CloudSignLab

BlogNIS2 guides

NIS2 evidence checklist: what to keep for each Article 21 measure

The records and proof that show your NIS2 measures work, measure by measure, and how to keep them current without a pile of folders.

3 min readBy CloudSignLab

NIS2 does not hand you a list of documents to file. It asks for appropriate and proportionate measures (Article 21) and holds management responsible for them (Article 20). When an authority, an auditor or a customer asks how you meet NIS2, the answer is evidence: records that show a measure exists and actually works.

This checklist follows the ten areas of Article 21(2). Use it to see what you already have and what is missing. Keep it proportionate: a 60-person company does not need the paperwork of a bank.

(a) Risk analysis and information system security policies

  • An approved information security policy, with the date and who approved it.
  • A risk register: risks, owners, ratings and the treatment you chose.
  • Proof of review: when the risks were last looked at and what changed.

(b) Incident handling

  • An incident response procedure with roles and contacts.
  • An incident log with times: when you became aware, what you did, when you reported.
  • Lessons learned after significant incidents.

(c) Business continuity and crisis management

  • Business continuity and disaster recovery plans with recovery time objectives.
  • Backup records and the result of the last restore test.
  • Results of continuity exercises and what you improved.

(d) Supply chain security

  • A list of your ICT suppliers with how critical each one is.
  • Security questions or assessments for the critical ones, and your decision.
  • Security clauses in contracts, and the date of the next review.

(e) Security in acquisition, development and maintenance

  • Vulnerability handling: how you find, rate and fix weaknesses, with due dates.
  • Records of patches and changes on important systems.

(f) Assessing the effectiveness of measures

  • Internal audits or reviews, their findings and corrective actions.
  • Key indicators you track, even simple ones, such as patch delays or open findings.

(g) Basic cyber hygiene and training

  • Training plans and records of who completed which course, including management.
  • Awareness activities, for example phishing exercises.

(h) Cryptography and encryption

  • A short policy on where encryption is used: devices, backups, data in transit.
  • Key management responsibilities.

(i) Human resources security, access control and asset management

  • An asset inventory with owners.
  • Joiner, mover and leaver steps, and periodic access reviews with decisions.

(j) Multi-factor authentication and secured communications

  • Where multi-factor authentication is required and proof that it is switched on.
  • Secured emergency communication: how you reach each other when normal channels fail.

Keep evidence alive, not archived

The most common gap is not missing documents but outdated ones: a policy nobody reviewed, a backup test from two years ago. Give each piece of evidence an owner and a review or expiry date, and link it to the measure it supports. Then a gap shows up before an auditor finds it.

CloudSignLab keeps evidence linked to each control, with expiry reminders and a readiness score per NIS2 measure. See how it works on the NIS2 page, or start with the free NIS2 check to find out whether NIS2 applies to you.

Start free

Share this article