NIS2 guideNIS2 readiness checklist

A 30-question NIS2 readiness checklist for lean teams.

A readiness checklist should not pretend to certify compliance. Its job is to help teams see what is known, what is missing, who owns the next step, and which gaps need legal, management, customer, or technical attention.

Framework-Pro + IncidentAIUpdated August 2026
Key points

What to remember before you act.

  • Use the checklist to create a gap list and action plan.
  • Assign owners and due dates for every uncertain answer.
  • Separate legal scope questions from practical readiness work.
  • Use evidence to support yes answers.
  • Review the checklist after major business, supplier, or system changes.

Scope and governance

  • 1. Which legal entities, services, and countries are included in the review?
  • 2. Which NIS2 sectors or national categories might apply?
  • 3. Have size criteria, exceptions, and group structure been checked?
  • 4. Who owns the NIS2 scope decision and review date?
  • 5. Who owns cybersecurity risk at management level?
  • 6. Is there a risk register or equivalent decision record?

Policies and controls

  • 7. Is there an approved information security policy?
  • 8. Are access control, MFA, privileged access, and access reviews defined?
  • 9. Is asset ownership and inventory maintained?
  • 10. Are backup, recovery, and continuity expectations written down?
  • 11. Is supplier security reviewed before and during vendor use?
  • 12. Is vulnerability management tracked with owners and dates?
  • 13. Are security awareness and cyber hygiene expectations defined?
  • 14. Can each policy be linked to a control, owner, and evidence source?

Incident response and reporting

  • 15. Are incident intake channels defined?
  • 16. Does every incident record capture detection time, source, impact, owner, evidence, and actions?
  • 17. Is there a severity and significance assessment process?
  • 18. Who decides whether NIS2, GDPR, customer, supplier, or contractual notification may be required?
  • 19. Is the 24-hour early-warning workflow known where NIS2 applies?
  • 20. Are timelines, decisions, and RCA notes preserved?
  • 21. Are post-incident reviews and corrective actions tracked?

Evidence, suppliers, and management

  • 22. Is there an evidence index for key controls?
  • 23. Can MFA, access reviews, backups, training, supplier reviews, and vulnerability handling be evidenced?
  • 24. Are critical suppliers and subprocessors listed?
  • 25. Are supplier incident notification commitments clear?
  • 26. Does management receive concise readiness and incident updates?
  • 27. Are risk acceptances and major decisions recorded?
  • 28. Are AI tools used with clear data handling and human review rules?
  • 29. Is there a prioritized 30-day or 90-day action plan?
  • 30. Is the checklist reviewed when services, customers, systems, or guidance change?

Turn answers into action

Use four answer types: yes with evidence, partly implemented, planned with date, or unknown. Unknown is better than pretending. It creates a clear next step.

The useful output is a short gap register: question, current answer, evidence, owner, risk, next action, and due date.

This checklist is a readiness tool, not legal advice or certification evidence by itself. Adapt it to your national guidance, sector, contracts, and internal governance.

Quick FAQ

What is a NIS2 readiness checklist?

It is a structured set of questions that helps an organization identify scope, security, incident, supplier, evidence, and management gaps before customer or regulatory pressure.

Does completing a checklist prove NIS2 compliance?

No. It helps identify readiness and gaps. Compliance depends on facts, national law, implementation, evidence, and accountable decisions.

Who should answer the checklist?

Security, IT, management, legal, privacy, procurement, service owners, and supplier owners may all need to contribute.

What should happen after the checklist?

Create a prioritized action plan with owners, due dates, evidence expectations, and management review.

Official sources used

These pages were used for factual grounding. aneo summarizes them in original wording and does not provide legal advice.

Knowledge Base

Continue your NIS2 readiness work.

Use the related resources below to turn this NIS2 question into a practical next step for your team.

Browse the full Knowledge Base
Readiness planning

Turn checklist answers into policies, controls, and incident workflows.

Use Framework-Pro for readiness documents and IncidentAI for structured incident records when response evidence matters.