NIS2 Compliance Checklist Template

Most NIS2 programmes stall in the gaps between teams: nobody confirmed which national law applies, the board approved a policy it never saw again, and the first time anyone reads Article 23 is the night of the incident.

NIS2 puts cybersecurity duties on essential and important entities in 18 sectors and makes their management bodies answerable for them. This free NIS2 compliance checklist runs the programme for a security or compliance lead: classification, registration, management body approval and training, the Article 21 measures, supply chain security, incident reporting readiness and the annual review. Answers in Phase 1 switch on the provider-specific and essential entity tasks only where they apply. The result is a dated record of who approved, tested and reviewed what.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: September 2026

Same Duties, Different Supervision

NIS2 is Directive (EU) 2022/2555. It replaced the first NIS Directive on 18 October 2024 and covers 18 sectors: 11 in Annex I, such as energy, transport, health and digital infrastructure, and 7 in Annex II, including manufacturing, food and digital providers. A listed entity is in scope once it is at least medium-sized under Recommendation 2003/361/EC: 50 or more staff, or annual turnover and balance sheet total both above €10 million.

Because it is a directive, the duties reach you through national law. The transposition deadline was 17 October 2024. The Commission sent letters of formal notice to 23 member states on 28 November 2024 and reasoned opinions to 19 on 7 May 2025. Germany’s law took effect on 6 December 2025, bringing about 29,500 entities under BSI supervision. On 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice, asking for a lump sum and daily penalties. The Dutch law, adopted the day before, took effect on 15 August 2026. Work on Articles 20, 21 and 23 carries across borders; registration routes and authorities do not.

Essential entity

Supervised before anything goes wrong

Who: large Annex I entities; qualified trust service providers, TLD registries and DNS service providers of any size; central government; CER Directive critical entities; and entities a member state designates.

Supervision: inspections, random checks, regular and targeted security audits and security scans (Article 32).

Fines: a maximum of at least €10 million or 2% of worldwide annual turnover, whichever is higher.

Important entity

Supervised after the event

Who: every other in-scope entity, typically medium-sized Annex I and all Annex II entities.

Supervision: ex post, on evidence or indication of non-compliance (Article 33).

Fines: a maximum of at least €7 million or 1.4% of worldwide annual turnover, whichever is higher.

Financial entities follow DORA instead

Banks, insurers, investment firms and other DORA entities

DORA, Regulation (EU) 2022/2554, has applied since 17 January 2025. Recital 28 of NIS2 treats it as a sector-specific act under Article 4, so the NIS2 rules on risk management, incident reporting, supervision and enforcement should not be applied to the financial entities it covers. A group with a bank and a data centre business may need both programmes.

What the NIS2 Compliance Checklist Covers

Seven phases, from classification to a re-approved annual review. Article numbers are from Directive (EU) 2022/2555.

Phase 1

Phase 1: Scope, Classification & National Law

Answers in this phase drive the conditional tasks in Phases 2, 4 and 7.

  • Map each legal entity to an Annex I or II sector and a size band — sector, entity type, headcount, turnover and balance sheet
  • Check the size-independent triggers in Article 2(2) to 2(4) — trust services, DNS, TLD registries, domain registration, telecoms, sole providers, critical entities
  • Confirm whether DORA displaces NIS2 for any entity in the group — financial entities follow DORA’s ICT risk and incident rules instead
  • Identify the national law, competent authority and CSIRT in each country — plus national additions, and the Article 26 main establishment rule for digital providers
  • Record the entity as essential or important, with the reasoning — authorities keep their own list and review it at least every two years (Article 3(3))
Phase 2

Phase 2: Registration & Contact Details

The registry task appears only for the digital provider types listed in Article 27.

  • Register with each competent authority through its national mechanism — contact details, IP ranges, sector and member states served (Article 3(4))
  • Submit the Article 27 registry details — main establishment or EU representative, member states served and IP ranges, for ENISA’s registry
  • File the authority’s confirmation or reference number — with a record of what was submitted and when
  • Set a trigger for changes to registered details — the Directive allows two weeks under Article 3(4) and three months under Article 27(3); national law may differ
Phase 3

Phase 3: Management Body Approval & Training

Article 20 makes the management body approve the measures, oversee their implementation and answer for infringements.

