Free Download
Compliance & Audit

NIS2 Directive
Readiness Checklist

EU Directive 2022/2555: Articles 20, 21 & 23 | Essential & Important Entities
Client Organisation
Client Name Ltd
Document Reference
XXX
Audit Date
2026
Lead Auditor
Directive Version
EU 2022/2555 (NIS2)
Entity Classification
Essential / Important
Competent Authority
TBC: National Authority
Report Status
Draft: In Review
This checklist covers all NIS2 governance obligations (Article 20), the ten mandatory cybersecurity risk-management measures (Article 21a–j), incident reporting requirements (Article 23), and entity scope and classification criteria. Click any status badge to cycle through YES / PARTIAL / NO / N/A. Evidence and Notes columns are editable. Use Ctrl+P to print or save as PDF.
Important Notice: Guidance Document Only This document is prepared by Cyvra as an internal working tool to support compliance readiness activities. It is a structured guidance aid, not an official regulatory instrument, and does not constitute legal, regulatory, or professional advice. Cyvra is not a certification body, accreditation authority, or regulator. Completing or scoring this checklist does not constitute certification, audit sign-off, or confirmation of regulatory compliance. The content reflects Cyvra's interpretation of publicly available regulatory requirements at the time of preparation; it may not capture all obligations relevant to your organisation, may not reflect subsequent regulatory updates, and should not be relied upon as a complete statement of applicable law. Cyvra makes no representation or warranty, express or implied, as to the accuracy or completeness of this document. To the fullest extent permitted by law, Cyvra accepts no liability for any loss, penalty, or damage arising from use of or reliance on this document. Organisations must seek independent legal and regulatory advice appropriate to their specific circumstances.
NIS2 Directive Readiness Checklist: Governance, Scope & Incident Reporting
Page 2 of 4
0%
0 Compliant
0 Partial
0 Non-Compliant
0 N/A
of 0 controls assessed
How to use: Click a status badge to cycle YES / PARTIAL / NO / N/A. Click Evidence or Notes to type directly. The score bar updates automatically.

Article 20: Governance & Management Body Accountability

5 check items | NIS2 new requirement
RefRequirement & Audit Check PointsStatusEvidence RequiredAuditor Notes
20.1Management Body Formal Approval
• Has the management body (board / C-suite) formally approved the cybersecurity risk-management policy and measures?
• Written board resolution or equivalent approval document available?
• Approval reviewed and reaffirmed at minimum annually?
Board resolution; signed policy; management approval records
20.2Management Body Active Oversight
• Does the management body actively oversee implementation of cybersecurity measures?
• Regular cybersecurity briefings scheduled and minuted?
• Management body receives incident and risk reports at defined intervals?
Meeting minutes; management dashboards; incident briefing records
20.3Cybersecurity Training for Management
• Do management body members receive regular cybersecurity training covering NIS2 obligations?
• Training programme documented with topics, frequency, and delivery method?
• Training completion records maintained for all management body members?
• Training addresses current threat landscape and regulatory changes?
Training programme; completion certificates; attendance records
20.4Designated Cybersecurity Authority (CISO / Equivalent)
• Is there a formally designated authority responsible for cybersecurity (CISO or equivalent role)?
• Role defined with clear authority, responsibility, and adequate resources?
• Reporting line from CISO/authority to management body documented?
Job description; org chart; terms of reference; resource allocation
20.5Accountability and Liability Framework
• Management body members understand personal accountability under NIS2 (Art. 20)?
• Liability and sanctions regime communicated to management body?
• Process to inform management body of compliance status and material risks?
Accountability policy; legal briefing records; compliance reports to board

Entity Classification & Scope (Art. 2, 3 & 6)

4 check items
RefRequirement & Audit Check PointsStatusEvidence RequiredAuditor Notes
SC.1Entity Classification Determination
• Has the organisation formally determined its NIS2 classification (Essential Entity / Important Entity)?
• Classification decision documented with supporting legal rationale and size/sector criteria?
• Classification reviewed when organisational changes occur (M&A, new services, sector changes)?
Classification determination doc; legal opinion; sector confirmation
SC.2Sector Identification: Annex I / Annex II
• Organisation's sector(s) correctly identified against NIS2 Annexes (I: Energy, Transport, Banking, Health, Water, Digital infrastructure; II: Postal, Waste management, Chemicals, Food, Manufacturing, Digital providers)?
• All applicable sector activities documented?
• If Critical Entity (CER Directive), cross-directive obligations identified?
