Free Download

Your NIS2 Audit Is Coming. Do You Know Where Your Gaps Are?

Whether you’re the compliance officer, DPO, or the IT manager who got handed NIS2, this free 16-page assessment tool shows you exactly what auditors check — and exactly where your gaps are. Enforcement is active EU-wide: the directive allows fines up to €10M or 2% of global turnover, with management personally accountable under Article 20.

  • Covers all 10 Article 21(2) security measures
  • CIR 2024/2690 Annex reference column included
  • 16-page workbook — maturity scoring per measure
  • Instant PDF download, no payment required
“Believe this will be a very useful tool for us.” — Enda Macken, Data & Systems Manager · Dromone Engineering, Ireland

Get Your Free Checklist

Enter your email to receive the Article 21 Compliance Checklist PDF instantly.

ENISA-aligned content CIR 2024/2690 Annex No payment required Instant PDF delivery No spam — unsubscribe anytime

The 10 NIS2 Article 21 Measures — Scored in One Workbook

The checklist covers every security domain under Article 21(2) of the NIS2 Directive, with the corresponding CIR 2024/2690 Annex section number for each. Use it to score your current documentation status against each measure.

NIS2 Article 21(2) Compliance Checklist
Directive (EU) 2022/2555 · CIR 2024/2690 Annex · 16 pages
DoneSecurity measureNIS2 ref
Risk analysis & information security policies21(2)(a)
Incident handling & Art. 23 reporting21(2)(b)
Business continuity & crisis management21(2)(c)
Supply chain security21(2)(d)
Security in acquisition, development & maintenance21(2)(e)
+ 5 more measures (f–j): effectiveness, training, cryptography, access control, MFA & secure comms — each with its CIR Annex reference

A preview of the 16-page workbook you’ll receive — not a stock image.

21(2)(a)

Risk Analysis & Security Policies

Documented risk assessment methodology, asset register, information security policy.

21(2)(b)

Incident Handling

Incident detection, response, and notification procedures aligned to Art. 23 reporting timelines.

21(2)(c)

Business Continuity & Crisis Management

BCP, backup procedures, DR strategy, crisis management plan, exercising schedule.

21(2)(d)

Supply Chain Security

Supplier security policy, risk assessments for critical ICT suppliers, contractual clauses.

21(2)(e)

Security in Acquisition, Development & Maintenance

Patch and vulnerability management procedures, secure development lifecycle documentation.

21(2)(f)

Policies to Assess Effectiveness

Cybersecurity measurement methodology, KPI framework, management review schedule.

21(2)(g)

Cybersecurity Hygiene & Training

Security awareness programme, training records, HR security policy, onboarding procedures.

21(2)(h)

Cryptography & Encryption

Encryption policy, key management procedure, cryptographic standards in use.

21(2)(i)

Human Resources, Access Control & Asset Management

Access control policy, asset register, role-based access controls, offboarding procedure.

21(2)(j)

Multi-Factor Authentication & Secure Communications

MFA policy, privileged access management, secure communication channels documentation.

“It provides detailed policy and procedure templates as well as detailed NIS2 compliance implementation guides. Believe this will be a very useful tool for us.”

Enda Macken, Data and Systems Manager — Dromone Engineering Limited, Ireland
All 10 Article 21(2) measures, each mapped to its CIR Annex section Cross-referenced to ENISA implementation guidance Updated for the 17 Oct 2024 CIR in-force date
About This Checklist

Written Against the Directive and the CIR — Not Against a Summary

Most free NIS2 checklists are vague blog summaries. This one is different: it is derived directly from NIS2 Directive 2022/2555 Article 21(2) and the Implementing Regulation CIR 2024/2690 Annex, which came into force on 17 October 2024 for Annex I Essential Entities.

Every measure on the checklist maps to the specific CIR Annex section and ENISA implementation guidance where available. When you receive the PDF, each row includes the directive article reference so you can verify it yourself.

NIS2-Templates.com publishes 66 editable compliance templates (54 Word + 12 Excel) covering all Article 21 requirements. The checklist is the first step — when you know your gaps, you know what documentation you need to close them.

Before You Download

Questions, Answered

Is it really free?

Yes — completely free, no payment and no card required. Enter your email and the 16-page workbook is sent to you instantly.

What format is it, and how is it delivered?

A 16-page workbook (PDF) you can print or share with your team. It’s emailed to you the moment you submit the form.

Will you spam me?

No. You’ll get the checklist plus occasional NIS2 compliance updates, and you can unsubscribe from any email in one click. We handle your data under GDPR — see our Privacy Policy.

Is it current with CIR 2024/2690?

Yes. Every measure is drawn from NIS2 Directive (EU) 2022/2555 Article 21(2) and the Implementing Regulation CIR 2024/2690 Annex, which came into force on 17 October 2024. Each row carries its directive reference so you can verify it yourself.

Do I still need the full template packs?

The checklist tells you where your gaps are. Closing them needs the actual documents — policies, registers, procedures. NIS2-Templates.com publishes 66 editable compliance templates (54 Word + 12 Excel) covering all of Article 21, so once you know your gaps you know exactly what to deploy.

This page provides general information only and does not constitute legal advice. Consult a qualified legal or compliance professional for advice specific to your organisation.