  • Present the Article 21 measures to the management body for approval — the risk assessment, treatment plan and policies
  • Record the approval with its date, attendees and document versions — tying the decision to exactly what was approved
  • Agree how the body will oversee implementation — reporting cadence, metrics and presenter
  • Complete cybersecurity training for every management body member — mandatory under Article 20(2); national law sets the detail
Phase 4

Phase 4: Article 21 Risk-Management Measures

Ten minimum measures, points (a) to (j), on an all-hazards basis. The last task appears only for providers covered by Implementing Regulation (EU) 2024/2690.

  • Run and document the cybersecurity risk assessment — point (a), with a risk treatment plan
  • Test incident handling, backups, disaster recovery and crisis management — points (b) and (c), each with a dated test
  • Evidence secure acquisition, development and vulnerability handling — point (e), including vulnerability disclosure
  • Confirm cyber hygiene, cryptography, HR security, access control and assets — points (g) to (i), including training and an asset inventory
  • Confirm MFA and secured communications where appropriate — point (j), including emergency communications
  • Assess whether the measures work — point (f): test controls, not just policies
  • Map controls to the Annex of Implementing Regulation (EU) 2024/2690 — the security policy and risk treatment plan are reviewed at least annually
Phase 5

Phase 5: Supply Chain Security

  • List the direct suppliers and service providers that affect your systems — point (d), including managed and cloud services
  • Assess each supplier’s vulnerabilities and security practices — product quality and secure development (Article 21(3))
  • Check the EU coordinated supply chain risk assessments — Article 21(3) requires their results to be considered
  • Add security terms to supplier contracts — incident notice, audit rights, vulnerability handling, subcontracting, exit
  • Send critical suppliers through a full vendor risk assessment — with a residual risk rating and an approver
Phase 6

Phase 6: Incident Reporting Readiness

  • Define what a significant incident means for the entity — severe operational disruption or financial loss, or considerable damage to others (Article 23(3))
  • Record the reporting route and test portal access — CSIRT or authority, form, named reporters and deputies
  • Assign owners for the 24-hour early warning and 72-hour notification — both run from becoming aware, nights and weekends included
  • Prepare templates for the final and progress reports — due one month after the notification
  • Set the rule for informing recipients of the service — who is told, by whom, and what they can do (Article 23(1) and (2))
  • Link the process to GDPR breach notification — personal data may also need a GDPR Article 33 report within 72 hours
  • Rehearse the reporting chain in a tabletop exercise — timing each stage against the deadlines
Phase 7

Phase 7: Annual Review & Supervision Readiness

The audit and accountability tasks appear only when the entity is classified as essential. Important entities are supervised after the event under Article 33.

  • Track a corrective measure for every gap found — without undue delay, as Article 21(4) requires
  • Assemble the evidence pack an authority would request — policies, audit results and underlying evidence (Articles 32 and 33)
  • Prepare for regular and targeted security audits — Article 32(2)(b); the entity usually pays for a targeted audit by an independent body
  • Name the individuals accountable for compliance — Article 32(6) requires that they can be held liable
  • Re-check classification, registration and national law — size, services, countries and laws change
  • Present the annual review to the management body for re-approval — closing the Article 20 loop

NIS2 Obligations and Where the Checklist Evidences Them

The table maps the Directive’s core obligations to evidence and to the phase that produces it. National laws decide the detail, so treat it as a starting point, not legal advice.

Obligation Evidence Evidenced in
Registration (Articles 3(4) and 27)Classification analysis, submission receipt, change logPhases 1 and 2
Management body approval, oversight and training (Article 20)Dated approval, oversight reports, training recordsPhases 3 and 7
21(2)(a) Risk analysis and information system security policiesRisk assessment, treatment plan, security policyPhase 4
21(2)(b) Incident handlingResponse procedure and exercise recordsPhases 4 and 6
21(2)(c) Business continuity, backup, disaster recovery, crisis managementPlans, restore tests, lessons learntPhase 4
21(2)(d) Supply chain securitySupplier list, assessments, contract termsPhase 5
21(2)(e) Secure acquisition, development and vulnerability handlingSecure development rules, vulnerability recordsPhase 4
21(2)(f) Assessing effectivenessControl tests or internal audit resultsPhases 4 and 7
21(2)(g)–(j) Cyber hygiene, training, cryptography, HR security, access control, assets, MFATraining records, key management, access reviews, asset inventory, MFA coveragePhase 4
Corrective measures (Article 21(4))Gap tracker with owners and datesPhase 7
Incident reporting (Article 23)Significance criteria, routes, templates, exercise resultsPhase 6

Article 23 sets four reporting stages for a significant incident.

Within 24 hours of becoming aware

Early warning

Whether the incident is suspected to be malicious and could have cross-border impact. Trust service providers file the full notification within 24 hours when trust services are hit.

Within 72 hours of becoming aware

Incident notification

An initial assessment of severity and impact, with indicators of compromise where available.

On request

Intermediate report

Status updates when the CSIRT or authority asks.

One month after the notification

Final report

Description, likely root cause, mitigation and cross-border impact. If the incident is still ongoing, a progress report instead, then the final report within one month of handling it.

Two proposals would change this; neither is adopted. The Digital Omnibus, proposed in November 2025, would route Article 23 reports through a single ENISA entry point, keeping the stages and deadlines. A January 2026 proposal to amend NIS2 would add a small mid-cap category treated as important entities, ask for ransomware details in reports and limit national add-ons where EU implementing rules exist. At the time of review both were still before European Parliament committees.

Why Run Your NIS2 Programme in CheckFlow?

1

An approval the board can be held to

Article 20 approval runs as a CheckFlow approval, recording who approved, when, and which policy versions. The activity trail covers every later step, and template versioning ties each year to the checklist it used.

2

Reporting deadlines with names on them

Run a separate incident reporting checklist, started by hand or from your alerting through the REST API or Zapier. Dynamic due dates set the 24-hour, 72-hour and one-month steps, and group assignment means the early warning still has an owner at 3am.

3

One programme across several countries

A data set holds each country’s law, authority, CSIRT and registration reference and fills the Phase 1 and 2 tasks. Conditional logic shows the registry and essential entity tasks only where they apply, and a recurring schedule starts the annual review.

CheckFlow is not a GRC platform, a security monitoring tool or a national reporting portal. Reports still go to your CSIRT or authority through their channel; CheckFlow makes sure the right person files each one on time. CheckFlow’s compliance checklist software shows how the same schedules, approvals and audit trail work across your other frameworks.

For the Phase 5 suppliers that matter most, the Vendor Risk Assessment Checklist runs the full due diligence. Many teams use NIST CSF 2.0 as the control framework behind their Article 21 measures, and the NIST CSF 2.0 Checklist runs that assessment. When an incident starts, the Incident Management Checklist handles the response while this page’s Phase 6 covers the regulatory reports.

Frequently Asked Questions

Does NIS2 apply to my company?

+

Two tests decide it: your entity type appears in Annex I or II, and you are at least medium-sized (50 or more staff, or turnover and balance sheet both above €10 million). Trust service providers, DNS service providers, TLD registries and domain registration services are covered at any size, and national law can designate smaller entities.

What is the difference between essential and important entities under NIS2?

+

Both have the same duties under Articles 20, 21 and 23. Essential entities are supervised proactively and face higher maximum fines; important entities are supervised after the event. For essential entities, if earlier enforcement fails, Article 32(5) also allows temporary suspension of a certification or authorisation, and a temporary ban on a chief executive or legal representative exercising managerial functions.

What are the NIS2 incident reporting deadlines?

+

An early warning within 24 hours of becoming aware of a significant incident, a notification within 72 hours, an intermediate report on request and a final report within one month of the notification. Providers covered by Implementing Regulation (EU) 2024/2690 have set criteria for what counts as significant, such as a direct financial loss above €500,000 or 5% of annual turnover, whichever is lower.

What are the fines for non-compliance with NIS2?

+

For breaches of Article 21 or 23, national law must allow fines up to at least €10 million or 2% of total worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever is higher in each case. National caps may be higher, and management body members can be held liable under Article 20.

Has every EU country transposed NIS2?

+

Not at the time of review. In July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for not notifying full transposition. Germany has applied its law since 6 December 2025, and the Netherlands since 15 August 2026. Where a law is pending, work to the Directive and the published draft, and check the national authority for the current position.

Does NIS2 apply to banks and other financial institutions?

+

For most financial entities, no. Banking is an Annex I sector, but DORA is the sector-specific law for financial entities, and its ICT risk and major incident reporting rules apply instead of NIS2’s. Non-financial companies in the same group may still fall under NIS2.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Every NIS2 Duty Owned, Dated and Ready for the Authority

Free trial — no credit card required.