Sector classification matrix; Annex reference; CER overlap assessment
SC.3National Competent Authority Registration
• Organisation registered with the relevant national competent authority (NCA) as required?
• NCA for each applicable sector identified?
• Point of Contact (PoC) for cybersecurity notifications registered with NCA?
• CSIRT/national notification channels confirmed?
NCA registration confirmation; PoC registry entry; CSIRT contact details
SC.4Cross-Border and Multi-Jurisdiction Obligations
• If operating in multiple EU member states, are obligations for each jurisdiction identified?
• Lead member state / primary establishment identified if applicable?
• Coordination mechanism for cross-border incident reporting established?
Jurisdiction register; lead member state designation; coordination procedure

Article 23: Incident Reporting Obligations

6 check items | 24h / 72h / 1-month timelines
RefRequirement & Audit Check PointsStatusEvidence RequiredAuditor Notes
23.1Significant Incident Criteria and Classification
• Criteria for "significant incident" formally defined per Art. 23 (substantial disruption, financial loss, cross-border impact)?
• Incident classification procedure documented with severity thresholds?
• All staff and on-call teams trained on reporting thresholds and escalation?
Incident classification policy; severity matrix; training records
23.2Early Warning: Within 24 Hours
• Process for submitting early warning to CSIRT/competent authority within 24h of becoming aware of significant incident?
• 24h notification template/procedure readily available to on-call team?
• 24/7 escalation path to person responsible for submitting early warning?
• Early warning covers: incident type, initial assessment, whether attack suspected?
24h notification procedure; template; on-call rota; test exercise records
23.3Incident Notification: Within 72 Hours
• Full incident notification submitted to authority within 72h of awareness?
• Notification includes: initial assessment, affected services, estimated impact, remediation actions taken?
• Named responsible person(s) for 72h submission identified and trained?
• Process for updating notification if new information becomes available?
72h notification procedure; template; designated contacts; previous submissions
23.4Intermediate Reports (On Request)
• Process for providing intermediate reports to competent authority on request?
• Interim progress update capability documented?
• Communication log maintained for all authority interactions during incident?
Interim reporting procedure; communication log template
23.5Final Report: Within 1 Month
• Final incident report submitted within 1 month of initial notification?
• Final report includes: detailed description, incident type, root cause analysis, remediation, recurrence prevention?
• Cross-border impact assessment included where applicable?
• Post-incident report archived and lessons learned actioned?
Final report template; root cause analysis procedure; previous final reports
23.6Customer and Downstream Notification
• Process for notifying affected customers or downstream service recipients of significant incidents?
• Customer notification threshold and timing criteria defined?
• Communication template for customer notifications approved?
Customer notification procedure; template; communication records
NIS2: Article 21 Security Measures (a–e): Risk, Incidents, BCP, Supply Chain, Network
Page 3 of 4
RefRequirement & Audit Check PointsStatusEvidence RequiredAuditor Notes
Art. 21(a): Policies on Risk Analysis and Information Systems Security
21a.1Risk Assessment Methodology
• Documented cybersecurity risk assessment methodology covering identification, analysis, and evaluation of cyber risks?
• Methodology includes likelihood and impact scales, risk acceptance criteria?
• Methodology reviewed and updated annually?
Risk methodology document; risk register; review records
21a.2Information Security Policy
• Overarching IS policy approved by management body and published?
• Policy covers all NIS2-relevant security areas (access, incident, supply chain, crypto, etc.)?
• Version-controlled, communicated to all staff, and available to relevant external parties?
IS Policy document; approval evidence; distribution records
21a.3Cyber Risk Register
• Cyber risk register maintained and kept current with identified risks, owners, and treatment plans?
• Risks reviewed at minimum quarterly or on occurrence of significant changes?
• Risk treatment actions tracked to closure with owner accountability?
Risk register; treatment plans; review records; action tracker
21a.4Threat Intelligence
• Threat intelligence feeds integrated into risk management processes?
• Sector-specific intelligence (ENISA, national CSIRT, ISACs) monitored?
• Threat landscape reviewed in management reporting?
Threat intel subscriptions; feed integration evidence; management reports
21a.5Annual and Event-Driven Risk Review
• Risk assessment conducted at least annually and triggered by significant changes?
• Results presented to management body with action plan?
• Risk decisions documented with residual risk acceptance by risk owners?
Annual risk assessment reports; management presentation; acceptance records
Art. 21(b): Incident Handling (Prevention, Detection, Analysis, Containment, Recovery)
21b.1Incident Response Plan
• Documented IRP approved by management and tested at least annually?
