Skip to main content

NIS2 Compliance Checklist

NIS2
For Tech Companies · 2026 Edition

Your CTO has just received a question from a customer asking you if you are compliant with NIS2.

Compliance checklistNIS2for technology companies 2026

Your corporate client sent a security questionnaire. One of the questions relates to NIS2. You’ve seen the regulation mentioned everywhere, but you’ve never had a clear picture of what they’re really asking for from a technology company like yours.

This checklist is for you.

Not a summary of the law firm. Not a 40 page PDF. A practical, step-by-step checklist that a technical founder or engineering leader can use to evaluate where they are.


First: Do You Even Fall Under NIS2?

This is where most guides waste your time. They describe NIS2 fully before telling you if it applies to you.

NIS2(EU Network and Information Security Directive 2) applies to two categories of organisations operating in the EU:

  • • Essential entities: energy, transport, banking, health, water, digital infrastructure, space, public administration
  • • Important entities: postal services, waste management, chemicals, food production, manufacturing, digital suppliers, research institutions

If you're a SaaS company, cloud provider, managed service provider (MSP) or B2B technology company If you operate in Europe, you almost fall into the category of “digital providers” or “significant entities” once you exceed these thresholds:

  • • 50+ employees, OR
  • • €10 million+ in annual turnover

That being said, your corporate customers can still request NIS2 alignment as a purchase condition, regardless of your size.

Find out what situation you are in before spending just an hour on this.


List of compliance verification

Each item includes what it actually means in practice, not just a regulatory quote.

Section 1: Governance and Accountability

1.1 Assigning an Information Security Owner

Someone at the management level must be responsible for compliance with NIS2.In a start-up, this is usually the CTO or chief engineer.In a larger company, it is a CISO or similar role.

1.2 Approve a cybersecurity policy at board level

Your management team must formally approve a written information security policy. It should not be 80 pages. A clear, signed policy covering data protection, access control, incident response and acceptable use is enough to get started.

1.3 Training in document management on cybersecurity risks

NIS2 explicitly requires leadership bodies to receive training and stay up-to-date with cybersecurity risks. This can be a quarterly information, an annual security review session with your leadership team, or a structured awareness training.

1.4 Creation of a register of critical systems and services

For each, identify what happens if it drops for 24 hours. If the answer is "we can't work," it's essential.


Section 2: Risk Management

2.1 Conduct a formal risk assessment

You need a documented process to identify, evaluate and treat security risks. This does not require a specialist consultant. A structured spreadsheet that maps threats, probability, impact and mitigation is a valid starting point.

2.2 Definition and documentation of risk management decisions

For each risk identified: accept it, mitigate it, transfer it (insurance) or avoid it.

Review the risk assessment at least once a year

NIS2requires ongoing risk management, not a single exercise. Put a recurring calendar item in your team calendar If a significant incident occurs or the technology set changes substantially, review it earlier.


Section 3: Technical security checks

This is the point where the checklist becomes specific. These are the controls that NIS2le is actually waiting for.

3.1 Multi-factor authentication (MFA) across all critical systems

Activate it. every administrator account. every cloud console. every code warehouse. every SaaS tool with access to production data. without exceptions. if a provider does not support MFA, this is a provider risk that you need to document.

3.2 Encryption of rest and transit data

All customer data stored on your systems must be encrypted in rest. All data transmitted between systems must use TLS1.2 or higher. Audit your storage configurations and trafficAPI.

3.3 Access control and least privilege

Each employee, contractor and service account should only have the access they need for their current role. Perform a quarterly access review. Remove accounts for deceased employees within 24 hours. Revoke excess access. This is one of the cheapest and most effective controls you can implement.

3.4 Patch and vulnerability management

You need a process for tracking and applying security patches. For critical vulnerabilities (CVSS score 9.0+), your target should be patches within 72 hours. For high severity (7.0-8.9), within two weeks.

3.5 Network segmentation

Production systems should be isolated from internal development and instrumentation. Your customer data should not be accessible from the same network segment as your Slack office. If you are on AWS, GCP or Azure, this is possible with VPCs and security groups.

3.6 Securitatea punctelor finale pe dispozitivele companiei

All employees’ laptops and mobile devices accessing company systems need endpoint protection: MDM recording, disk encryption (FileVault or BitLocker), screen locking, and remote deletion capability.

3.7 The secure configuration base for your infrastructure.

Cloud environments outperform secure configurations over time. Run a configuration audit against CIS benchmarks or your cloud provider’s best security practices.AWSSecurity Hub, Azure Defender and GCP Security Command Center all provide automated scores.

3.8 Penetration testing

NIS2 does not require annual name penetration tests, but regulators expect you to actively test your defense. A qualified third-party penetration test, covering your public application and cloud infrastructure, is the clearest way to demonstrate this.


Section 4: Supply Chain Security

This section captures most start-ups from the guard.

4.1 Inventory of third-party providers with access to the system

List each provider, tool, or service that processes your customer data or has access to your systems.

4.2 Security Assessment of Critical Suppliers

For your providers with the highest risk, review their security position. This means that you request their SOC2 report or ISO27001 certificate, review their data processing agreement and check their breach disclosure history.

