Understanding the NIS2 requirements is the foundation of any compliance programme under the EU’s expanded cybersecurity directive. NIS2 sets out both the security measures you must implement and the incident-reporting obligations you must meet — all backed by documentation. This guide breaks down the requirements and gives you a practical checklist of what to have in place.

For the full context, see our complete NIS2 Directive guide.
The core NIS2 requirements
At its heart, NIS2 requires in-scope entities to take appropriate and proportionate technical, operational, and organizational measures to manage cybersecurity risk, and to report significant incidents on a tight timeline. Senior management must approve and oversee these measures. The directive takes an all-hazards, risk-based approach, so the exact depth scales with your size and risk profile — but the categories of requirement are consistent.
NIS2 security measures checklist
- Policies on risk analysis and information system security.
- Incident handling procedures.
- Business continuity, backup, and crisis management plans.
- Supply-chain security, including supplier assessments.
- Security in the acquisition, development, and maintenance of systems.
- Vulnerability handling and disclosure processes.
- Policies to assess the effectiveness of measures.
- Basic cyber hygiene and security training.
- Cryptography and encryption policies.
- Access control, asset management, and multi-factor authentication.
NIS2 incident reporting requirements
For a significant incident, NIS2 requires an early warning within 24 hours, a full notification within 72 hours, and a final report within one month. You need a documented process that detects, assesses, classifies, and reports within these deadlines — and captures lessons afterwards. Because the timelines are short, the workflow and templates must exist before an incident, not be improvised during one.
Governance and documentation you must keep
NIS2 makes management bodies accountable, so your evidence file should demonstrate board approval and oversight of the cybersecurity measures, along with management training. Overall, expect to document: your security policies and risk assessment, business continuity and incident-response plans, supply-chain security records, access-control and cryptography policies, and governance records showing senior-management involvement. If it is not documented, a regulator will treat it as absent — which is exactly where a mapped template set saves time.
Every NIS2 requirement, documented.
Our NIS2 Toolkit delivers the security policies, incident-response procedures, supply-chain controls, and governance records NIS2 demands — mapped to the directive and editable in Word and Excel.
Frequently asked questions
What are the main NIS2 requirements?
Risk-based security measures — covering risk analysis, incident handling, business continuity, supply-chain security, cryptography, access control, and MFA — plus staged incident reporting and documented management accountability.
What must be documented for NIS2?
Security policies and risk assessment, business continuity and incident-response plans, supply-chain security records, access-control and cryptography policies, and governance records showing senior-management oversight.
How quickly must incidents be reported under NIS2?
An early warning within 24 hours, a full notification within 72 hours, and a final report within one month of a significant incident.