0 / 24
getting started
Updated August 2026 ยท Applies to essential & important entities

The NIS2 Compliance Checklist for Management Teams

24 concrete measures across 6 categories, mapped to Article 21 of Directive (EU) 2022/2555. Tick what's in place, watch your score update live, and get a prioritized gap list at the end. Nothing is stored โ€” everything runs in your browser.

This is a self-assessment tool, not legal advice. It maps to the minimum cybersecurity risk-management measures in NIS2 Article 21 plus the Article 23 reporting duties. Member-state transpositions vary โ€” verify against your national law and involve counsel for formal registration questions.

1. Governance & Risk Management

Art. 21(1)โ€“(2)(a) + Art. 20 โ€” management carries personal accountability.

2. Incident Handling & Reporting

Art. 21(2)(b) + Art. 23 โ€” detect, respond, and report on the clock.

3. Business Continuity & Crisis Management

Art. 21(2)(c) โ€” keep operating, and prove you can recover.

4. Supply Chain Security

Art. 21(2)(d) โ€” your suppliers' weakness is your liability.

5. Access Control & Asset Management

Art. 21(2)(i) โ€” least privilege, known inventory.

6. Hygiene, Cryptography & Effectiveness

Art. 21(2)(e)(f)(g)(h) โ€” the remaining named measures.

Next step: several technical items (TLS, HSTS, headers, resilience signals) can be verified automatically. Run the free scanner on your public URL โ€” it works on any CMS, not just WordPress. Need the documents behind supplier clauses and policies? Browse ComplianceDocs templates.

Frequently asked questions

Who must comply with NIS2?

Essential and important entities across 18 sectors โ€” energy, transport, banking, financial-market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing, digital providers and research โ€” generally 50+ employees or โ‚ฌ10M+ turnover while providing services in the EU. Suppliers to these entities are pulled in via Article 21(2)(d) contract requirements even when individually below the size threshold.

What exactly does Article 21 require?

Ten minimum measures: risk-analysis and information-security policies; incident handling; business continuity, backup and crisis management; supply-chain security; security in acquisition, development and maintenance; policies to assess effectiveness; basic cyber-hygiene and training; cryptography and encryption policies; HR security, access control and asset management; and multi-factor authentication or secured voice/video/text channels. This checklist maps each one.

How fast do I have to report an incident?

Three deadlines: early warning within 24 hours of awareness, full notification within 72 hours, final report within one month. Only "significant" incidents qualify, but the definition is broad โ€” significant operational disruption or financial/material loss for you, or considerable harm to others. Prepare the process now; don't improvise during an outage.

What happens if we don't comply?

Fines up to โ‚ฌ10M or 2% of worldwide turnover for essential entities (โ‚ฌ7M / 1.4% for important ones). Supervisors can audit, issue binding instructions, and temporarily suspend certifications or authorizations. Under Article 20, management bodies can be held accountable for failing to oversee compliance.

We're a small supplier to a bigger NIS2 entity โ€” does this apply to us?

Directly, maybe not; contractually, almost certainly yes. Large NIS2 entities must assess and manage their suppliers' security, so expect questionnaires, contract clauses and MFA requirements to flow down to you. Working through this checklist puts you ahead of those requests instead of scrambling when the questionnaire arrives.