| Ref | Requirement & Audit Check Points | Status | Evidence Required | Auditor Notes |
|---|---|---|---|---|
| 20.1 | Management Body Formal Approval • Has the management body (board / C-suite) formally approved the cybersecurity risk-management policy and measures? • Written board resolution or equivalent approval document available? • Approval reviewed and reaffirmed at minimum annually? | — | Board resolution; signed policy; management approval records | |
| 20.2 | Management Body Active Oversight • Does the management body actively oversee implementation of cybersecurity measures? • Regular cybersecurity briefings scheduled and minuted? • Management body receives incident and risk reports at defined intervals? | — | Meeting minutes; management dashboards; incident briefing records | |
| 20.3 | Cybersecurity Training for Management • Do management body members receive regular cybersecurity training covering NIS2 obligations? • Training programme documented with topics, frequency, and delivery method? • Training completion records maintained for all management body members? • Training addresses current threat landscape and regulatory changes? | — | Training programme; completion certificates; attendance records | |
| 20.4 | Designated Cybersecurity Authority (CISO / Equivalent) • Is there a formally designated authority responsible for cybersecurity (CISO or equivalent role)? • Role defined with clear authority, responsibility, and adequate resources? • Reporting line from CISO/authority to management body documented? | — | Job description; org chart; terms of reference; resource allocation | |
| 20.5 | Accountability and Liability Framework • Management body members understand personal accountability under NIS2 (Art. 20)? • Liability and sanctions regime communicated to management body? • Process to inform management body of compliance status and material risks? | — | Accountability policy; legal briefing records; compliance reports to board |
| Ref | Requirement & Audit Check Points | Status | Evidence Required | Auditor Notes |
|---|---|---|---|---|
| SC.1 | Entity Classification Determination • Has the organisation formally determined its NIS2 classification (Essential Entity / Important Entity)? • Classification decision documented with supporting legal rationale and size/sector criteria? • Classification reviewed when organisational changes occur (M&A, new services, sector changes)? | — | Classification determination doc; legal opinion; sector confirmation | |
| SC.2 | Sector Identification: Annex I / Annex II • Organisation's sector(s) correctly identified against NIS2 Annexes (I: Energy, Transport, Banking, Health, Water, Digital infrastructure; II: Postal, Waste management, Chemicals, Food, Manufacturing, Digital providers)? • All applicable sector activities documented? • If Critical Entity (CER Directive), cross-directive obligations identified? | — | Sector classification matrix; Annex reference; CER overlap assessment | |
| SC.3 | National Competent Authority Registration • Organisation registered with the relevant national competent authority (NCA) as required? • NCA for each applicable sector identified? • Point of Contact (PoC) for cybersecurity notifications registered with NCA? • CSIRT/national notification channels confirmed? | — | NCA registration confirmation; PoC registry entry; CSIRT contact details | |
| SC.4 | Cross-Border and Multi-Jurisdiction Obligations • If operating in multiple EU member states, are obligations for each jurisdiction identified? • Lead member state / primary establishment identified if applicable? • Coordination mechanism for cross-border incident reporting established? | — | Jurisdiction register; lead member state designation; coordination procedure |
| Ref | Requirement & Audit Check Points | Status | Evidence Required | Auditor Notes |
|---|---|---|---|---|
| 23.1 | Significant Incident Criteria and Classification • Criteria for "significant incident" formally defined per Art. 23 (substantial disruption, financial loss, cross-border impact)? • Incident classification procedure documented with severity thresholds? • All staff and on-call teams trained on reporting thresholds and escalation? | — | Incident classification policy; severity matrix; training records | |
| 23.2 | Early Warning: Within 24 Hours • Process for submitting early warning to CSIRT/competent authority within 24h of becoming aware of significant incident? • 24h notification template/procedure readily available to on-call team? • 24/7 escalation path to person responsible for submitting early warning? • Early warning covers: incident type, initial assessment, whether attack suspected? | — | 24h notification procedure; template; on-call rota; test exercise records | |