• Plan covers all phases: detection, analysis, containment, eradication, recovery, post-incident review?
• Roles and responsibilities assigned for each phase?
IRP document; test exercise records; role assignments
21b.2Detection and Monitoring Capabilities
• Technical monitoring and detection capabilities deployed across network and systems?
• SIEM, IDS/IPS, EDR, or equivalent tools providing 24/7 alerting for critical systems?
• Detection coverage documented (assets, alert categories, response SLAs)?
SIEM/monitoring tool evidence; alert coverage matrix; SLA documentation
21b.3Incident Analysis, Triage and Playbooks
• Incident triage and severity classification procedure defined?
• Escalation thresholds and communication chains documented?
• Playbooks/runbooks for common incident types (ransomware, data breach, DDoS)?
Triage procedure; severity matrix; playbooks; escalation tree
21b.4Containment and Eradication
• Procedures for containing threats and isolating compromised systems?
• Network isolation / quarantine capability tested?
• Malware removal, system cleaning, and rebuild procedures documented?
Containment procedures; isolation test records; rebuild procedures
21b.5Recovery Procedures
• Post-incident recovery procedures documented with RTOs defined for critical services?
• Service restoration steps, validation tests, and sign-off process documented?
• Return-to-normal-operations criteria defined?
Recovery procedures; RTO/RPO definitions; restoration test records
21b.6Post-Incident Review and Lessons Learned
• Post-incident review conducted for all significant incidents?
• Lessons learned documented and actions assigned with owners and due dates?
• Root cause analysis outputs feeding back into risk management and policy updates?
PIR reports; action tracker; risk register updates; policy revision evidence
Art. 21(c): Business Continuity, Backup Management, Disaster Recovery & Crisis Management
21c.1Business Continuity Plan (BCP)
• BCP documented covering all critical network and information services?
• BCP tested at least annually including cyber incident scenarios?
• BCP roles, escalation contacts, and activation criteria documented?
BCP document; test exercise reports; activation records
21c.2Backup Policy and Testing
• Backup policy covering scope, frequency, retention period, storage location (including offsite/air-gapped), and encryption?
• Backups of all critical systems taken and restoration tested regularly (at minimum quarterly)?
• Backup integrity verification and restoration time measured?
Backup policy; backup logs; restoration test records; integrity check results
21c.3IT Disaster Recovery Plan
• IT DR plan aligned with BCP covering critical systems failover and recovery?
• RTO and RPO defined and agreed for all critical services?
• DR failover testing conducted at least annually with results documented?
DR plan; RTO/RPO register; DR test results; BCP alignment evidence
21c.4Crisis Management Procedures
• Crisis management procedures for major cyber events documented?
• Crisis team composition, roles, and escalation path defined?
• Crisis communications plan covering internal, external, media, and regulatory communications?
Crisis management plan; team composition; comms templates; exercise records
21c.5Emergency Contacts and Communication Resilience
• Emergency contact list (key personnel, regulators, suppliers, authorities) maintained and reviewed quarterly?
• Out-of-band communication capability available if primary systems are compromised?
• Contacts tested during exercises?
Emergency contact directory; review records; out-of-band comms test evidence
Art. 21(d): Supply Chain Security
21d.1Supplier Inventory and Risk Register
• Comprehensive inventory of critical third-party suppliers and service providers maintained?
• Supply chain risk register with risk ratings, criticality classification, and last assessment dates?
• Suppliers categorised by tier (critical, significant, standard)?
Supplier inventory; supply chain risk register; tiering criteria
21d.2Security Requirements in Supplier Contracts
• Cybersecurity requirements included in all critical supplier contracts?
• Contractual clauses covering: incident notification obligations, minimum security standards, audit rights, data protection?
• Compliance with ENISA supply chain security guidelines reviewed?
Sample supplier contracts; security clauses checklist; legal review evidence
21d.3Supplier Security Assessments and Audits
• Regular security assessments or audits of critical suppliers conducted?
• Assessment frequency based on supplier risk tier (critical: annual, significant: biennial)?
• Assessment results tracked and remediation plans monitored?
Supplier assessment reports; assessment schedule; remediation tracker
21d.4Software and Hardware Provenance
• Process to verify integrity and authenticity of software and hardware from suppliers?
• SBOM (software bill of materials) or equivalent for critical software components?
• Third-party component vulnerability monitoring (CVE tracking, vendor advisories)?
SBOM records; software verification process; CVE monitoring evidence
21d.5Third-Party Access Controls
• Privileged and remote access by suppliers formally controlled, monitored, and logged?
• Just-in-time access provisioning or session recording for critical supplier access?
• Formal offboarding process for terminated supplier relationships?
Access control logs; JIT access records; session recordings; offboarding checklist
Art. 21(e): Network Security, Secure Acquisition, Development & Maintenance
21e.1Network Security Architecture
• Network segmentation, perimeter controls, and access control architecture documented?
• Firewall policies, DMZ, and micro-segmentation implemented and reviewed annually?
• Network architecture diagram current and accurate?
Network architecture docs; firewall rules review; segmentation evidence
21e.2Vulnerability Management Programme
• Vulnerability scanning programme covering all in-scope network assets and systems?
• Critical and high vulnerabilities patched within defined SLAs (e.g., critical 72h, high 14 days)?
• Vulnerability management KPIs tracked and reported to management?
Scan reports; patch SLA policy; KPI reports; remediation records
21e.3Secure Development Lifecycle (SDLC)
• Secure SDLC policy covering design, code review, testing, and deployment?
• SAST/DAST tools integrated into CI/CD pipeline for developed applications?
• Security testing (penetration testing) conducted for significant system changes?
SDLC policy; SAST/DAST results; pen test reports; code review evidence
21e.4Change Management
• Formal change management process for all IS/network changes with security impact assessment?
• Changes tested and approved before production deployment?
• Post-change review and rollback capability documented and tested?
Change management process; CAB records; security assessment forms; rollback plans
21e.5Vulnerability Disclosure Policy
• Responsible vulnerability disclosure (RVD) policy published and accessible?
• Reporting channel for external security researchers (security.txt or equivalent)?
• CVE coordination and NCA disclosure process documented?
RVD policy; disclosure channel; coordination procedure; CVD history
NIS2: Article 21 Security Measures (f–j): Effectiveness, Training, Crypto, HR/Access, MFA
Page 4 of 4
RefRequirement & Audit Check PointsStatusEvidence RequiredAuditor Notes
Art. 21(f): Policies and Procedures to Assess Effectiveness of Cybersecurity Measures
21f.1Cybersecurity KPIs and Metrics Framework
• Cybersecurity KPIs and metrics defined, measured, and reported at planned intervals?
• Metrics cover: detection times, response times, patch compliance, training completion, incident rates?
• KPIs reviewed against targets and reported to management quarterly?
KPI framework; metric reports; management dashboard; target comparison
21f.2Independent Audits and Penetration Testing
• Regular independent security audits of key controls conducted (at least annually)?
• Penetration testing of critical systems and interfaces performed?
• Audit and test findings tracked to remediation with owner accountability?
Audit reports; pen test results; finding tracker; remediation evidence
21f.3Continuous Monitoring of Control Effectiveness
• Continuous monitoring programme for security control effectiveness in place?
• Automated compliance checks for critical controls (e.g., patching, AV, config compliance)?
• Monitoring results integrated with risk management and reported to management?
Monitoring tool evidence; compliance reports; integration with risk register
21f.4Management Review of Cybersecurity Effectiveness
• Cybersecurity effectiveness formally reviewed by management at minimum annually?
• Review inputs include: audit results, KPIs, incidents, threat intelligence, risk changes?
• Review outputs (decisions, improvement actions) documented and tracked?
Management review minutes; action register; improvement plans
Art. 21(g): Basic Cyber Hygiene Practices and Cybersecurity Training
21g.1Cyber Hygiene Baseline Standards
• Basic cyber hygiene standards documented and enforced across the organisation?
• Standards cover: password/MFA policy, patching cadence, AV/EDR, phishing awareness, secure configurations?
• Hygiene baseline applied consistently to employees, contractors, and managed devices?
Cyber hygiene policy; baseline standards doc; compliance monitoring evidence
21g.2Security Awareness Training Programme
• Mandatory security awareness training for all staff at onboarding and annually thereafter?
• Training covers NIS2 obligations, phishing, social engineering, incident reporting procedures?
• Effectiveness measured via phishing simulations, tests, or assessments?
Training programme; completion records; phishing simulation results; test scores
21g.3Technical and Security Staff Training
• Role-specific cybersecurity training for IT, security, and DevOps staff?
• CPD/certification requirements for security roles defined (e.g., CISSP, CISM, SC-200)?
• Training programme aligned with current threat landscape and NIS2 requirements?
Training plan; certifications; CPD records; role-specific curriculum
21g.4Incident Response Exercises
• Tabletop or live incident response exercises conducted at minimum annually?
• Exercises include NIS2 reporting timeline scenarios (24h / 72h obligations)?
