NIS2 Risk Assessment: A Practical Guide for SMEs
Step-by-step NIS2 risk assessment guide for SMEs. 5×5 matrix method, threat catalogue, risk register, and worked example for Article 21 compliance.
NIS2 compliance guides and resources
Step-by-step NIS2 risk assessment guide for SMEs. 5×5 matrix method, threat catalogue, risk register, and worked example for Article 21 compliance.
Last verified: March 2026. Based on ENISA Technical Implementation Guidance v1.0 (June 2025), Commission Implementing Regulation (EU) 2024/2690, and Directive (EU) 2022/2555 (NIS2). In June 2025, the European Union Agency for Cybersecurity (ENISA) published what is arguably the most important…
ISO 27001 covers 70-80% of NIS2 requirements. Learn the key differences, full controls mapping table, and how to close the compliance gap efficiently.
NIS2 fines reach €10 million or 2% of global turnover for essential entities — and Article 20 makes directors personally liable. Full breakdown of NIS2 penalties, supervisory measures, and how to protect yourself.
Does NIS2 apply to your organisation? Complete guide to NIS2 scope: 18 sectors, Essential vs Important entities, size thresholds, always-in-scope rules, and a 5-step self-assessment.
Complete NIS2 compliance checklist covering all 7 phases and 59 actionable items — governance, risk assessment, all 10 Article 21 measures, incident management, supply chain, training, and testing. Free PDF download.
A complete guide to all 10 NIS2 Article 21 cybersecurity risk management measures — what each requires, the CIR 2024/2690 Annex sections that define them, the documents you need to prove compliance, and how to prioritise your implementation programme.
The NIS2 Directive (EU 2022/2555) is the EU’s updated cybersecurity law. Learn who it applies to, what it requires, penalties for non-compliance, and how to achieve compliance in 2026.