Skip to main content
← All posts·
Regulatory Compliance

NIS2 Compliance Checklist: 50-Point Guide for Critical Infrastructure [2026]

Complete NIS2 compliance checklist for essential and important entities. 50 action items covering the 10 minimum security measures, incident reporting, management accountability, supply chain security, and cross-border coordination.

Luca Berton13 min read

How to Use This Checklist

This 50-point checklist maps to NIS2's Article 21 minimum measures and related obligations. Score each item: 0 (Not started), 1 (In progress), 2 (Implemented). Essential entities face stricter supervision and higher penalties — prioritise accordingly.

Measure 1: Risk Analysis & Information System Security

Policy & Risk Assessment (5 items)

  1. Information security policy documented, approved by management, and communicated to all staff
  2. Risk assessment methodology defined and applied to all network and information systems
  3. Risk treatment plan documented with clear ownership and timelines
  4. Risk register maintained and reviewed at least quarterly
  5. Residual risks formally accepted by management body

Measure 2: Incident Handling

Detection, Response & Reporting (5 items)

  1. Incident detection, analysis, and response procedures documented and tested
  2. Early warning submitted to CSIRT within 24 hours of becoming aware of significant incident
  3. Incident notification submitted within 72 hours with initial assessment
  4. Final report submitted within 1 month with root cause analysis and remediation measures
  5. Incident response team defined with roles, escalation procedures, and contact details
📘 Book

Kubernetes Recipes

A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).

Watch on Skillshare →

Measure 3: Business Continuity & Crisis Management

  1. Business continuity plan (BCP) documented for all critical services
  2. Disaster recovery plan with defined RTO/RPO for critical systems
  3. Backup strategy implemented with regular testing of restore procedures
  4. Crisis management procedures defined with communication protocols
  5. BCP tested at least annually through tabletop exercises or full simulations

Measure 4: Supply Chain Security

  1. Critical suppliers and service providers identified and risk-assessed
  2. Security requirements included in all supplier contracts
  3. Supplier security posture monitored through audits, certifications, or assessments
  4. Incident notification clauses in supplier contracts with defined timelines
  5. Supplier concentration risk assessed — alternatives identified for critical suppliers
🎓 Course

Optimizing Azure DevTest Labs

Enhance performance, security, and cost efficiency of Azure DevTest Labs.

Start on Pluralsight →

Measure 5: Security in System Acquisition, Development & Maintenance

  1. Security requirements defined for all system acquisitions and developments
  2. Vulnerability handling procedures for all systems (patching, workarounds, mitigations)
  3. Secure development lifecycle (SDLC) implemented for internally developed software
  4. Security testing (SAST, DAST, penetration testing) performed before production deployment
  5. Change management process includes security review for all significant changes

Measure 6: Assessing Cybersecurity Risk Management Effectiveness

  1. Regular audits of cybersecurity risk management measures (internal or external)
  2. Key risk indicators (KRIs) and key performance indicators (KPIs) defined and monitored
  3. Penetration testing performed at least annually on critical systems
  4. Vulnerability assessments conducted regularly with remediation tracking
  5. Audit findings tracked to closure with management accountability
📋 Free Resource

EU AI Act Compliance Checklist

40-point checklist covering risk classification, data governance, transparency, and human oversight. Based on the official regulation.

Get Free Checklist →

Measure 7: Cyber Hygiene & Training

  1. Cybersecurity awareness training for all employees (at least annually)
  2. Management body receives specific cybersecurity training on risks and governance
  3. Phishing simulation exercises conducted regularly
  4. Secure configuration baselines defined for all system types
  5. Patch management process with defined timelines by severity

Measure 8: Cryptography & Encryption

  1. Encryption policy covers data at rest, in transit, and in use
  2. TLS 1.2+ enforced on all external and internal communications
  3. Key management procedures documented (generation, storage, rotation, revocation)
  4. Cryptographic standards aligned with ENISA/BSI recommendations
  5. Certificate management automated with monitoring for expiry

Measure 9: HR Security, Access Control & Asset Management

  1. Access control policy based on least privilege and need-to-know principles
  2. Privileged access management (PAM) implemented with logging and review
  3. User access reviews performed at least quarterly for critical systems
  4. Joiner/mover/leaver process ensures timely access provisioning and revocation
  5. Asset inventory covers all hardware, software, data, and network components

Measure 10: Multi-Factor Authentication & Secured Communications

  1. MFA enforced for all remote access, privileged access, and critical systems
  2. Secured voice, video, and text communications available for sensitive discussions
  3. Emergency communication systems tested and available during crises
  4. Single sign-on (SSO) implemented where possible to reduce credential sprawl
  5. Network segmentation isolates critical systems from general corporate network

Scoring Guide

  • 85-100: Strong compliance posture. Focus on continuous improvement and evidence documentation.
  • 65-84: Good foundation with gaps. Prioritise Measures 2 (incident handling) and 4 (supply chain) — these are most scrutinised.
  • 45-64: Significant gaps. Create a 6-month remediation roadmap. Consider external support.
  • 25-44: Major compliance risk. Board-level attention required immediately.
  • 0-24: Critical. Engage compliance specialists. Enforcement risk is high.

Management Accountability

NIS2 Article 20: Management bodies of essential and important entities must approve the cybersecurity risk-management measures, oversee their implementation, and can be held personally liable for infringements. They must also undergo cybersecurity training. This isn't optional — it's a legal requirement with personal consequences.

NIS2
compliance checklist
critical infrastructure
cybersecurity
supply chain security
incident reporting

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

Or see AI readiness assessment scope & pricing

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →