NIS2 Scoring
EUEuropean Union · English
a service bySightadel

NIS2 guide

NIS2 checklist with 34 checkpoints

The same questions as in the NIS2 scoring, here as a list to tick off and print. If you can answer every item with “yes, documented”, you have the core NIS2 duties under control.

Last updated: October 2026 · Legal basis: Directive (EU) 2022/2555 (NIS2); details depend on national law

Go through the items with the person responsible for information security in your organisation. Only tick what is implemented and evidenced: an auditor or supervisory authority asks for proof, not intentions. Each area shows the relevant article of the directive. Check your national law for the exact wording that applies to you.

Tip: The scoring weights the same items and sends you an action plan sorted by urgency as a PDF.

Management body Art. 20 NIS2

  1. Has the management body formally approved the cybersecurity risk-management measures (a dated resolution)?
  2. Does the management body oversee implementation regularly, for example through a standing report?
  3. Do the members of the management body attend information security training regularly?
    Article 20(2) NIS2 requires members of management bodies to follow training.
  4. Is there a named person responsible for information security, with a clear mandate and budget?

More in the guide

Registration and incident reporting Art. 3(4), 23, 27 NIS2

  1. Is your organisation registered with the competent national authority (or have you confirmed that no registration is required)?
    Member States had to draw up lists of entities by 17 April 2025 (Art. 3(3)). Portal and deadline depend on national law.
  2. Do you have a defined process for reporting significant incidents to the CSIRT or competent authority on time?
    Early warning within 24 hours, incident notification within 72 hours, final report one month later (Art. 23(4)).
  3. Have you defined when an incident counts as “significant”?
  4. Have you set out how you inform the recipients of your services about significant incidents?

More in the guide

Risk analysis and security policies Art. 21(2)(a) NIS2

  1. Is there a documented risk analysis for your information systems that is updated regularly?
  2. Is there an information security policy approved by the management body?
  3. Do you run an information security management system (ISMS), for example based on ISO/IEC 27001?

Incident handling Art. 21(2)(b) NIS2

  1. Is there a described process for detecting, assessing and handling security incidents?
  2. Are security-relevant events logged and analysed (for example logs, alerts)?
  3. Have you rehearsed a serious incident in the last 12 months (for example a tabletop exercise)?

Business continuity and crisis management Art. 21(2)(c) NIS2

  1. Are backups taken regularly, stored separately, and is restoration tested?
  2. Is there a contingency plan that sets out how critical processes continue or are restored after an outage?
  3. Is a crisis team defined, with roles and contact details?

Supply chain security Art. 21(2)(d) NIS2

  1. Do you know which service providers and suppliers matter for your security (a register)?
  2. Do contracts with key service providers include security requirements (for example incident notification, audit rights)?
  3. Do you assess the security of key suppliers regularly (questionnaire, certificate, audit)?

Security in acquisition, development and maintenance Art. 21(2)(e) NIS2

  1. Are security updates for systems and software applied promptly and traceably?
  2. Are your systems checked regularly for vulnerabilities (scans, penetration tests)?
  3. Are there security requirements for buying or developing new systems?

Effectiveness of measures Art. 21(2)(f) NIS2

  1. Is the effectiveness of the security measures reviewed regularly (internal audits, metrics)?
  2. Are audit findings tracked until they are resolved?

Cyber hygiene and training Art. 21(2)(g) NIS2

  1. Are all staff trained in information security regularly (for example phishing)?
  2. Are there binding basic rules for using IT securely (passwords, devices, email)?

Cryptography and encryption Art. 21(2)(h) NIS2

  1. Is data on laptops, mobile devices and storage media encrypted?
  2. Are there rules for encryption and key management (for example for transmission and backups)?

HR security, access control and assets Art. 21(2)(i) NIS2

  1. Are access rights granted on the principle of least privilege and reviewed regularly?
  2. Is access granted and removed in a controlled way when staff join, move or leave?
  3. Is there an up-to-date inventory of your IT systems and applications?

Authentication and secure communication Art. 21(2)(j) NIS2

  1. Is multi-factor authentication in place for remote access, cloud services and administrator accounts?
  2. Is there a secured communication channel for emergencies when email and the phone system are down?

How to use the checklist

Start with the items that have direct legal consequences: registration, the reporting chain and the management body’s approval. Then tackle measures with a big effect for moderate effort, such as multi-factor authentication and tested backups. Plan everything else over the next six to twelve months. What lies behind each measure is explained on the page about the ten measures of Article 21. Which national law applies to you is shown in the transposition overview.

Frequently asked questions

Is this checklist complete?

It covers Articles 20, 21 and 23 and the registration duty at the level a management body needs to know. Implementing each measure in detail takes further checkpoints, depending on your size, risk and national law.

Does the checklist replace an audit?

No. It shows where you stand. Whether measures are effective is checked by an internal or external audit.

Is the checklist useful for suppliers that are not in scope?

Yes, as a guide. Customers in scope ask about the same topics in supplier assessments, because they have to address supply chain security under Article 21(2)(d).