NIS2
NIS2 Directive Cybersecurity Readiness Checklist
An Article 21-oriented checklist for governance, risk, incident reporting, and supply-chain measures under NIS2.
- Estimated time
- 4–12 Months
- Audience
- Essential and Important Entities in the EU
- Last updated
Operational reference for NIS2 preparation. National transposition and competent authorities determine obligations and supervision.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Entity Classification
Phase 2: Article 21 Measures
Phase 3: Reporting
Phase 4: Assurance
FAQ
Does ISO 27001 certify NIS2?+–
No, but an ISMS covers many Article 21 measures. Reporting and governance duties remain legal.
Who enforces NIS2?+–
National competent authorities in each Member State.
Are SaaS companies in scope?+–
Some digital providers and managed services can be. Classification is fact-specific under national lists.
What are the reporting deadlines?+–
NIS2 uses early warning and follow-up timelines (including 24 hours for significant incidents). Confirm the national transposition.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer