Your NIS2 Audit Is Coming. Do You Know Where Your Gaps Are?
Whether you’re the compliance officer, DPO, or the IT manager who got handed NIS2, this free 16-page assessment tool shows you exactly what auditors check — and exactly where your gaps are. Enforcement is active EU-wide: the directive allows fines up to €10M or 2% of global turnover, with management personally accountable under Article 20.
- Covers all 10 Article 21(2) security measures
- CIR 2024/2690 Annex reference column included
- 16-page workbook — maturity scoring per measure
- Instant PDF download, no payment required
Get Your Free Checklist
Enter your email to receive the Article 21 Compliance Checklist PDF instantly.
The 10 NIS2 Article 21 Measures — Scored in One Workbook
The checklist covers every security domain under Article 21(2) of the NIS2 Directive, with the corresponding CIR 2024/2690 Annex section number for each. Use it to score your current documentation status against each measure.
| Done | Security measure | NIS2 ref |
|---|---|---|
| Risk analysis & information security policies | 21(2)(a) | |
| Incident handling & Art. 23 reporting | 21(2)(b) | |
| Business continuity & crisis management | 21(2)(c) | |
| Supply chain security | 21(2)(d) | |
| Security in acquisition, development & maintenance | 21(2)(e) | |
| + 5 more measures (f–j): effectiveness, training, cryptography, access control, MFA & secure comms — each with its CIR Annex reference | ||
A preview of the 16-page workbook you’ll receive — not a stock image.
Risk Analysis & Security Policies
Documented risk assessment methodology, asset register, information security policy.
Incident Handling
Incident detection, response, and notification procedures aligned to Art. 23 reporting timelines.
Business Continuity & Crisis Management
BCP, backup procedures, DR strategy, crisis management plan, exercising schedule.
Supply Chain Security
Supplier security policy, risk assessments for critical ICT suppliers, contractual clauses.
Security in Acquisition, Development & Maintenance
Patch and vulnerability management procedures, secure development lifecycle documentation.
Policies to Assess Effectiveness
Cybersecurity measurement methodology, KPI framework, management review schedule.
Cybersecurity Hygiene & Training
Security awareness programme, training records, HR security policy, onboarding procedures.
Cryptography & Encryption
Encryption policy, key management procedure, cryptographic standards in use.
Human Resources, Access Control & Asset Management
Access control policy, asset register, role-based access controls, offboarding procedure.
Multi-Factor Authentication & Secure Communications
MFA policy, privileged access management, secure communication channels documentation.
“It provides detailed policy and procedure templates as well as detailed NIS2 compliance implementation guides. Believe this will be a very useful tool for us.”
Enda Macken, Data and Systems Manager — Dromone Engineering Limited, IrelandWritten Against the Directive and the CIR — Not Against a Summary
Most free NIS2 checklists are vague blog summaries. This one is different: it is derived directly from NIS2 Directive 2022/2555 Article 21(2) and the Implementing Regulation CIR 2024/2690 Annex, which came into force on 17 October 2024 for Annex I Essential Entities.
Every measure on the checklist maps to the specific CIR Annex section and ENISA implementation guidance where available. When you receive the PDF, each row includes the directive article reference so you can verify it yourself.
NIS2-Templates.com publishes 66 editable compliance templates (54 Word + 12 Excel) covering all Article 21 requirements. The checklist is the first step — when you know your gaps, you know what documentation you need to close them.
Questions, Answered
Is it really free?
Yes — completely free, no payment and no card required. Enter your email and the 16-page workbook is sent to you instantly.
What format is it, and how is it delivered?
A 16-page workbook (PDF) you can print or share with your team. It’s emailed to you the moment you submit the form.
Will you spam me?
No. You’ll get the checklist plus occasional NIS2 compliance updates, and you can unsubscribe from any email in one click. We handle your data under GDPR — see our Privacy Policy.
Is it current with CIR 2024/2690?
Yes. Every measure is drawn from NIS2 Directive (EU) 2022/2555 Article 21(2) and the Implementing Regulation CIR 2024/2690 Annex, which came into force on 17 October 2024. Each row carries its directive reference so you can verify it yourself.
Do I still need the full template packs?
The checklist tells you where your gaps are. Closing them needs the actual documents — policies, registers, procedures. NIS2-Templates.com publishes 66 editable compliance templates (54 Word + 12 Excel) covering all of Article 21, so once you know your gaps you know exactly what to deploy.
This page provides general information only and does not constitute legal advice. Consult a qualified legal or compliance professional for advice specific to your organisation.
