NIS2

Checklist: Is Your Organisation Ready for NIS2?

Are you covered by NIS2? Use our checklist to assess your readiness and identify gaps for full compliance.

  1. 18
    sectors covered by NIS2
    NIS2 Directive
  2. 50+
    employees or €10M turnover as threshold
    NIS2 Directive
  3. 6
    main areas for compliance
    NIS2 Directive Article 21

Step 1: Are You Covered?

Size Criteria

Does your organisation meet at least one of the following?

  • 50+ employees
  • €10+ million in annual turnover

If yes to at least one, continue to the sector check below.

Exception: Certain critical services are covered regardless of size (DNS, qualified trust services, TLD registries).

Sector Check

Does your organisation operate in any of these sectors?

Essential entities (strictest requirements):

  • Energy (electricity, oil, gas, district heating, hydrogen)
  • Transport (aviation, rail, road, maritime)
  • Banking
  • Financial market infrastructure
  • Healthcare
  • Drinking water
  • Wastewater
  • Digital infrastructure (DNS, data centres, cloud, CDN)
  • ICT service management (B2B managed services, MSP)
  • Public administration (central level)
  • Space (ground-based infrastructure)

Important entities:

  • Postal and courier services
  • Waste management
  • Chemicals (manufacturing, production, distribution)
  • Food (production, processing, distribution)
  • Manufacturing (medical devices, computers, electronics, vehicles, machinery)
  • Digital services (marketplaces, search engines, social platforms)
  • Research (excluding education)

Result:

  • ✅ Size + Sector = You are covered by NIS2
  • ⚠️ Under threshold but critical service = Check specific exceptions
  • ⚠️ Supplier to covered organisation = You may be affected indirectly

Want a quicker assessment? Use our interactive NIS2 classification tool which gives you answers in minutes.


Step 2: Checklist by Area

Area 1: Risk Management

Basic requirements:

  • Systematic risk management process is documented
  • Risk assessments are conducted regularly (at least annually)
  • Risks are categorised and prioritised
  • Risk treatment plans exist for identified risks
  • Risk register is updated and accessible

Advanced:

  • Risk methodology follows established standard (ISO 27005 or similar)
  • Management approves risk acceptance levels
  • Risks are monitored and reported to management
  • Threat and vulnerability analysis is conducted

Score: ___ / 9

Area 2: Incident Management

Basic requirements:

  • Incident management process is documented
  • Definition of “significant incident” is established
  • Contact channels to national CSIRT are established
  • Templates for three report types exist (24h, 72h, 1 month)
  • Escalation procedures are documented

Advanced:

  • Incident management has been tested/exercised in the last year
  • On-call capability or equivalent exists for rapid response
  • Incidents are logged and analysed for lessons learned
  • Forensic capability exists (internal or via partner)

Score: ___ / 9

Area 3: Business Continuity

Basic requirements:

  • Business continuity plan is documented
  • Critical systems and processes are identified
  • Backup exists for critical systems and data
  • RTO and RPO are defined for critical systems
  • Disaster recovery plan exists

Advanced:

  • Continuity plans have been tested in the last year
  • Backup restoration is tested regularly
  • Alternative workplaces/systems are identified
  • Crisis communication plan exists

Score: ___ / 9

Area 4: Supplier Security

Basic requirements:

  • Critical suppliers are identified
  • Security requirements are imposed on suppliers
  • Contracts contain security clauses
  • Initial security assessment is conducted
  • Suppliers must report incidents

Advanced:

  • Regular follow-up of suppliers occurs
  • Sub-suppliers are controlled
  • Supplier register is updated
  • Exit strategy exists for critical suppliers

Score: ___ / 9

Area 5: Technical Controls

Basic requirements:

  • Access control and permissions management exists
  • Encryption is used for sensitive data
  • Security logs are generated and stored
  • Antivirus/EDR exists on endpoints
  • Network segmentation is implemented

Advanced:

  • MFA is used for critical systems
  • Vulnerability scanning is conducted regularly
  • Patches are installed within defined timeframes
  • Penetration tests are conducted periodically

Score: ___ / 9

Area 6: Governance and Documentation

Basic requirements:

  • Cybersecurity policy exists and is approved by management
  • Management has undergone cybersecurity training
  • Responsibility allocation for security is documented
  • Staff are trained in security awareness
  • Documentation is version-controlled and accessible

Advanced:

  • Regular reporting to the board occurs
  • Security objectives and KPIs are defined
  • Internal audits are conducted
  • Improvement process is documented

Score: ___ / 9


Step 3: Calculate Total

Total Score

AreaScore
Risk Management___ / 9
Incident Management___ / 9
Business Continuity___ / 9
Supplier Security___ / 9
Technical Controls___ / 9
Governance and Documentation___ / 9
TOTAL___ / 54

Interpretation

0-18 points: Critical level

Significant gaps exist. Prioritise immediately: start with risk management and incident management. Consider external help to accelerate the process.

19-36 points: Developing level

Foundation exists, but important parts are missing. Identify areas where you scored lowest and prioritise these.

37-45 points: Good level

You're on the right track. Focus on advanced requirements and continuous improvement.

46-54 points: Mature level

Strong position. Ensure ongoing maintenance, testing, and adaptation to new requirements.


Step 4: Next Steps

For Low Scores (0-36)

  1. Secure management commitment NIS2 requires management engagement. Present the requirements and consequences to secure mandate and resources.
  2. Conduct GAP analysis Perform formal mapping of what's missing for NIS2 compliance. Prioritise based on risk.
  3. Create action plan Define activities, responsibilities, deadlines, and resources to close the gaps.
  4. Start with risk management A functioning risk management process is the foundation for everything else. Begin there.

For High Scores (37-54)

  1. Test your processes A plan on paper is not the same as working capability. Conduct exercises and tests.
  2. Strengthen documentation Ensure everything is documented in a way that can be presented during supervision.
  3. Focus on continuity NIS2 compliance is not a project — it's a continuous process. Establish maintenance routines.

Need more details about requirements? See our complete NIS2 framework overview for in-depth information about each requirement area.

How Securapilot Can Help

Securapilot gives you the tools to go from checklist to action:

  • Automated GAP analysis — Map current state against NIS2 requirements
  • Risk management module — Structured risk assessment and treatment
  • Incident management — Processes and reports that meet timing requirements
  • Supplier management — Overview and assessment of suppliers
  • Dashboard — Real-time overview of compliance status

Book a demo and see how we can help you achieve NIS2 compliance.


Frequently asked questions

How do I know if my organisation is covered by NIS2?

Generally, organisations with at least 50 employees or €10 million turnover within the 18 defined sectors are covered. Certain critical services are covered regardless of size. Use the checklist below to assess your situation.

What happens if we're not compliant?

Non-compliance can lead to fines up to €10 million or 2% of global turnover for essential entities. Management can also be held personally liable.

How long does it take to become NIS2-compliant?

It varies depending on current maturity level. Organisations starting from scratch should expect 12-18 months. Those with existing ISO 27001 certification can often achieve compliance in 3-6 months.

Can suppliers be affected?

Yes, indirectly. NIS2 requires supply chain security, meaning covered organisations will impose requirements on their suppliers. Even if you're not directly covered, you may need to meet requirements to retain customers.


#NIS2#checklist#compliance#cybersecurity#readiness#self-assessment

We use anonymous statistics without cookies to improve the website. Read more