Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIS2 requirements checklist covering security measures, incident reporting and documentation

NIS2 Requirements & Documentation Checklist

Understanding the NIS2 requirements is the foundation of any compliance programme under the EU’s expanded cybersecurity directive. NIS2 sets out both the security measures you must implement and the incident-reporting obligations you must meet — all backed by documentation. This guide breaks down the requirements and gives you a practical checklist of what to have in place.

NIS2 requirements checklist covering security measures, incident reporting and documentation

For the full context, see our complete NIS2 Directive guide.

The core NIS2 requirements

At its heart, NIS2 requires in-scope entities to take appropriate and proportionate technical, operational, and organizational measures to manage cybersecurity risk, and to report significant incidents on a tight timeline. Senior management must approve and oversee these measures. The directive takes an all-hazards, risk-based approach, so the exact depth scales with your size and risk profile — but the categories of requirement are consistent.

NIS2 security measures checklist

  • Policies on risk analysis and information system security.
  • Incident handling procedures.
  • Business continuity, backup, and crisis management plans.
  • Supply-chain security, including supplier assessments.
  • Security in the acquisition, development, and maintenance of systems.
  • Vulnerability handling and disclosure processes.
  • Policies to assess the effectiveness of measures.
  • Basic cyber hygiene and security training.
  • Cryptography and encryption policies.
  • Access control, asset management, and multi-factor authentication.

NIS2 incident reporting requirements

For a significant incident, NIS2 requires an early warning within 24 hours, a full notification within 72 hours, and a final report within one month. You need a documented process that detects, assesses, classifies, and reports within these deadlines — and captures lessons afterwards. Because the timelines are short, the workflow and templates must exist before an incident, not be improvised during one.

Governance and documentation you must keep

NIS2 makes management bodies accountable, so your evidence file should demonstrate board approval and oversight of the cybersecurity measures, along with management training. Overall, expect to document: your security policies and risk assessment, business continuity and incident-response plans, supply-chain security records, access-control and cryptography policies, and governance records showing senior-management involvement. If it is not documented, a regulator will treat it as absent — which is exactly where a mapped template set saves time.

Every NIS2 requirement, documented.

Our NIS2 Toolkit delivers the security policies, incident-response procedures, supply-chain controls, and governance records NIS2 demands — mapped to the directive and editable in Word and Excel.

Get the NIS2 Toolkit →

Frequently asked questions

What are the main NIS2 requirements?

Risk-based security measures — covering risk analysis, incident handling, business continuity, supply-chain security, cryptography, access control, and MFA — plus staged incident reporting and documented management accountability.

What must be documented for NIS2?

Security policies and risk assessment, business continuity and incident-response plans, supply-chain security records, access-control and cryptography policies, and governance records showing senior-management oversight.

How quickly must incidents be reported under NIS2?

An early warning within 24 hours, a full notification within 72 hours, and a final report within one month of a significant incident.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.