BLOG · NIS2 CHECKLIST

NIS2 Compliance Checklist:
25 Checks Before Your Next Audit

A practical, printable checklist covering every NIS2 Article 21 measure a small agency needs — risk management, incident handling, supply chain security and documentation.

Updated August 2026 · Reading time: 8 minutes

Who Must Comply

NIS2 (Directive (EU) 2022/2555) is the EU's cybersecurity rulebook for essential and important entities. If your agency builds or maintains digital infrastructure for clients — hosting, e-commerce, SaaS, networks — you are likely in scope either directly or through your clients' supply-chain obligations under Article 21(2)(d). Member states had to transpose the directive by October 17, 2024, and enforcement is active across the EU in 2026.

🏢 Essential Entities

Energy, transport, banking, health, digital infrastructure, public administration. Stricter supervision, fines up to €10M or 2% of global turnover.

📦 Important Entities

Postal services, waste management, chemicals, food, manufacturing, digital providers. Fines up to €7M or 1.4% of turnover.

🔗 Supply Chain

Even if your agency is too small to be in scope itself, essential-entity clients must verify YOUR security under Article 21(2)(d). A completed checklist is your proof.

The Checklist

Work through all 25 checks. Each maps to an Article 21 measure. Checks marked ⚠️ are the ones auditors find missing most often at small organisations.

🛡️ 1. Risk Analysis & IS Policy (Art. 21(2)(a))

Documented information-security policy approved by management. ⚠️ Risk assessment methodology actually written down, not just implied. Annual review scheduled.

🖥️ 2. Incident Handling (Art. 21(2)(b))

Incident response plan with roles and contact lists. ⚠️ 24-hour initial / 72-hour notification / final-report timeline documented. Post-incident review process defined.

🔁 3. Business Continuity (Art. 21(2)(c))

Backups tested by restore, not just taken. Disaster-recovery RTO/RPO targets set. Alternate communication channel identified.

🔗 4. Supply Chain Security (Art. 21(2)(d))

Vendor register with security assessment per vendor. Security clauses in contracts (hosting, plugins, freelancers). Exit plan for critical vendors.

🔐 5. Acquisition & Maintenance (Art. 21(2)(e))

Vulnerability disclosure policy published. Patch-management routine with maximum timeframes. Secure development lifecycle for shipped code.

📊 6. Effectiveness Assessment (Art. 21(2)(f))

Annual security audit or self-assessment. Metrics tracked (patch latency, incident counts). Management reviews results on record.

🎓 7. Cyber Hygiene & Training (Art. 21(2)(g))

Security awareness training at least yearly. MFA enforced everywhere possible. Password manager mandated. Least-privilege access reviewed quarterly.

🔒 8. Cryptography & Encryption (Art. 21(2)(h))

Encryption in transit (TLS 1.2+) and at rest for personal/client data. Key management documented. Encrypted backups.

👥 9. HR, Access Control & Asset Mgmt (Art. 21(2)(i))

Onboarding/offboarding checklist revokes access immediately. Asset inventory of hardware, software and data flows. Clean-desk and device policy.

📝 10. Documentation & Evidence

Every policy above dated, versioned and signed off. ⚠️ Evidence folder: training logs, backup test reports, patch logs, incident post-mortems. Auditors ask for evidence, not intentions.

Reporting Timelines

Article 23 sets strict reporting duties for entities in scope. An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, an intermediate report on request, and a final report within one month. Even if your agency is not directly in scope, your essential-entity clients will pass these deadlines down to you contractually — knowing the clock starts at awareness, not at confirmation, is what keeps their notifications accurate.

How to Use This Checklist

Print this page (Ctrl/Cmd+P produces a clean PDF). Score each check as Pass / Partial / Fail. Any Fail becomes a task with an owner and a deadline. Re-run the checklist quarterly — NIS2 requires policies to stay effective under Article 21(1), not just exist once. For automated help, run our free NIS2 scan against any site you operate: it checks the externally visible technical controls (TLS, headers, exposed files) that map to checks 5, 7 and 8.

Going Deeper

Our NIS2 e-book expands this checklist into a full implementation guide with contract clauses, incident report templates and a 30-day plan.

Run the Free NIS2 Scan →    NIS2 E-Book →

Frequently Asked Questions

Is there an official NIS2 PDF checklist?

ENISA and national CSIRTs publish guidance documents, but there is no single official checklist PDF. This page is a practical consolidation of the ten Article 21 measures into 25 verifiable checks — print it with Ctrl/Cmd+P.

Does my small agency really fall under NIS2?

Possibly not directly — size caps matter (essential: typically 50+ employees; important: medium-sized). But NIS2 reaches small agencies through the supply chain: larger clients must assess your security, and many now demand documented evidence before signing.

What happens if we ignore it?

For entities in scope: fines up to €10M/2% turnover (essential) or €7M/1.4% (important), plus management liability under Article 20. For out-of-scope agencies: losing enterprise clients who require evidence of security practices.

How is NIS2 different from GDPR?

GDPR protects personal data; NIS2 protects network and information systems. They overlap operationally (incident response, encryption, vendor management) but are separate laws with separate reporting channels. See our GDPR vs NIS2 overlap guide.

Run the Free NIS2 Scan →    NIS2 E-Book →