
NIS2 does not hand you a list of documents to file. It asks for appropriate and proportionate measures (Article 21) and holds management responsible for them (Article 20). When an authority, an auditor or a customer asks how you meet NIS2, the answer is evidence: records that show a measure exists and actually works.
This checklist follows the ten areas of Article 21(2). Use it to see what you already have and what is missing. Keep it proportionate: a 60-person company does not need the paperwork of a bank.
(a) Risk analysis and information system security policies
- An approved information security policy, with the date and who approved it.
- A risk register: risks, owners, ratings and the treatment you chose.
- Proof of review: when the risks were last looked at and what changed.
(b) Incident handling
- An incident response procedure with roles and contacts.
- An incident log with times: when you became aware, what you did, when you reported.
- Lessons learned after significant incidents.
(c) Business continuity and crisis management
- Business continuity and disaster recovery plans with recovery time objectives.
- Backup records and the result of the last restore test.
- Results of continuity exercises and what you improved.
(d) Supply chain security
- A list of your ICT suppliers with how critical each one is.
- Security questions or assessments for the critical ones, and your decision.
- Security clauses in contracts, and the date of the next review.
(e) Security in acquisition, development and maintenance
- Vulnerability handling: how you find, rate and fix weaknesses, with due dates.
- Records of patches and changes on important systems.
(f) Assessing the effectiveness of measures
- Internal audits or reviews, their findings and corrective actions.
- Key indicators you track, even simple ones, such as patch delays or open findings.
(g) Basic cyber hygiene and training
- Training plans and records of who completed which course, including management.
- Awareness activities, for example phishing exercises.
(h) Cryptography and encryption
- A short policy on where encryption is used: devices, backups, data in transit.
- Key management responsibilities.
(i) Human resources security, access control and asset management
- An asset inventory with owners.
- Joiner, mover and leaver steps, and periodic access reviews with decisions.
(j) Multi-factor authentication and secured communications
- Where multi-factor authentication is required and proof that it is switched on.
- Secured emergency communication: how you reach each other when normal channels fail.
Keep evidence alive, not archived
The most common gap is not missing documents but outdated ones: a policy nobody reviewed, a backup test from two years ago. Give each piece of evidence an owner and a review or expiry date, and link it to the measure it supports. Then a gap shows up before an auditor finds it.
CloudSignLab keeps evidence linked to each control, with expiry reminders and a readiness score per NIS2 measure. See how it works on the NIS2 page, or start with the free NIS2 check to find out whether NIS2 applies to you.
Start free