4.3 Include security requirements in vendor contracts

Your contracts with providers that process personal data or have access to the system should include: minimum security standards, timelines for notification of breaches (NIS2 requires notification 24 hours a day to authorities), data processing obligations and the right to audit.

4.4 Continuous monitoring of the security position of the supplier

Quarterly is enough for most suppliers. Annual is acceptable for low-risk instruments. Critical suppliers with access to production guarantee more frequent checks.


Section 5: Incident Response

5.1 Document an incident response plan

Write down what you do when something goes wrong.Who is notified?Who decides if it is an incident that can be?Who communicates with customers?Who speaks to regulators?A two-page document covering these questions is enough to get started.

5.2 Know your NIS2 notification obligations

This is the part that will step you up if you don’t know it.

According to NIS2, if you encounter a significant incident affecting the security of your network and information systems, you must:

  • • Notify the relevant national authority within 24 hours of becoming aware (early warning)
  • • Submit a full incident notification within 72 hours (including initial assessment, severity, indicators of compromise)
  • • Provide a final incident report within one month

A “significant incident” is one that has caused or is likely to cause serious operational disruption, financial loss or material damage to other persons.

5.3 Test your incident response plan

Choose a realistic scenario (“we discovered unauthorized access to our database three days ago”).

Log and monitor your critical systems

You can't detect an incident for which you don't log in. At least: authentication events, privileged access, API calls to sensitive data and changes to system configuration. Centralize logs. Configure alerts for abnormal behavior. Keep logs for at least 12 months.


Section 6: Business Continuity

6.1 Maintain and test backups

System backups and critical data must exist, have to be encrypted and have to be tested.

6.2 Document recovery time objectives (RTOs)

For each critical service, define how long you can tolerate it being unavailable (RTO) and how much data loss is acceptable (RPO).

6.3 Document a business continuity plan

What if your primary cloud region collapses? What if your offices are inaccessible? What if a key employee is unavailable during a crisis? These scenarios don’t need perfect answers.


Section 7: Reporting and Registration

7.1 Register with the competent national authority

Most EU Member States have designated a national authority responsible for supervising NIS2. In France, it is ANSSI. In Germany, BSI. In the Netherlands, NCSC-NL. In Ireland, NCSC. If your business falls under NIS2, you are required to register with the relevant authority. Check if your country has published a public register or registration process. Many did this until 2024 and 2025.

7.2 Understand which authority has jurisdiction over you

If you operate in more than one EU Member State, the jurisdiction is generally determined by the head office (where the head office or major EU operations are located).

7.3 Documentary proof of conformity

NIS2 does not require an official certification, as does ISO27001. but it requires you to be able to demonstrate compliance when requested. Maintain a compliance record: the controls you have implemented, the policies you have approved, the risk assessments you have carried out and the incidents you have managed.


NIS2 vs. ISO 27001: Do You Need Both?

Frequently asked question. Here's the direct answer.

ISO27001 certification is not required by NIS2.But the two frameworks substantially overlap. If you are already certifiedISO27001, you have addressed most of the technical and governance requirements of NIS2. You will still need to cover specific obligationsNIS2: 24-hour incident notification timelines, supply chain security requirements and registration with national authorities.

If you start from scratch and your customers are primarily European companies, consider obtaining ISO27001 certification.

If you are a small team focused on a U.S. market that also sells in Europe, aligning NIS2 without official certification is a reasonable intermediate position.


The Most Mistakes Technology Companies Make with NIS2

Treat it as a legal exercise, not as a security exercise. The regulation exists because real organizations have had catastrophic failures.Controls are there because they work.Build them to protect your systems, not just to check a box.

Waiting for a fine before you start. Sanctions under NIS2 may reach EUR 10 million or 2% of the total annual turnover for significant entities and EUR 20 million or 2% of the total turnover for critical entities.

Ignoring supply chain requirements. Most breaches come through suppliers, not through direct attacks.The supply chain provisions of NIS2 exist for this reason.

Conflating NIS2 and GDPR. They are linked but separate.GDPR governs personal data.NIS2 governs the security of networks and information systems. A breach can trigger obligations within both.


What to do next

If you start from scratch, do these five things first:

  1. 1. Confirms if NIS2 is legally applicable to you (size, sector, EU presence)
  2. 2. Assign a named owner for complianceNIS2to your company.
  3. 3. Perform a risk assessment and map critical systems
  4. 4. Activate MFA in all critical systems (this week, not the next quarter)
  5. 5. Documentation of an incident response plan and 24- to 72-hour notification procedure

Anything else can be gradually over the course of 6 to 12 months.

If you want to track progress towards the complete checklist, structure your evidence and prepare for the audit without spending hundreds of hours on documentation, the platform The platform maps the NIS2 requirements for concrete tasks, tracks completion and stores your evidence in one place.

NIS2 is not the most complex regulation you will ever face, but it requires deliberate and documented action. Start now.

For more details, see complete NIS2 guide and NIS2 for tech teams.

The platform can help you get NIS2-ready

Book a meeting
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert