---
name: "NIS2 Compliance Checklist — Article 21(2)"
version: "1.0"
updated: "2026-07-16"
source: "https://www.orbiqhq.com/eu-regulations/nis2-compliance-checklist-article-21"
license: "Free to use and adapt within your organisation. Attribution appreciated. Not legal advice."
legal_basis:
  - "https://eur-lex.europa.eu/eli/dir/2022/2555/oj"   # NIS2 — Directive (EU) 2022/2555 (Arts. 20, 21, 23)
---

# NIS2 Compliance Checklist — Article 21(2) (machine-readable template)

Purpose: gap-assess an organisation against all ten cybersecurity risk-management measures
of Article 21(2) of Directive (EU) 2022/2555 (NIS2), using an ISO 27001 ISMS as the baseline.
For each measure the checklist records: what NIS2 requires, what a typical well-implemented
ISMS already delivers, the remaining gap, the recommended action, and a priority. An agent
can run a complete self-assessment from the records below; track `status`, `owner`,
`evidence_ref`, and `target_date` per measure.

Assessment scale for `isms_coverage`:
- `covered` — a well-implemented ISO 27001:2022 ISMS delivers the essential processes and controls.
- `foundation` — governance exists, but NIS2's operational execution goes beyond it; add an operational layer.
- `partial` — partially covered; specific NIS2 expectations exceed typical implementations.

Context: national implementations make these measures binding law (e.g. Germany's NIS2UmsuCG
via § 30 BSIG). Article 20(1) makes the management body accountable for approving and
overseeing the measures; Article 20(2) obliges management to follow cybersecurity training.
Supervisory authorities can request evidence of effectiveness at any time.

---

## Checklist records

| # | measure | nis2_requires | isms_coverage | gap | action | priority |
|---|---|---|---|---|---|---|
| a | Risk analysis and information system security policies | Policies for risk analysis and information system security, with regular review and updates | `covered` | — | Ensure the risk analysis covers NIS2-specific operational aspects: incident reporting, supply chain, proof of effectiveness | low |
| b | Incident handling | Prevention, detection and management of incidents, linked to the Article 23 reporting ladder (24h early warning, 72h notification, 1-month final report) | `foundation` | Operational 24h/72h capability under time pressure — coordination across security, legal, communications and management | Build incident management beyond the plan: tabletop exercises against the 24h deadline; templates for all three reporting stages | **high** |
| c | Business continuity and crisis management | Business continuity, backup management, disaster recovery and crisis management | `covered` | — | Verify BCM plans cover cyber incidents with simultaneous Article 23 reporting obligations | low |
| d | Supply chain security | Supply chain security incl. supplier-specific vulnerabilities and the overall cybersecurity quality of suppliers and service providers | `foundation` | Continuous monitoring instead of annual snapshots; event-triggered re-assessments; retrievable supplier evidence | Build monitoring capability; shift from cyclical to trigger-based assessments; add NIS2 clauses to contracts; make evidence retrievable on demand | **high** |
| e | Security in acquisition, development and maintenance | Security in acquisition, development and maintenance of network and information systems, incl. vulnerability handling and disclosure | `covered` | Check vulnerability disclosure against ENISA implementation guidance | Verify disclosure processes meet NIS2/ENISA expectations, which go beyond typical ISMS implementations | medium |
| f | Effectiveness assessment | Policies and procedures to assess the effectiveness of risk-management measures; authorities can request evidence at any time | `foundation` | Continuous evidence availability, not audit-cycle documentation | Shift evidence management to continuous availability: versioning, validity periods, ownership; answer authority requests within days | **high** |
| g | Cyber hygiene and cybersecurity training | Basic cyber hygiene and cybersecurity training, incl. regular training for the management body itself (Art. 20(2)) | `covered` | Demonstrable executive training participation | Ensure the management body demonstrably participates in training — directly liability-relevant | low |
| h | Cryptography and encryption | Policies and procedures for cryptography and, where appropriate, encryption | `covered` | — | Keep cryptography policies current with the state of the art | low |
| i | Personnel security, access control and asset management | Human resources security, access control policies and asset management | `covered` | — | Confirm MFA coverage where NIS2 requires it (see measure j) | low |
| j | MFA, secured communications and emergency communications | Multi-factor or continuous authentication, secured voice/video/text communications and secured emergency communication systems, where appropriate | `partial` | Secured emergency channels that work independently of the regular (possibly compromised) infrastructure | Audit MFA coverage; establish independent emergency channels; ensure encrypted incident-coordination communication | medium |

Tracking fields per record: `status` (enum: `not_started` / `in_progress` / `done`),
`owner` (text), `evidence_ref` (link or artifact ID), `target_date` (ISO 8601).

## Related deadlines and duties

| Obligation | Deadline / rule | Legal basis |
|---|---|---|
| Early warning to the CSIRT or competent authority | Within 24 hours of becoming aware of a significant incident | Art. 23(4)(a) |
| Incident notification | Within 72 hours of becoming aware | Art. 23(4)(b) |
| Final report | Within one month of the incident notification | Art. 23(4)(d) |
| Management approval and oversight of the measures | Ongoing; personal liability attaches | Art. 20(1) |
| Cybersecurity training for the management body | Regular | Art. 20(2) |

## Interpretation pattern

Governance measures (a, c, e, g, h, i) are largely covered by a well-implemented ISMS.
Operational measures (b, d, f, j) require additions beyond the documentation layer. The three
high-priority gaps — incident handling (b), supply chain security (d), and proof of
effectiveness (f) — should be closed first.

---

Maintained by Orbiq (orbiqhq.com). Full per-measure explanations, ISO 27001 Annex A control
references and sources: https://www.orbiqhq.com/eu-regulations/nis2-compliance-checklist-article-21
