IT security intelligence. Since 2006.Cloudflare services ↗
TRUST-IT / Practical guide

NIS2 readiness: from requirements to an evidence plan

Readiness is a coordinated organisational effort. Start by confirming scope, then connect risk decisions, operational controls, and evidence to named owners.

Reviewing risk assessments and security controls

Confirm the scope before building a checklist

NIS2 addresses cybersecurity across specified sectors and entity categories. Whether an organisation is in scope depends on its activities and other criteria, including national implementation. Confirm applicability with appropriate advisers and the relevant authority. A generic online checklist cannot decide this for your organisation.

Map services, dependencies, and responsibilities

Identify the services your organisation delivers, the systems that support them, and the suppliers you depend on. Record control owners and escalation paths. This creates a basis for discussing risk, incident handling, continuity, access, and supplier security without reducing the exercise to document collection.

Collect evidence of operation

A written policy and an operating control are different things. Evidence can include access reviews, training records, incident exercises, tested recovery procedures, supplier assessments, and management decisions. Agree how each item will be maintained and who will review it.

Prioritise and revisit

Turn gaps into actions with owners, dependencies, and review dates. Focus first on risks to critical services and controls that enable other improvements. Reassess after significant changes. This guide describes a readiness approach, not a legal determination, deadline schedule, or assurance of compliance.

Further reading

Put the guidance to work

Connect risk management, GDPR, NIS2, DORA, and ISO 27001 preparation with practical CISO and DPO support.

Governance & compliance

What’s your next
technology challenge?

Talk to our team