• Exercise findings documented and actioned in IRP updates?
Exercise programme; exercise reports; after-action reviews; IRP updates
Art. 21(h): Policies and Procedures Regarding Cryptography and Encryption
21h.1Cryptography and Encryption Policy
• Cryptography and encryption policy approved and implemented?
• Policy specifies approved algorithms (AES-256, RSA-2048+, TLS 1.2+), key lengths, and prohibited ciphers?
• Policy aligned with ENISA cryptographic guidelines and reviewed annually?
Cryptography policy; algorithm standards; annual review record
21h.2Encryption in Transit
• TLS 1.2+ enforced for all web services, APIs, and external communications?
• VPN or secure channels mandatory for all remote access?
• Deprecated protocols (TLS 1.0/1.1, SSL, unencrypted HTTP) disabled and monitored?
TLS configuration scans; VPN policy; protocol audit reports
21h.3Encryption at Rest
• Full disk encryption deployed on all laptops, mobile devices, and portable media?
• Database and file-level encryption for sensitive personal and business data at rest?
• Cloud storage encryption verified (customer-managed keys where applicable)?
Encryption inventory; FDE compliance reports; cloud encryption config
21h.4Cryptographic Key Management
• Key management procedures covering generation, storage, rotation, and secure destruction?
• HSM or secure key vault (e.g., Azure Key Vault, AWS KMS, HashiCorp Vault) used for critical keys?
• Key rotation schedule defined and enforced?
Key management procedure; key inventory; HSM/vault configuration; rotation logs
Art. 21(i): Human Resources Security, Access Control Policies and Asset Management
21i.1Asset Inventory
• Comprehensive inventory of network and information system assets (hardware, software, data, cloud)?
• Asset register reviewed and updated quarterly; ownership assigned?
• Asset criticality classification used to prioritise protection measures?
Asset register; discovery scan results; criticality classification; review records
21i.2HR Security and Pre-Employment Screening
• Pre-employment screening for all roles with significant IS access (background checks, references)?
• Employment contracts include cybersecurity obligations (acceptable use, confidentiality, NIS2 awareness)?
• Disciplinary process for cybersecurity policy violations documented?
Screening policy; contract templates; disciplinary procedure; HR records
21i.3Access Control Policy (Least Privilege)
• Formal access control policy based on least privilege and need-to-know principles?
• Role-based access control (RBAC) implemented for all critical systems?
• Access reviews conducted at minimum bi-annually with documented outcomes?
Access control policy; RBAC matrix; access review records
21i.4Privileged Access Management (PAM)
• Privileged accounts inventoried, justified, and controlled via PAM solution or equivalent?
• Privileged sessions monitored and recorded for critical systems?
• Shared accounts eliminated or strictly controlled with individual accountability?
PAM tool evidence; privileged account register; session logs; shared account policy
21i.5Identity Lifecycle Management (Joiners, Movers, Leavers)
• Formal JML process ensuring IS access granted, modified, and revoked in a timely manner?
• Automated de-provisioning or SLA-bound manual revocation for leavers?
• Regular reconciliation of access rights against current employment/role status?
JML procedure; provisioning/de-provisioning logs; access reconciliation records
Art. 21(j): Multi-Factor Authentication and Secure Communications
21j.1Multi-Factor Authentication (MFA)
• MFA enforced for all remote access (VPN, RDP, cloud portals) and all privileged accounts?
• MFA extended to all external-facing services and applications with user accounts?
• MFA policy documented with exceptions process requiring formal risk acceptance?
MFA enforcement evidence; exceptions register; policy document
21j.2Continuous and Risk-Based Authentication
• Continuous or risk-based authentication implemented for sensitive transactions and privileged actions?
• Session timeouts enforced and re-authentication triggered for high-risk operations?
• Anomalous access patterns triggering step-up authentication?
Authentication policy; session timeout config; risk-based auth logs; anomaly alerts
21j.3Secure Voice, Video and Text Communications
• Secured communication solutions mandated for sensitive business discussions (E2E encrypted platforms)?
• BYOD policy addressing secure communications requirements for personal devices?
• Staff trained on approved vs prohibited communication channels for sensitive data?
Secure comms policy; approved tool list; BYOD policy; training evidence
21j.4Emergency Communication Systems
• Secured emergency communication systems available for use during cyber incidents?
• Out-of-band communication channel maintained and tested (e.g., separate phone lines, encrypted messaging)?
• Emergency communication channel included in crisis management exercises?
Emergency comms system documentation; OOB channel test records; exercise evidence