| 23.3 | Incident Notification: Within 72 Hours • Full incident notification submitted to authority within 72h of awareness? • Notification includes: initial assessment, affected services, estimated impact, remediation actions taken? • Named responsible person(s) for 72h submission identified and trained? • Process for updating notification if new information becomes available? | — | 72h notification procedure; template; designated contacts; previous submissions | |
| 23.4 | Intermediate Reports (On Request) • Process for providing intermediate reports to competent authority on request? • Interim progress update capability documented? • Communication log maintained for all authority interactions during incident? | — | Interim reporting procedure; communication log template | |
| 23.5 | Final Report: Within 1 Month • Final incident report submitted within 1 month of initial notification? • Final report includes: detailed description, incident type, root cause analysis, remediation, recurrence prevention? • Cross-border impact assessment included where applicable? • Post-incident report archived and lessons learned actioned? | — | Final report template; root cause analysis procedure; previous final reports | |
| 23.6 | Customer and Downstream Notification • Process for notifying affected customers or downstream service recipients of significant incidents? • Customer notification threshold and timing criteria defined? • Communication template for customer notifications approved? | — | Customer notification procedure; template; communication records |
| Ref | Requirement & Audit Check Points | Status | Evidence Required | Auditor Notes |
|---|---|---|---|---|
| Art. 21(a): Policies on Risk Analysis and Information Systems Security | ||||
| 21a.1 | Risk Assessment Methodology • Documented cybersecurity risk assessment methodology covering identification, analysis, and evaluation of cyber risks? • Methodology includes likelihood and impact scales, risk acceptance criteria? • Methodology reviewed and updated annually? | — | Risk methodology document; risk register; review records | |
| 21a.2 | Information Security Policy • Overarching IS policy approved by management body and published? • Policy covers all NIS2-relevant security areas (access, incident, supply chain, crypto, etc.)? • Version-controlled, communicated to all staff, and available to relevant external parties? | — | IS Policy document; approval evidence; distribution records | |
| 21a.3 | Cyber Risk Register • Cyber risk register maintained and kept current with identified risks, owners, and treatment plans? • Risks reviewed at minimum quarterly or on occurrence of significant changes? • Risk treatment actions tracked to closure with owner accountability? | — | Risk register; treatment plans; review records; action tracker | |
| 21a.4 | Threat Intelligence • Threat intelligence feeds integrated into risk management processes? • Sector-specific intelligence (ENISA, national CSIRT, ISACs) monitored? • Threat landscape reviewed in management reporting? | — | Threat intel subscriptions; feed integration evidence; management reports | |
| 21a.5 | Annual and Event-Driven Risk Review • Risk assessment conducted at least annually and triggered by significant changes? • Results presented to management body with action plan? • Risk decisions documented with residual risk acceptance by risk owners? | — | Annual risk assessment reports; management presentation; acceptance records | |
| Art. 21(b): Incident Handling (Prevention, Detection, Analysis, Containment, Recovery) | ||||
| 21b.1 | Incident Response Plan • Documented IRP approved by management and tested at least annually? • Plan covers all phases: detection, analysis, containment, eradication, recovery, post-incident review? • Roles and responsibilities assigned for each phase? | — | IRP document; test exercise records; role assignments | |
| 21b.2 | Detection and Monitoring Capabilities • Technical monitoring and detection capabilities deployed across network and systems? • SIEM, IDS/IPS, EDR, or equivalent tools providing 24/7 alerting for critical systems? • Detection coverage documented (assets, alert categories, response SLAs)? | — | SIEM/monitoring tool evidence; alert coverage matrix; SLA documentation | |
| 21b.3 | Incident Analysis, Triage and Playbooks • Incident triage and severity classification procedure defined? • Escalation thresholds and communication chains documented? • Playbooks/runbooks for common incident types (ransomware, data breach, DDoS)? | — | Triage procedure; severity matrix; playbooks; escalation tree | |
| 21b.4 | Containment and Eradication • Procedures for containing threats and isolating compromised systems? • Network isolation / quarantine capability tested? • Malware removal, system cleaning, and rebuild procedures documented? | — | Containment procedures; isolation test records; rebuild procedures | |
| 21b.5 | Recovery Procedures • Post-incident recovery procedures documented with RTOs defined for critical services? • Service restoration steps, validation tests, and sign-off process documented? • Return-to-normal-operations criteria defined? | — | Recovery procedures; RTO/RPO definitions; restoration test records | |
| 21b.6 | Post-Incident Review and Lessons Learned • Post-incident review conducted for all significant incidents? • Lessons learned documented and actions assigned with owners and due dates? • Root cause analysis outputs feeding back into risk management and policy updates? | — | PIR reports; action tracker; risk register updates; policy revision evidence | |
| Art. 21(c): Business Continuity, Backup Management, Disaster Recovery & Crisis Management | ||||
| 21c.1 | Business Continuity Plan (BCP) • BCP documented covering all critical network and information services? • BCP tested at least annually including cyber incident scenarios? • BCP roles, escalation contacts, and activation criteria documented? | — | BCP document; test exercise reports; activation records | |
| 21c.2 | Backup Policy and Testing • Backup policy covering scope, frequency, retention period, storage location (including offsite/air-gapped), and encryption? • Backups of all critical systems taken and restoration tested regularly (at minimum quarterly)? • Backup integrity verification and restoration time measured? | — | Backup policy; backup logs; restoration test records; integrity check results | |
| 21c.3 | IT Disaster Recovery Plan • IT DR plan aligned with BCP covering critical systems failover and recovery? • RTO and RPO defined and agreed for all critical services? • DR failover testing conducted at least annually with results documented? | — | DR plan; RTO/RPO register; DR test results; BCP alignment evidence | |
| 21c.4 | Crisis Management Procedures • Crisis management procedures for major cyber events documented? • Crisis team composition, roles, and escalation path defined? • Crisis communications plan covering internal, external, media, and regulatory communications? | — | Crisis management plan; team composition; comms templates; exercise records | |
| 21c.5 | Emergency Contacts and Communication Resilience • Emergency contact list (key personnel, regulators, suppliers, authorities) maintained and reviewed quarterly? • Out-of-band communication capability available if primary systems are compromised? • Contacts tested during exercises? | — | Emergency contact directory; review records; out-of-band comms test evidence | |
| Art. 21(d): Supply Chain Security | ||||
| 21d.1 | Supplier Inventory and Risk Register • Comprehensive inventory of critical third-party suppliers and service providers maintained? • Supply chain risk register with risk ratings, criticality classification, and last assessment dates? • Suppliers categorised by tier (critical, significant, standard)? | — | Supplier inventory; supply chain risk register; tiering criteria | |
| 21d.2 | Security Requirements in Supplier Contracts • Cybersecurity requirements included in all critical supplier contracts? • Contractual clauses covering: incident notification obligations, minimum security standards, audit rights, data protection? • Compliance with ENISA supply chain security guidelines reviewed? | — | Sample supplier contracts; security clauses checklist; legal review evidence | |
| 21d.3 | Supplier Security Assessments and Audits • Regular security assessments or audits of critical suppliers conducted? • Assessment frequency based on supplier risk tier (critical: annual, significant: biennial)? • Assessment results tracked and remediation plans monitored? | — | Supplier assessment reports; assessment schedule; remediation tracker | |
| 21d.4 | Software and Hardware Provenance • Process to verify integrity and authenticity of software and hardware from suppliers? • SBOM (software bill of materials) or equivalent for critical software components? • Third-party component vulnerability monitoring (CVE tracking, vendor advisories)? | — | SBOM records; software verification process; CVE monitoring evidence | |
| 21d.5 | Third-Party Access Controls • Privileged and remote access by suppliers formally controlled, monitored, and logged? • Just-in-time access provisioning or session recording for critical supplier access? • Formal offboarding process for terminated supplier relationships? | — | Access control logs; JIT access records; session recordings; offboarding checklist | |
| Art. 21(e): Network Security, Secure Acquisition, Development & Maintenance | ||||
| 21e.1 | Network Security Architecture • Network segmentation, perimeter controls, and access control architecture documented? • Firewall policies, DMZ, and micro-segmentation implemented and reviewed annually? • Network architecture diagram current and accurate? | — | Network architecture docs; firewall rules review; segmentation evidence | |
