NIS2 Compliance Checklist
Checklist to find out if your company is subject to the NIS2 Directive, and what cybersecurity measures it requires if so — 40 controls organized by article.
What's included
- Excel with 40 controls organized into 6 sections (applicability, governance, risk management, Art. 21 technical measures, Art. 23 incident notification, supply chain)
- PDF interpretation guide by section
- Legal Notice
Why this document exists
The NIS2 Directive (EU 2022/2555) dramatically widens which companies count as "essential" or "important" for cybersecurity — far more than under the original NIS directive. The first section of this checklist answers the question most companies get wrong: whether they're actually in scope. From there, it organizes governance, risk management, and incident notification obligations into a single working document.
Frequently asked questions
Is my company subject to NIS2?
It depends on your sector and size. NIS2 applies to essential and important entities across 18 sectors (energy, health, digital, public administration, etc.) that exceed medium-enterprise thresholds. The checklist helps you determine this in the first sections.
Does this replace legal advice?
No. It's a working template that organizes and speeds up self-assessment, but it doesn't constitute legal advice or guarantee compliance with Directive (EU) 2022/2555 — see the included Legal Notice.
What format is it delivered in?
Excel with the controls and PDF guide, plus the Legal Notice, as an instant download after purchase.