NIS2 Compliance Checklist: Your Complete Guide
Knowing what NIS2 requires is one thing. Knowing where your organization actually stands is another. With the April 18, 2026 self-assessment deadline approaching for essential entities, this checklist breaks down NIS2 requirements into actionable items you can assess today.
How to Use This Checklist
Go through each category and honestly assess your current state. Mark items as:
1. Governance & Accountability
NIS2 requires management accountability. Leadership must be involved in cybersecurity decisions.
2. Risk Management
You must identify, assess, and manage cybersecurity risks systematically.
3. Incident Handling
NIS2 mandates 24-hour initial notification and structured incident response.
4. Business Continuity
Ensure critical operations can continue during and after security incidents.
5. Supply Chain Security
Your security is only as strong as your weakest supplier.
6. Network & Systems Security
Protect your infrastructure from unauthorized access and attacks.
7. Access Control
Ensure only authorized people access sensitive systems and data.
8. Cryptography
Protect sensitive data with appropriate encryption.
9. Human Resources Security
People are often the weakest link. Address human factors.
10. Asset Management
You can't protect what you don't know you have.
Scoring Your Assessment
After completing the checklist, calculate your readiness:
Next Steps
Based on your assessment:
- 1 Prioritize gaps by risk level and effort
- 2 Create an action plan with deadlines
- 3 Assign owners to each action item
- 4 Track progress weekly
- 5 Re-assess quarterly
Want a Guided Assessment?
Easy Cyber Protection walks you through each checkpoint with clear guidance on what "good" looks like. Get a structured compliance roadmap based on your specific gaps.
Frequently Asked Questions
How often should I use this checklist?
Perform a full assessment at least annually, or after significant changes to your organization, systems, or threat landscape. Quarterly reviews of high-risk areas are recommended.
Do I need all items to be compliant?
Not necessarily. What's required depends on your NIS2 classification (Essential vs Important) and your risk profile. This checklist covers comprehensive requirements - some may not apply to your organization.
What if I'm missing many items?
That's normal when starting out. Focus on high-impact, quick-win items first: incident response plan, MFA, and backup testing. Build from there systematically.
Should I hire a consultant for the assessment?
For initial assessments, doing it internally helps you understand your organization. Consider external help for validation, complex technical areas, or if you lack internal expertise.
How does this relate to CyberFundamentals?
This checklist aligns with NIS2 Article 21 requirements. CyberFundamentals provides the specific controls to implement. Use this checklist to identify gaps, then CyberFundamentals to close them.