Back to blog
Checklists

NIS2 readiness checklist

Ten required measures, incident reporting inside 24 hours, and personal liability for management. A practical checklist for essential and important entities and their suppliers.
GRC Copilot Team
NIS2 readiness checklist

NIS2 widened the population of regulated organisations dramatically and attached management accountability to compliance. That combination — more entities, personal consequences — is why it is being taken more seriously than its predecessor.

1. Determine your status

  • Are you an essential or important entity? Sector and size drive it, and the distinction affects supervision intensity rather than the measures themselves.
  • Confirm which member state supervises you, and whether you operate in several.
  • Register with the competent authority — a duty that is easy to overlook and independently enforceable.
  • If you are not in scope directly, check whether customers in scope will push obligations to you contractually. This is how most suppliers first encounter it.

2. The ten minimum measures

Evidence each of these, proportionate to your risk:

  • Risk analysis and information system security policies.
  • Incident handling.
  • Business continuity, backup management and crisis management.
  • Supply chain security, including relationships with direct suppliers.
  • Security in acquisition, development and maintenance, including vulnerability handling and disclosure.
  • Policies to assess the effectiveness of the measures — the one most often missing, because it requires measurement rather than implementation.
  • Basic cyber hygiene and security training.
  • Cryptography and encryption policy.
  • Human resources security, access control and asset management.
  • Multi-factor authentication, secured communications and secured emergency communications.

Map NIS2 to controls you already have

GRC Copilot maps NIS2 measures onto your existing control set and tracks the evidence for each.

3. Incident reporting — the clocks

  • Early warning within 24 hours of becoming aware of a significant incident. This is the obligation that breaks unprepared teams: it means someone must be able to reach a judgement and file, out of hours.
  • Incident notification within 72 hours, with an initial assessment.
  • Final report within one month.
  • Recipient notification where the incident may adversely affect service recipients.
  • Defined criteria for "significant", agreed in advance so the decision is not improvised.
Note the 24-hour early warning is a lower bar than a full report — it is a heads-up, not an analysis. Teams that treat it as requiring a complete picture miss it. Build the process to file early with partial information and supplement.

4. Management accountability

  • Management bodies must approve the cybersecurity risk measures and oversee their implementation — evidenced in minutes, not asserted.
  • Management must undergo training, and this is checkable.
  • Members can be held personally liable for breaches of these duties, and authorities can temporarily prohibit individuals from management functions in serious cases.

Practically: get the measures formally tabled and approved at board level, minute it, and run the training. These are cheap actions that discharge a duty carrying real personal exposure.

5. Supply chain

  • Assess security of direct suppliers and service providers.
  • Consider suppliers' own secure development practices and overall security posture.
  • Reflect requirements in contracts, with flow-down.

6. Evidence to hold

Approved policies with board minutes; risk assessment; asset inventory; incident register with reporting timestamps; continuity and backup testing evidence; training records including management; supplier assessments and contract clauses; and evidence that you measure effectiveness.

Frequently asked questions

Does NIS2 apply to us if we are outside the EU?

It can where you provide in-scope services in the EU, and entities may need a representative. Contractual flow-down from EU customers reaches further still.

Is ISO 27001 enough?

It covers most of the substance. Registration, reporting clocks, management approval evidence and effectiveness measurement are the gaps.

What is a significant incident?

Broadly, one causing severe operational disruption or financial loss, or affecting others through considerable damage. Define your interpretation in advance and record it.

How does it differ from DORA?

DORA is financial-sector specific and more prescriptive on third parties and testing. Where both apply, DORA generally takes precedence for those entities.

Key takeaways

  • Registration is a separate, independently enforceable duty.
  • The 24-hour early warning is a heads-up — file early and supplement.
  • Board approval and training discharge a duty carrying personal liability.
  • Measuring effectiveness is the most commonly missing measure.
#nis2 #checklist #readiness #essential-entities #management-liability #incident-reporting