| 21e.2 | Vulnerability Management Programme • Vulnerability scanning programme covering all in-scope network assets and systems? • Critical and high vulnerabilities patched within defined SLAs (e.g., critical 72h, high 14 days)? • Vulnerability management KPIs tracked and reported to management? | — | Scan reports; patch SLA policy; KPI reports; remediation records | |
| 21e.3 | Secure Development Lifecycle (SDLC) • Secure SDLC policy covering design, code review, testing, and deployment? • SAST/DAST tools integrated into CI/CD pipeline for developed applications? • Security testing (penetration testing) conducted for significant system changes? | — | SDLC policy; SAST/DAST results; pen test reports; code review evidence | |
| 21e.4 | Change Management • Formal change management process for all IS/network changes with security impact assessment? • Changes tested and approved before production deployment? • Post-change review and rollback capability documented and tested? | — | Change management process; CAB records; security assessment forms; rollback plans | |
| 21e.5 | Vulnerability Disclosure Policy • Responsible vulnerability disclosure (RVD) policy published and accessible? • Reporting channel for external security researchers (security.txt or equivalent)? • CVE coordination and NCA disclosure process documented? | — | RVD policy; disclosure channel; coordination procedure; CVD history | |
| Ref | Requirement & Audit Check Points | Status | Evidence Required | Auditor Notes |
|---|---|---|---|---|
| Art. 21(f): Policies and Procedures to Assess Effectiveness of Cybersecurity Measures | ||||
| 21f.1 | Cybersecurity KPIs and Metrics Framework • Cybersecurity KPIs and metrics defined, measured, and reported at planned intervals? • Metrics cover: detection times, response times, patch compliance, training completion, incident rates? • KPIs reviewed against targets and reported to management quarterly? | — | KPI framework; metric reports; management dashboard; target comparison | |
| 21f.2 | Independent Audits and Penetration Testing • Regular independent security audits of key controls conducted (at least annually)? • Penetration testing of critical systems and interfaces performed? • Audit and test findings tracked to remediation with owner accountability? | — | Audit reports; pen test results; finding tracker; remediation evidence | |
| 21f.3 | Continuous Monitoring of Control Effectiveness • Continuous monitoring programme for security control effectiveness in place? • Automated compliance checks for critical controls (e.g., patching, AV, config compliance)? • Monitoring results integrated with risk management and reported to management? | — | Monitoring tool evidence; compliance reports; integration with risk register | |
| 21f.4 | Management Review of Cybersecurity Effectiveness • Cybersecurity effectiveness formally reviewed by management at minimum annually? • Review inputs include: audit results, KPIs, incidents, threat intelligence, risk changes? • Review outputs (decisions, improvement actions) documented and tracked? | — | Management review minutes; action register; improvement plans | |
| Art. 21(g): Basic Cyber Hygiene Practices and Cybersecurity Training | ||||
| 21g.1 | Cyber Hygiene Baseline Standards • Basic cyber hygiene standards documented and enforced across the organisation? • Standards cover: password/MFA policy, patching cadence, AV/EDR, phishing awareness, secure configurations? • Hygiene baseline applied consistently to employees, contractors, and managed devices? | — | Cyber hygiene policy; baseline standards doc; compliance monitoring evidence | |
| 21g.2 | Security Awareness Training Programme • Mandatory security awareness training for all staff at onboarding and annually thereafter? • Training covers NIS2 obligations, phishing, social engineering, incident reporting procedures? • Effectiveness measured via phishing simulations, tests, or assessments? | — | Training programme; completion records; phishing simulation results; test scores | |
| 21g.3 | Technical and Security Staff Training • Role-specific cybersecurity training for IT, security, and DevOps staff? • CPD/certification requirements for security roles defined (e.g., CISSP, CISM, SC-200)? • Training programme aligned with current threat landscape and NIS2 requirements? | — | Training plan; certifications; CPD records; role-specific curriculum | |
| 21g.4 | Incident Response Exercises • Tabletop or live incident response exercises conducted at minimum annually? • Exercises include NIS2 reporting timeline scenarios (24h / 72h obligations)? • Exercise findings documented and actioned in IRP updates? | — | Exercise programme; exercise reports; after-action reviews; IRP updates | |
| Art. 21(h): Policies and Procedures Regarding Cryptography and Encryption | ||||
| 21h.1 | Cryptography and Encryption Policy • Cryptography and encryption policy approved and implemented? • Policy specifies approved algorithms (AES-256, RSA-2048+, TLS 1.2+), key lengths, and prohibited ciphers? • Policy aligned with ENISA cryptographic guidelines and reviewed annually? | — | Cryptography policy; algorithm standards; annual review record | |
| 21h.2 | Encryption in Transit • TLS 1.2+ enforced for all web services, APIs, and external communications? • VPN or secure channels mandatory for all remote access? • Deprecated protocols (TLS 1.0/1.1, SSL, unencrypted HTTP) disabled and monitored? | — | TLS configuration scans; VPN policy; protocol audit reports | |
| 21h.3 | Encryption at Rest • Full disk encryption deployed on all laptops, mobile devices, and portable media? • Database and file-level encryption for sensitive personal and business data at rest? • Cloud storage encryption verified (customer-managed keys where applicable)? | — | Encryption inventory; FDE compliance reports; cloud encryption config | |
| 21h.4 | Cryptographic Key Management • Key management procedures covering generation, storage, rotation, and secure destruction? • HSM or secure key vault (e.g., Azure Key Vault, AWS KMS, HashiCorp Vault) used for critical keys? • Key rotation schedule defined and enforced? | — | Key management procedure; key inventory; HSM/vault configuration; rotation logs | |
| Art. 21(i): Human Resources Security, Access Control Policies and Asset Management | ||||
| 21i.1 | Asset Inventory • Comprehensive inventory of network and information system assets (hardware, software, data, cloud)? • Asset register reviewed and updated quarterly; ownership assigned? • Asset criticality classification used to prioritise protection measures? | — | Asset register; discovery scan results; criticality classification; review records | |
| 21i.2 | HR Security and Pre-Employment Screening • Pre-employment screening for all roles with significant IS access (background checks, references)? • Employment contracts include cybersecurity obligations (acceptable use, confidentiality, NIS2 awareness)? • Disciplinary process for cybersecurity policy violations documented? | — | Screening policy; contract templates; disciplinary procedure; HR records | |
| 21i.3 | Access Control Policy (Least Privilege) • Formal access control policy based on least privilege and need-to-know principles? • Role-based access control (RBAC) implemented for all critical systems? • Access reviews conducted at minimum bi-annually with documented outcomes? | — | Access control policy; RBAC matrix; access review records | |
| 21i.4 | Privileged Access Management (PAM) • Privileged accounts inventoried, justified, and controlled via PAM solution or equivalent? • Privileged sessions monitored and recorded for critical systems? • Shared accounts eliminated or strictly controlled with individual accountability? | — | PAM tool evidence; privileged account register; session logs; shared account policy | |
| 21i.5 | Identity Lifecycle Management (Joiners, Movers, Leavers) • Formal JML process ensuring IS access granted, modified, and revoked in a timely manner? • Automated de-provisioning or SLA-bound manual revocation for leavers? • Regular reconciliation of access rights against current employment/role status? | — | JML procedure; provisioning/de-provisioning logs; access reconciliation records | |
| Art. 21(j): Multi-Factor Authentication and Secure Communications | ||||
| 21j.1 | Multi-Factor Authentication (MFA) • MFA enforced for all remote access (VPN, RDP, cloud portals) and all privileged accounts? • MFA extended to all external-facing services and applications with user accounts? • MFA policy documented with exceptions process requiring formal risk acceptance? | — | MFA enforcement evidence; exceptions register; policy document | |
| 21j.2 | Continuous and Risk-Based Authentication • Continuous or risk-based authentication implemented for sensitive transactions and privileged actions? • Session timeouts enforced and re-authentication triggered for high-risk operations? • Anomalous access patterns triggering step-up authentication? | — | Authentication policy; session timeout config; risk-based auth logs; anomaly alerts | |
| 21j.3 | Secure Voice, Video and Text Communications • Secured communication solutions mandated for sensitive business discussions (E2E encrypted platforms)? • BYOD policy addressing secure communications requirements for personal devices? • Staff trained on approved vs prohibited communication channels for sensitive data? | — | Secure comms policy; approved tool list; BYOD policy; training evidence | |
| 21j.4 | Emergency Communication Systems • Secured emergency communication systems available for use during cyber incidents? • Out-of-band communication channel maintained and tested (e.g., separate phone lines, encrypted messaging)? • Emergency communication channel included in crisis management exercises? | — | Emergency comms system documentation; OOB channel test records; exercise evidence | |