How to Use This Checklist
This 50-point checklist maps to NIS2's Article 21 minimum measures and related obligations. Score each item: 0 (Not started), 1 (In progress), 2 (Implemented). Essential entities face stricter supervision and higher penalties — prioritise accordingly.
Measure 1: Risk Analysis & Information System Security
Policy & Risk Assessment (5 items)
- Information security policy documented, approved by management, and communicated to all staff
- Risk assessment methodology defined and applied to all network and information systems
- Risk treatment plan documented with clear ownership and timelines
- Risk register maintained and reviewed at least quarterly
- Residual risks formally accepted by management body
Measure 2: Incident Handling
Detection, Response & Reporting (5 items)
- Incident detection, analysis, and response procedures documented and tested
- Early warning submitted to CSIRT within 24 hours of becoming aware of significant incident
- Incident notification submitted within 72 hours with initial assessment
- Final report submitted within 1 month with root cause analysis and remediation measures
- Incident response team defined with roles, escalation procedures, and contact details
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Measure 3: Business Continuity & Crisis Management
- Business continuity plan (BCP) documented for all critical services
- Disaster recovery plan with defined RTO/RPO for critical systems
- Backup strategy implemented with regular testing of restore procedures
- Crisis management procedures defined with communication protocols
- BCP tested at least annually through tabletop exercises or full simulations
Measure 4: Supply Chain Security
- Critical suppliers and service providers identified and risk-assessed
- Security requirements included in all supplier contracts
- Supplier security posture monitored through audits, certifications, or assessments
- Incident notification clauses in supplier contracts with defined timelines
- Supplier concentration risk assessed — alternatives identified for critical suppliers
Optimizing Azure DevTest Labs
Enhance performance, security, and cost efficiency of Azure DevTest Labs.
Start on Pluralsight →Measure 5: Security in System Acquisition, Development & Maintenance
- Security requirements defined for all system acquisitions and developments
- Vulnerability handling procedures for all systems (patching, workarounds, mitigations)
- Secure development lifecycle (SDLC) implemented for internally developed software
- Security testing (SAST, DAST, penetration testing) performed before production deployment
- Change management process includes security review for all significant changes
Measure 6: Assessing Cybersecurity Risk Management Effectiveness
- Regular audits of cybersecurity risk management measures (internal or external)
- Key risk indicators (KRIs) and key performance indicators (KPIs) defined and monitored
- Penetration testing performed at least annually on critical systems
- Vulnerability assessments conducted regularly with remediation tracking
- Audit findings tracked to closure with management accountability
EU AI Act Compliance Checklist
40-point checklist covering risk classification, data governance, transparency, and human oversight. Based on the official regulation.
Get Free Checklist →Measure 7: Cyber Hygiene & Training
- Cybersecurity awareness training for all employees (at least annually)
- Management body receives specific cybersecurity training on risks and governance
- Phishing simulation exercises conducted regularly
- Secure configuration baselines defined for all system types
- Patch management process with defined timelines by severity
Measure 8: Cryptography & Encryption
- Encryption policy covers data at rest, in transit, and in use
- TLS 1.2+ enforced on all external and internal communications
- Key management procedures documented (generation, storage, rotation, revocation)
- Cryptographic standards aligned with ENISA/BSI recommendations
- Certificate management automated with monitoring for expiry
Measure 9: HR Security, Access Control & Asset Management
- Access control policy based on least privilege and need-to-know principles
- Privileged access management (PAM) implemented with logging and review
- User access reviews performed at least quarterly for critical systems
- Joiner/mover/leaver process ensures timely access provisioning and revocation
- Asset inventory covers all hardware, software, data, and network components
Measure 10: Multi-Factor Authentication & Secured Communications
- MFA enforced for all remote access, privileged access, and critical systems
- Secured voice, video, and text communications available for sensitive discussions
- Emergency communication systems tested and available during crises
- Single sign-on (SSO) implemented where possible to reduce credential sprawl
- Network segmentation isolates critical systems from general corporate network
Scoring Guide
- 85-100: Strong compliance posture. Focus on continuous improvement and evidence documentation.
- 65-84: Good foundation with gaps. Prioritise Measures 2 (incident handling) and 4 (supply chain) — these are most scrutinised.
- 45-64: Significant gaps. Create a 6-month remediation roadmap. Consider external support.
- 25-44: Major compliance risk. Board-level attention required immediately.
- 0-24: Critical. Engage compliance specialists. Enforcement risk is high.
Management Accountability
NIS2 Article 20: Management bodies of essential and important entities must approve the cybersecurity risk-management measures, oversee their implementation, and can be held personally liable for infringements. They must also undergo cybersecurity training. This isn't optional — it's a legal requirement with personal consequences.
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton
