This free NIS2 compliance checklist turns Directive (EU) 2022/2555 into a working spreadsheet you can act on today. If you are a compliance lead or CISO trying to answer the two questions that matter first, are we in scope, and where are our gaps, this NIS2 compliance checklist gives you a structured place to start. It walks through scope, the ten cybersecurity risk-management measures in Article 21(2), and the incident reporting duties in Article 23, with a status column and an owner column so nothing sits unassigned. NIS2 is transposed into national law by each member state, so exact procedures vary, but the core obligations are common across the EU. Download the Excel file below, work through the 48 items, and you will have a defensible gap list within an afternoon.
Get the NIS2 Scope and Gap Checklist
Work through the Article 21 measures and Article 23 reporting duties to find your NIS2 gaps. 48 items with status and owner columns.

What the NIS2 Scope and Gap Checklist covers
The download is a single Excel workbook with 48 line items grouped into three sections. Every row uses the same columns so progress is easy to track: the requirement, a plain-language note on what good looks like, a Status field (Not started, In progress, In place, or Not applicable), an Owner field, and a Notes and evidence field for links to the document or system that proves it.
Section 1, Scope. The first question most entities have is whether they are in scope at all. These rows capture your sector, your size, and whether you fall under essential or important entity classification, so you finish with a written rationale instead of a guess.
Section 2, Article 21 measures. Ten blocks, one per measure in Article 21(2), each broken into checkable sub-items you can assign and evidence.
Section 3, Article 23 reporting. Rows for the 24-hour early warning, the 72-hour incident notification, and the one-month final report, so the deadlines are baked into your incident process before you ever need them.

NIS2 the honest way: what actually matters
NIS2 (Directive (EU) 2022/2555) widened both the sectors and the entities that must manage cybersecurity risk. It applies to essential and important entities, determined by sector and size. Because it is a directive, each member state transposes it into national law, so registration steps, supervisory authorities, and penalties differ by country even though the substance is shared. If you need a plain explanation of the sectors and thresholds, read what is NIS2 and who must comply.
Three things carry most of the weight.
Governance. Article 20 makes the management body accountable for cybersecurity risk-management measures and requires them to be trained. This is not a delegated IT task; senior managers are personally in the frame.
The ten measures in Article 21(2). These are the minimum measures every in-scope entity must implement: risk analysis and information security policy; incident handling; business continuity and backup; supply chain security; security in acquisition and development including vulnerability handling; assessing the effectiveness of measures; cyber hygiene and training; cryptography; HR security, access control, and asset management; and multi-factor authentication with secure communications.
Reporting under Article 23. When a significant incident hits, the clock starts. You owe an early warning within 24 hours, a fuller incident notification within 72 hours, and a final report within one month. The 24-hour window is short, which is why agreeing the process in advance beats improvising during an incident.

How to use the NIS2 Scope and Gap Checklist
- Confirm scope first. Complete Section 1 before anything else. If you are not in scope, record why; if you are, note whether you are an essential or important entity.
- Assign an owner to every row. A measure without a named owner does not get done. Fill the Owner column across all 48 items.
- Score current state honestly. Set each Status to Not started, In progress, In place, or Not applicable. Resist marking things In place until you can point to evidence.
- Attach evidence. In the Notes and evidence column, link the policy, ticket, or system that proves the control. Empty evidence is a gap.
- Wire up reporting. Use Section 3 to confirm your team knows the 24-hour, 72-hour, and one-month duties and who files them.
- Re-run quarterly. Systems change, so revisit the NIS2 compliance checklist on a schedule and keep owners and status current.

Do this automatically in Venvera
A spreadsheet is the right way to start, but it goes stale the moment your systems change. In Venvera, the same scope questions, Article 21 measures, and Article 23 reporting duties live in the NIS2 framework as tracked controls with owners, due dates, and evidence that updates as your environment does. Because one piece of evidence can satisfy requirements across several standards at once, the access-control policy you map for NIS2 also counts toward your other obligations without re-uploading it. Plans start from EUR 399/month. If you are weighing your options, here is how we think about being an alternative to Vanta for NIS2 compliance.
Frequently Asked Questions
Who has to comply with NIS2?
NIS2 applies to essential and important entities, determined by sector and size. Because thresholds and sector definitions are set during national transposition, the safest first step is to confirm your classification in writing, which is exactly what the scope section of the checklist is for. For a fuller explanation, see what is NIS2 and who must comply.
What are the NIS2 reporting deadlines?
Article 23 sets three. You must send an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month.
Is a checklist enough for NIS2 compliance?
No. A checklist is how you find gaps and assign owners. Closing those gaps means implementing the Article 21 measures, evidencing them, and keeping them current, and Article 20 puts that accountability on your management body. Use the file to get organised, then maintain the work continuously.
Does NIS2 apply the same way in every EU country?
The obligations are common because they come from Directive (EU) 2022/2555, but each member state transposes it into national law, so registration steps, supervisory authorities, and penalties can vary. Always check your national implementation for procedural detail.




