Free Download

NIS2 Directive
Readiness Checklist

62 check items covering every NIS2 obligation: governance (Article 20), all 10 mandatory security measures (Article 21), and incident reporting timelines (Article 23). Open in any browser, mark status, add evidence notes, and print as PDF. No sign-up needed.

Built by CISM-certified consultants · Based on EU Directive 2022/2555 · 20+ years experience
Cyvra & NIS2

We take businesses from checklist to compliant

The checklist shows where your gaps are. Cyvra builds the remediation plan and works alongside your team to close them before enforcement catches up.

Gap Analysis
We assess your current controls against every NIS2 Article 21 measure, identify gaps by severity, and give you a prioritised plan with owners and target dates.
Implementation Support
Our consultants build the policies, incident response procedures, supply chain controls, and technical measures NIS2 requires, without drowning your team in documentation.
Incident Reporting Readiness
We build your 24-hour, 72-hour, and 1-month reporting workflows and test them before an incident happens. When regulators ask, you will have the records to show.
Netherlands-based, delivery in English and Dutch
CISM-certified lead consultants with 20+ years of hands-on security experience
We implement alongside your team, not just produce advisory reports
Clients across financial services, healthcare, and hospitality
What's Inside

Full NIS2 obligation coverage

Every governance, security, and reporting obligation from EU Directive 2022/2555. Nothing omitted or rolled up.

Art. 20
Governance & Management Body Accountability
Board approval of cybersecurity measures, active oversight, management training, designated CISO, personal liability framework
5 checks
Art. 2–6
Entity Scope & Classification
Essential vs Important entity determination, Annex I/II sector identification, national competent authority registration, cross-border obligations
4 checks
Art. 23
Incident Reporting Obligations
Significant incident criteria, 24-hour early warning, 72-hour full notification, intermediate reports, 1-month final report, customer notification
6 checks
Art. 21(a–e)
Risk, Incidents, BCP, Supply Chain & Network
Risk assessment and IS policy, incident handling and playbooks, backup and disaster recovery, supply chain security, vulnerability management and secure development
27 checks
Art. 21(f–j)
Effectiveness, Training, Crypto, HR/Access & MFA
Security KPIs and audits, cyber hygiene and awareness training, cryptography and encryption policy, HR security and identity lifecycle, MFA and secure communications
21 checks
How to Use

Up and running in minutes

No software to install. Works in Chrome, Edge, or Firefox.

1
Download and open
Save the HTML file to your computer and open it in any modern browser. Nothing to install or configure.
2
Mark each control
Click any status badge to cycle through YES / PARTIAL / NO / N/A. The compliance score updates live. Click in the Evidence or Notes column to type directly.
3
Save as PDF
Use Ctrl+P to print or export as PDF. The layout is optimised across six pages ready to share with your team or auditor.
Commonly Asked Questions

NIS2: common questions

Who does NIS2 apply to?
NIS2 applies to medium and large organisations in 18 critical sectors including energy, transport, banking, healthcare, digital infrastructure, and managed IT services. Essential Entities (Annex I) face the strictest obligations and supervisory scrutiny. Important Entities (Annex II) have the same technical requirements but lighter supervisory conditions. If you operate in a covered sector and exceed 50 employees or €10 million in turnover, you are likely in scope.
What are the penalties for non-compliance?
For Essential Entities, maximum fines reach €10 million or 2% of global annual turnover, whichever is higher. Important Entities face up to €7 million or 1.4% of global turnover. NIS2 also introduces personal liability for management bodies, meaning board members can be held accountable for systematic failures to implement required security measures.
Is NIS2 in force in the Netherlands and UK?
The Netherlands transposed NIS2 through the Cyberbeveiligingswet, which came into force in 2025. The Dutch NCSC and sector-specific authorities act as competent authorities. The UK left the EU before NIS2 and operates under its own Network and Information Systems (NIS) Regulations. UK organisations with EU operations or EU clients may still need to demonstrate NIS2 alignment.
Does ISO 27001 certification cover NIS2?
ISO 27001 and NIS2 overlap significantly in risk management, access control, incident response, and supply chain security. A certified ISMS satisfies a large portion of NIS2 requirements. However, NIS2 adds specific obligations around incident reporting timelines, management body accountability, and sector-specific controls that ISO 27001 does not directly address. Cyvra can map your existing ISMS to the NIS2 gap.

Download the checklist

No email, no sign-up. Download it, use it as many times as you need, and share it with your team. When the results show gaps you need to close, that is where Cyvra comes in.

Download Free Checklist Read our NIS2 compliance guide

EU Directive 2022/2555 • 62 check items • 4 pages • Interactive HTML

This checklist consists of

62
Check Items
10
Security Measures
4
Print Pages

Ready to close your NIS2 gaps?

We handle the gap analysis, policy build, technical controls, and incident reporting setup. You focus on your business.

Get in touch