Skip to content

NIS2

NIS2 Directive Cybersecurity Readiness Checklist

An Article 21-oriented checklist for governance, risk, incident reporting, and supply-chain measures under NIS2.

Estimated time
4–12 Months
Audience
Essential and Important Entities in the EU
Last updated

Operational reference for NIS2 preparation. National transposition and competent authorities determine obligations and supervision.

Progress0% Completed

Progress is saved in this browser only. Nothing is sent to a server.

Phase 1: Entity Classification

Phase 2: Article 21 Measures

Phase 3: Reporting

Phase 4: Assurance

FAQ

Does ISO 27001 certify NIS2?+

No, but an ISMS covers many Article 21 measures. Reporting and governance duties remain legal.

Who enforces NIS2?+

National competent authorities in each Member State.

Are SaaS companies in scope?+

Some digital providers and managed services can be. Classification is fact-specific under national lists.

What are the reporting deadlines?+

NIS2 uses early warning and follow-up timelines (including 24 hours for significant incidents). Confirm the national transposition.

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer