NIS2 Requirements: How Ready Is Your Organisation?
Evaluate how well your organization's current practices align with NIS2 cybersecurity requirements across 10 key areas.
This assessment provides a preliminary readiness overview only and does not constitute legal or compliance advice. For a full NIS2 compliance audit, consult a qualified specialist.
What NIS2 Actually Requires You to Do
Working out whether NIS2 applies to you is the easy part. The harder question is what you actually have to implement once it does — and that is where most organisations discover how far they have to go.
The Directive splits your obligations across three articles. Article 21 sets out ten cybersecurity risk-management measures you must have in place. Article 23 defines what you must report to your national authority and how fast. Article 20 makes your management body personally accountable for both. The assessment above scores you against all ten Article 21 areas; the sections below explain what each one means in practice.
If you have not yet confirmed whether NIS2 applies to your organisation, start with the NIS2 scope check instead.
The 10 Security Measures Required by NIS2 (Article 21)
Article 21(2) lists ten measures that every essential and important entity must implement, based on an all-hazards approach and proportionate to the risk. These are the same ten areas the readiness assessment above scores you against.
| # | Article 21(2) measure | What it means in practice |
|---|---|---|
| a | Risk analysis and information system security policies | A documented risk assessment methodology, an approved information security policy, and evidence that both are reviewed at least annually |
| b | Incident handling | Defined detection, triage, escalation and post-incident review processes, with named owners and tested response runbooks |
| c | Business continuity, backup management, disaster recovery and crisis management | Tested backups with documented recovery point and recovery time objectives, plus a crisis management playbook that has been exercised |
| d | Supply chain security | Security requirements written into supplier contracts, a vendor risk assessment process, and visibility of your critical direct suppliers |
| e | Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure | Patch management SLAs, a vulnerability disclosure policy, secure development practices and change control |
| f | Policies and procedures to assess the effectiveness of risk-management measures | Internal audit, control testing and security metrics reported to the management body on a defined cycle |
| g | Basic cyber hygiene practices and cybersecurity training | A role-based awareness and training programme with completion tracking, covering phishing, passwords and secure handling of data |
| h | Policies and procedures on the use of cryptography and, where appropriate, encryption | Encryption in transit and at rest for sensitive data, with a documented key management standard |
| i | Human resources security, access control policies and asset management | Joiner, mover and leaver processes, least-privilege access reviews, and a maintained asset inventory |
| j | Multi-factor authentication or continuous authentication, secured voice, video and text communications, and secured emergency communications | MFA enforced on remote access, administrative accounts and email, plus a secure out-of-band channel for use during an incident |
These are minimums, not a ceiling. Article 21(1) requires the measures to be proportionate to your risk exposure, size and the societal impact of a disruption — so a large energy operator and a mid-sized food manufacturer will be held to visibly different standards for the same ten headings.
NIS2 Incident Reporting Deadlines
Article 23 sets some of the tightest reporting clocks in EU law. They start from the moment you become aware of a significant incident — not from when you finish investigating it.
Early warning
Notify your CSIRT or competent authority. State whether the incident is suspected to be caused by unlawful or malicious acts, and whether it could have a cross-border impact.
Incident notification
Provide an initial assessment of severity and impact, update the early warning, and include indicators of compromise where available.
Intermediate report
Supply status updates if the authority or CSIRT asks for them while the incident is still being handled.
Final report
Deliver a detailed description of the incident, its severity and impact, the threat type or root cause, the mitigation measures applied, and any cross-border effects.
An incident is significant if it has caused or is capable of causing severe operational disruption or financial loss to your organisation, or if it has affected or could affect others by causing considerable material or non-material damage. Meeting these deadlines is largely a question of preparation: most organisations that miss the 24-hour window do so because nobody was clear on who decides, who files, and with which authority.
Why Your Board Is Personally Accountable (Article 20)
NIS2 deliberately moved cybersecurity out of the IT department and into the boardroom. Under Article 20, the management bodies of essential and important entities must:
- Approve the cybersecurity risk-management measures taken by the organisation
- Oversee their implementation, rather than delegating and disengaging
- Be held liable for infringements where they fail to do so
- Follow training themselves, and encourage comparable training across the workforce, so they can identify risks and assess management practices
In practice this means board-level sign-off needs to be documented and dated, security reporting has to reach the management body on a defined cycle, and directors need training records of their own. These are among the first things a supervisory authority will ask to see.
NIS2 Compliance Checklist
Use this to sanity-check your position against the ten Article 21 measures before a formal assessment.
- Documented risk assessment methodology, reviewed within the last 12 months
- Incident response plan with named owners, tested at least once
- Backups tested by actual restore, with agreed RTO and RPO
- Security requirements in contracts with critical suppliers
- Patch management SLAs and a vulnerability disclosure route
- Internal audit or control testing evidencing the measures work
- Role-based security training with completion records
- Encryption standard covering data in transit and at rest
- Access reviews, joiner/mover/leaver process and asset inventory
- MFA on remote access, admin accounts and email
- Board approval of the measures, documented and dated
- A named person and route for filing a 24-hour early warning
Scored yourself and found gaps? The assessment above gives you a structured readiness score across all ten areas. For national reporting routes and authorities, see our country-by-country NIS2 guides, or talk to our team about a full gap assessment.
What a NIS2 Readiness Assessment Involves
A readiness assessment measures where you sit today against the ten Article 21 measures, so you can prioritise the gaps that carry the most regulatory and operational risk. Most organisations land somewhere on the following scale for each measure.
| Level | What it looks like | What an auditor would find |
|---|---|---|
| 1 — Not started | No policy, process or owner exists for this measure | Nothing to examine; an immediate finding |
| 2 — Ad hoc | The activity happens in practice but is undocumented and depends on individuals | Evidence is inconsistent and cannot be reproduced on request |
| 3 — Defined | A documented, approved policy exists with a named owner and defined cadence | Documentation is sound, but effectiveness is unproven |
| 4 — Managed and tested | The measure is operating, evidenced, tested and reported to the management body | Records, test results and board reporting all corroborate each other |
Essential entities should expect ex-ante supervision — proactive audits and on-site inspections whether or not anything has gone wrong — so level 3 is rarely enough on the measures that matter most. Important entities face ex-post supervision, meaning scrutiny arrives after an incident or a complaint, usually at the worst possible moment.
Frequently Asked Questions
What are the requirements of NIS2?
NIS2 requires in-scope organisations to implement ten cybersecurity risk-management measures under Article 21: risk analysis and security policies, incident handling, business continuity and backups, supply chain security, secure acquisition and development including vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography and encryption, human resources security and access control, and multi-factor authentication with secured communications. Organisations must also meet the Article 23 reporting deadlines and satisfy the Article 20 management accountability duties.
What is a NIS2 readiness assessment?
A NIS2 readiness assessment scores your current security practices against the ten Article 21 measures and identifies the gaps between where you are and what the Directive requires. It typically produces a maturity rating per measure, a prioritised remediation plan, and the evidence base your management body needs to approve and oversee the programme.
How do I comply with NIS2?
Confirm your scope and entity classification, register with your national competent authority, implement the ten Article 21 measures proportionately to your risk, establish a reporting route that can meet the 24-hour early warning deadline, and put documented board approval and oversight in place. Because NIS2 is transposed nationally, check your specific obligations in each Member State where you operate.
What are the NIS2 incident reporting deadlines?
You must submit an early warning within 24 hours of becoming aware of a significant incident, a fuller incident notification within 72 hours, an intermediate report if the authority requests one, and a final report within one month of the incident notification.
Does NIS2 require multi-factor authentication?
Yes. Article 21(2)(j) explicitly names the use of multi-factor authentication or continuous authentication solutions, alongside secured voice, video and text communications and secured emergency communication systems, applied where appropriate to your risk profile. In practice this means MFA on remote access, privileged accounts and email at a minimum.
What happens if we fail a NIS2 audit?
Supervisory authorities can issue binding instructions, order you to remedy deficiencies within a deadline, require you to notify affected customers, and impose administrative fines. Essential entities face up to €10 million or 2% of total worldwide annual turnover, whichever is higher; important entities face up to €7 million or 1.4%. Authorities can also temporarily suspend certifications and, for essential entities, bar individuals from management roles.