Confirm the scope before building a checklist
NIS2 addresses cybersecurity across specified sectors and entity categories. Whether an organisation is in scope depends on its activities and other criteria, including national implementation. Confirm applicability with appropriate advisers and the relevant authority. A generic online checklist cannot decide this for your organisation.
Map services, dependencies, and responsibilities
Identify the services your organisation delivers, the systems that support them, and the suppliers you depend on. Record control owners and escalation paths. This creates a basis for discussing risk, incident handling, continuity, access, and supplier security without reducing the exercise to document collection.
Collect evidence of operation
A written policy and an operating control are different things. Evidence can include access reviews, training records, incident exercises, tested recovery procedures, supplier assessments, and management decisions. Agree how each item will be maintained and who will review it.
Prioritise and revisit
Turn gaps into actions with owners, dependencies, and review dates. Focus first on risks to critical services and controls that enable other improvements. Reassess after significant changes. This guide describes a readiness approach, not a legal determination, deadline schedule, or assurance of compliance.
Further reading
Put the guidance to work
Connect risk management, GDPR, NIS2, DORA, and ISO 27001 preparation with practical CISO and DPO support.
Governance & compliance