Step 1: Are You Covered?
Size Criteria
Does your organisation meet at least one of the following?
- 50+ employees
- €10+ million in annual turnover
If yes to at least one, continue to the sector check below.
Exception: Certain critical services are covered regardless of size (DNS, qualified trust services, TLD registries).
Sector Check
Does your organisation operate in any of these sectors?
Essential entities (strictest requirements):
- Energy (electricity, oil, gas, district heating, hydrogen)
- Transport (aviation, rail, road, maritime)
- Banking
- Financial market infrastructure
- Healthcare
- Drinking water
- Wastewater
- Digital infrastructure (DNS, data centres, cloud, CDN)
- ICT service management (B2B managed services, MSP)
- Public administration (central level)
- Space (ground-based infrastructure)
Important entities:
- Postal and courier services
- Waste management
- Chemicals (manufacturing, production, distribution)
- Food (production, processing, distribution)
- Manufacturing (medical devices, computers, electronics, vehicles, machinery)
- Digital services (marketplaces, search engines, social platforms)
- Research (excluding education)
Result:
- ✅ Size + Sector = You are covered by NIS2
- ⚠️ Under threshold but critical service = Check specific exceptions
- ⚠️ Supplier to covered organisation = You may be affected indirectly
Want a quicker assessment? Use our interactive NIS2 classification tool which gives you answers in minutes.
Step 2: Checklist by Area
Area 1: Risk Management
Basic requirements:
- Systematic risk management process is documented
- Risk assessments are conducted regularly (at least annually)
- Risks are categorised and prioritised
- Risk treatment plans exist for identified risks
- Risk register is updated and accessible
Advanced:
- Risk methodology follows established standard (ISO 27005 or similar)
- Management approves risk acceptance levels
- Risks are monitored and reported to management
- Threat and vulnerability analysis is conducted
Score: ___ / 9
Area 2: Incident Management
Basic requirements:
- Incident management process is documented
- Definition of “significant incident” is established
- Contact channels to national CSIRT are established
- Templates for three report types exist (24h, 72h, 1 month)
- Escalation procedures are documented
Advanced:
- Incident management has been tested/exercised in the last year
- On-call capability or equivalent exists for rapid response
- Incidents are logged and analysed for lessons learned
- Forensic capability exists (internal or via partner)
Score: ___ / 9
Area 3: Business Continuity
Basic requirements:
- Business continuity plan is documented
- Critical systems and processes are identified
- Backup exists for critical systems and data
- RTO and RPO are defined for critical systems
- Disaster recovery plan exists
Advanced:
- Continuity plans have been tested in the last year
- Backup restoration is tested regularly
- Alternative workplaces/systems are identified
- Crisis communication plan exists
Score: ___ / 9
Area 4: Supplier Security
Basic requirements:
- Critical suppliers are identified
- Security requirements are imposed on suppliers
- Contracts contain security clauses
- Initial security assessment is conducted
- Suppliers must report incidents
Advanced:
- Regular follow-up of suppliers occurs
- Sub-suppliers are controlled
- Supplier register is updated
- Exit strategy exists for critical suppliers
Score: ___ / 9
Area 5: Technical Controls
Basic requirements:
- Access control and permissions management exists
- Encryption is used for sensitive data
- Security logs are generated and stored
- Antivirus/EDR exists on endpoints
- Network segmentation is implemented
Advanced:
- MFA is used for critical systems
- Vulnerability scanning is conducted regularly
- Patches are installed within defined timeframes
- Penetration tests are conducted periodically
Score: ___ / 9
Area 6: Governance and Documentation
Basic requirements:
- Cybersecurity policy exists and is approved by management
- Management has undergone cybersecurity training
- Responsibility allocation for security is documented
- Staff are trained in security awareness
- Documentation is version-controlled and accessible
Advanced:
- Regular reporting to the board occurs
- Security objectives and KPIs are defined
- Internal audits are conducted
- Improvement process is documented
Score: ___ / 9
Step 3: Calculate Total
Total Score
| Area | Score |
|---|---|
| Risk Management | ___ / 9 |
| Incident Management | ___ / 9 |
| Business Continuity | ___ / 9 |
| Supplier Security | ___ / 9 |
| Technical Controls | ___ / 9 |
| Governance and Documentation | ___ / 9 |
| TOTAL | ___ / 54 |
Interpretation
Significant gaps exist. Prioritise immediately: start with risk management and incident management. Consider external help to accelerate the process.
Foundation exists, but important parts are missing. Identify areas where you scored lowest and prioritise these.
You're on the right track. Focus on advanced requirements and continuous improvement.
Strong position. Ensure ongoing maintenance, testing, and adaptation to new requirements.
Step 4: Next Steps
For Low Scores (0-36)
- Secure management commitment NIS2 requires management engagement. Present the requirements and consequences to secure mandate and resources.
- Conduct GAP analysis Perform formal mapping of what's missing for NIS2 compliance. Prioritise based on risk.
- Create action plan Define activities, responsibilities, deadlines, and resources to close the gaps.
- Start with risk management A functioning risk management process is the foundation for everything else. Begin there.
For High Scores (37-54)
- Test your processes A plan on paper is not the same as working capability. Conduct exercises and tests.
- Strengthen documentation Ensure everything is documented in a way that can be presented during supervision.
- Focus on continuity NIS2 compliance is not a project — it's a continuous process. Establish maintenance routines.
Need more details about requirements? See our complete NIS2 framework overview for in-depth information about each requirement area.
How Securapilot Can Help
Securapilot gives you the tools to go from checklist to action:
- Automated GAP analysis — Map current state against NIS2 requirements
- Risk management module — Structured risk assessment and treatment
- Incident management — Processes and reports that meet timing requirements
- Supplier management — Overview and assessment of suppliers
- Dashboard — Real-time overview of compliance status
Book a demo and see how we can help you achieve NIS2 compliance.
Frequently asked questions
How do I know if my organisation is covered by NIS2?
Generally, organisations with at least 50 employees or €10 million turnover within the 18 defined sectors are covered. Certain critical services are covered regardless of size. Use the checklist below to assess your situation.
What happens if we're not compliant?
Non-compliance can lead to fines up to €10 million or 2% of global turnover for essential entities. Management can also be held personally liable.
How long does it take to become NIS2-compliant?
It varies depending on current maturity level. Organisations starting from scratch should expect 12-18 months. Those with existing ISO 27001 certification can often achieve compliance in 3-6 months.
Can suppliers be affected?
Yes, indirectly. NIS2 requires supply chain security, meaning covered organisations will impose requirements on their suppliers. Even if you're not directly covered, you may need to meet requirements to retain customers.