Most NIS2 programmes stall in the gaps between teams: nobody confirmed which national law applies, the board approved a policy it never saw again, and the first time anyone reads Article 23 is the night of the incident.
NIS2 puts cybersecurity duties on essential and important entities in 18 sectors and makes their management bodies answerable for them. This free NIS2 compliance checklist runs the programme for a security or compliance lead: classification, registration, management body approval and training, the Article 21 measures, supply chain security, incident reporting readiness and the annual review. Answers in Phase 1 switch on the provider-specific and essential entity tasks only where they apply. The result is a dated record of who approved, tested and reviewed what.
NIS2 is Directive (EU) 2022/2555. It replaced the first NIS Directive on 18 October 2024 and covers 18 sectors: 11 in Annex I, such as energy, transport, health and digital infrastructure, and 7 in Annex II, including manufacturing, food and digital providers. A listed entity is in scope once it is at least medium-sized under Recommendation 2003/361/EC: 50 or more staff, or annual turnover and balance sheet total both above €10 million.
Because it is a directive, the duties reach you through national law. The transposition deadline was 17 October 2024. The Commission sent letters of formal notice to 23 member states on 28 November 2024 and reasoned opinions to 19 on 7 May 2025. Germany’s law took effect on 6 December 2025, bringing about 29,500 entities under BSI supervision. On 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice, asking for a lump sum and daily penalties. The Dutch law, adopted the day before, took effect on 15 August 2026. Work on Articles 20, 21 and 23 carries across borders; registration routes and authorities do not.
Essential entity
Supervised before anything goes wrong
Who: large Annex I entities; qualified trust service providers, TLD registries and DNS service providers of any size; central government; CER Directive critical entities; and entities a member state designates.
Supervision: inspections, random checks, regular and targeted security audits and security scans (Article 32).
Fines: a maximum of at least €10 million or 2% of worldwide annual turnover, whichever is higher.
Important entity
Supervised after the event
Who: every other in-scope entity, typically medium-sized Annex I and all Annex II entities.
Supervision: ex post, on evidence or indication of non-compliance (Article 33).
Fines: a maximum of at least €7 million or 1.4% of worldwide annual turnover, whichever is higher.
Financial entities follow DORA instead
Banks, insurers, investment firms and other DORA entities
DORA, Regulation (EU) 2022/2554, has applied since 17 January 2025. Recital 28 of NIS2 treats it as a sector-specific act under Article 4, so the NIS2 rules on risk management, incident reporting, supervision and enforcement should not be applied to the financial entities it covers. A group with a bank and a data centre business may need both programmes.
What the NIS2 Compliance Checklist Covers
Seven phases, from classification to a re-approved annual review. Article numbers are from Directive (EU) 2022/2555.
Phase 1
Phase 1: Scope, Classification & National Law
Answers in this phase drive the conditional tasks in Phases 2, 4 and 7.
Map each legal entity to an Annex I or II sector and a size band — sector, entity type, headcount, turnover and balance sheet
Check the size-independent triggers in Article 2(2) to 2(4) — trust services, DNS, TLD registries, domain registration, telecoms, sole providers, critical entities
Confirm whether DORA displaces NIS2 for any entity in the group — financial entities follow DORA’s ICT risk and incident rules instead
Identify the national law, competent authority and CSIRT in each country — plus national additions, and the Article 26 main establishment rule for digital providers
Record the entity as essential or important, with the reasoning — authorities keep their own list and review it at least every two years (Article 3(3))
Phase 2
Phase 2: Registration & Contact Details
The registry task appears only for the digital provider types listed in Article 27.
Register with each competent authority through its national mechanism — contact details, IP ranges, sector and member states served (Article 3(4))
Submit the Article 27 registry details — main establishment or EU representative, member states served and IP ranges, for ENISA’s registry
File the authority’s confirmation or reference number — with a record of what was submitted and when
Set a trigger for changes to registered details — the Directive allows two weeks under Article 3(4) and three months under Article 27(3); national law may differ
Phase 3
Phase 3: Management Body Approval & Training
Article 20 makes the management body approve the measures, oversee their implementation and answer for infringements.
Present the Article 21 measures to the management body for approval — the risk assessment, treatment plan and policies
Record the approval with its date, attendees and document versions — tying the decision to exactly what was approved
Agree how the body will oversee implementation — reporting cadence, metrics and presenter
Complete cybersecurity training for every management body member — mandatory under Article 20(2); national law sets the detail
Phase 4
Phase 4: Article 21 Risk-Management Measures
Ten minimum measures, points (a) to (j), on an all-hazards basis. The last task appears only for providers covered by Implementing Regulation (EU) 2024/2690.
Run and document the cybersecurity risk assessment — point (a), with a risk treatment plan
Test incident handling, backups, disaster recovery and crisis management — points (b) and (c), each with a dated test
Evidence secure acquisition, development and vulnerability handling — point (e), including vulnerability disclosure
Confirm cyber hygiene, cryptography, HR security, access control and assets — points (g) to (i), including training and an asset inventory
Confirm MFA and secured communications where appropriate — point (j), including emergency communications
Assess whether the measures work — point (f): test controls, not just policies
Map controls to the Annex of Implementing Regulation (EU) 2024/2690 — the security policy and risk treatment plan are reviewed at least annually
Phase 5
Phase 5: Supply Chain Security
List the direct suppliers and service providers that affect your systems — point (d), including managed and cloud services
Assess each supplier’s vulnerabilities and security practices — product quality and secure development (Article 21(3))
Check the EU coordinated supply chain risk assessments — Article 21(3) requires their results to be considered
Send critical suppliers through a full vendor risk assessment — with a residual risk rating and an approver
Phase 6
Phase 6: Incident Reporting Readiness
Define what a significant incident means for the entity — severe operational disruption or financial loss, or considerable damage to others (Article 23(3))
Record the reporting route and test portal access — CSIRT or authority, form, named reporters and deputies
Assign owners for the 24-hour early warning and 72-hour notification — both run from becoming aware, nights and weekends included
Prepare templates for the final and progress reports — due one month after the notification
Set the rule for informing recipients of the service — who is told, by whom, and what they can do (Article 23(1) and (2))
Link the process to GDPR breach notification — personal data may also need a GDPR Article 33 report within 72 hours
Rehearse the reporting chain in a tabletop exercise — timing each stage against the deadlines
Phase 7
Phase 7: Annual Review & Supervision Readiness
The audit and accountability tasks appear only when the entity is classified as essential. Important entities are supervised after the event under Article 33.
Track a corrective measure for every gap found — without undue delay, as Article 21(4) requires
Assemble the evidence pack an authority would request — policies, audit results and underlying evidence (Articles 32 and 33)
Prepare for regular and targeted security audits — Article 32(2)(b); the entity usually pays for a targeted audit by an independent body
Name the individuals accountable for compliance — Article 32(6) requires that they can be held liable
Re-check classification, registration and national law — size, services, countries and laws change
Present the annual review to the management body for re-approval — closing the Article 20 loop
NIS2 Obligations and Where the Checklist Evidences Them
The table maps the Directive’s core obligations to evidence and to the phase that produces it. National laws decide the detail, so treat it as a starting point, not legal advice.
Article 23 sets four reporting stages for a significant incident.
Within 24 hours of becoming aware
Early warning
Whether the incident is suspected to be malicious and could have cross-border impact. Trust service providers file the full notification within 24 hours when trust services are hit.
Within 72 hours of becoming aware
Incident notification
An initial assessment of severity and impact, with indicators of compromise where available.
On request
Intermediate report
Status updates when the CSIRT or authority asks.
One month after the notification
Final report
Description, likely root cause, mitigation and cross-border impact. If the incident is still ongoing, a progress report instead, then the final report within one month of handling it.
Two proposals would change this; neither is adopted. The Digital Omnibus, proposed in November 2025, would route Article 23 reports through a single ENISA entry point, keeping the stages and deadlines. A January 2026 proposal to amend NIS2 would add a small mid-cap category treated as important entities, ask for ransomware details in reports and limit national add-ons where EU implementing rules exist. At the time of review both were still before European Parliament committees.
Why Run Your NIS2 Programme in CheckFlow?
1
An approval the board can be held to
Article 20 approval runs as a CheckFlow approval, recording who approved, when, and which policy versions. The activity trail covers every later step, and template versioning ties each year to the checklist it used.
2
Reporting deadlines with names on them
Run a separate incident reporting checklist, started by hand or from your alerting through the REST API or Zapier. Dynamic due dates set the 24-hour, 72-hour and one-month steps, and group assignment means the early warning still has an owner at 3am.
3
One programme across several countries
A data set holds each country’s law, authority, CSIRT and registration reference and fills the Phase 1 and 2 tasks. Conditional logic shows the registry and essential entity tasks only where they apply, and a recurring schedule starts the annual review.
CheckFlow is not a GRC platform, a security monitoring tool or a national reporting portal. Reports still go to your CSIRT or authority through their channel; CheckFlow makes sure the right person files each one on time. CheckFlow’s compliance checklist software shows how the same schedules, approvals and audit trail work across your other frameworks.
For the Phase 5 suppliers that matter most, the Vendor Risk Assessment Checklist runs the full due diligence. Many teams use NIST CSF 2.0 as the control framework behind their Article 21 measures, and the NIST CSF 2.0 Checklist runs that assessment. When an incident starts, the Incident Management Checklist handles the response while this page’s Phase 6 covers the regulatory reports.
Two tests decide it: your entity type appears in Annex I or II, and you are at least medium-sized (50 or more staff, or turnover and balance sheet both above €10 million). Trust service providers, DNS service providers, TLD registries and domain registration services are covered at any size, and national law can designate smaller entities.
What is the difference between essential and important entities under NIS2?
+
Both have the same duties under Articles 20, 21 and 23. Essential entities are supervised proactively and face higher maximum fines; important entities are supervised after the event. For essential entities, if earlier enforcement fails, Article 32(5) also allows temporary suspension of a certification or authorisation, and a temporary ban on a chief executive or legal representative exercising managerial functions.
What are the NIS2 incident reporting deadlines?
+
An early warning within 24 hours of becoming aware of a significant incident, a notification within 72 hours, an intermediate report on request and a final report within one month of the notification. Providers covered by Implementing Regulation (EU) 2024/2690 have set criteria for what counts as significant, such as a direct financial loss above €500,000 or 5% of annual turnover, whichever is lower.
What are the fines for non-compliance with NIS2?
+
For breaches of Article 21 or 23, national law must allow fines up to at least €10 million or 2% of total worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever is higher in each case. National caps may be higher, and management body members can be held liable under Article 20.
Has every EU country transposed NIS2?
+
Not at the time of review. In July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for not notifying full transposition. Germany has applied its law since 6 December 2025, and the Netherlands since 15 August 2026. Where a law is pending, work to the Directive and the published draft, and check the national authority for the current position.
Does NIS2 apply to banks and other financial institutions?
+
For most financial entities, no. Banking is an Annex I sector, but DORA is the sector-specific law for financial entities, and its ICT risk and major incident reporting rules apply instead of NIS2’s. Non-financial companies in the same group may still fall under NIS2.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
Every NIS2 Duty Owned, Dated and Ready for the Authority
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more