis and information-security policies; incident handling; business continuity, backup and crisis management; supply-chain security; security in acquisition, development and maintenance; policies to assess effectiveness; basic cyber-hygiene and training; cryptography and encryption policies; HR security, access control and asset management; and multi-factor authentication or secured voice/video/text channels. This checklist maps each one.
How fast do I have to report an incident?
Three deadlines: early warning within 24 hours of awareness, full notification within 72 hours, final report within one month. Only "significant" incidents qualify, but the definition is broad โ significant operational disruption or financial/material loss for you, or considerable harm to others. Prepare the process now; don't improvise during an outage.
What happens if we don't comply?
Fines up to โฌ10M or 2% of worldwide turnover for essential entities (โฌ7M / 1.4% for important ones). Supervisors can audit, issue binding instructions, and temporarily suspend certifications or authorizations. Under Article 20, management bodies can be held accountable for failing to oversee compliance.
We're a small supplier to a bigger NIS2 entity โ does this apply to us?
Directly, maybe not; contractually, almost certainly yes. Large NIS2 entities must assess and manage their suppliers' security, so expect questionnaires, contract clauses and MFA requirements to flow down to you. Working through this checklist puts you ahead of those requests instead of scrambling when the questionnaire arrives.