5 NIS2 Maturity Levels: Self-Assess Your Compliance Readiness and Close the Gap to Level 3
The first formal NIS2 supervisory activities swept across EU member states in 2025, with the first audit wave targeting essential entities before June 2026. Competent authorities are not asking whether your organisation has cybersecurity controls — they are asking whether you can prove they work.
That distinction — between having security and demonstrating it — separates organisations at different cybersecurity maturity levels. An organisation at Level 1 might have a firewall, antivirus, and daily backups. An organisation at Level 3 has documented controls, management approval records, tested processes, and structured evidence available on demand. The gap between those two states is exactly what Article 21 of the NIS2 Directive is designed to close — and what auditors measure. [1]
This guide maps a 5-level maturity model directly to NIS2 Article 21’s 10 mandatory security measures. You will find a clear description of each level, a domain-by-domain evidence table showing what auditors expect at Level 3 versus Level 2, a self-assessment scoring rubric, and practical steps to advance from one level to the next.
Does NIS2 apply to your organisation? Essential entities are typically large organisations (250+ employees or €50M+ annual turnover) in high-criticality sectors such as energy, transport, banking, health, digital infrastructure, and public administration. Important entities include medium-sized organisations (50–249 employees or €10M–€50M turnover) in the same sectors, plus some smaller operators of critical services. If you are uncertain of your scope, our NIS2 compliance checklist includes a scope verification section.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
What Is a Cybersecurity Maturity Assessment?
A cybersecurity maturity assessment evaluates how systematically an organisation manages security risk — not just what controls it has, but how consistently those controls are designed, documented, approved, tested, and improved over time.
The five-level model in this guide draws from established capability maturity model (CMM) methodology, adapted to NIS2’s proportionality principle. Article 21(1) requires measures that are “appropriate and proportionate” to the entity’s exposure to risk, size, and the likelihood and severity of incidents. A 60-person firm and a 6,000-person enterprise implement the same domains at different depths. Maturity assessment is the tool for calibrating that proportionality correctly.
| Level | Name | Core Characteristic | NIS2 Status |
|---|---|---|---|
| 1 | Initial / Ad-hoc | Reactive, individual-dependent, no documentation | Non-compliant |
| 2 | Developing / Documented | Policies drafted but inconsistently applied | Non-compliant |
| 3 | Defined / Implemented | Standardised, management-approved, operating evidence | Minimum compliant |
| 4 | Managed / Measured | Quantified with KPIs, continuously monitored | Above minimum |
| 5 | Optimising | Intelligence-driven, continuously improving | Best in class |
Level 1: Initial / Ad-hoc
Cybersecurity at Level 1 is reactive and person-dependent. No formal risk management process exists. Security decisions are made informally, controls were selected without a structured risk assessment, and incident response depends on whoever is available at the time. Most Level 1 organisations have some technical controls — firewalls, antivirus, backups — but these exist as isolated point solutions, not as a coherent and governed security programme.
Article 21(1) compliance status: Fails the management body approval requirement. No record exists of management formally approving or overseeing cybersecurity risk-management measures — a mandatory governance requirement regardless of organisation size.
Article 21(2) compliance status: Fails all 10 measures. No risk analysis policy (a), no formal incident handling procedure (b), no tested business continuity plan (c), no documented supplier security requirements (d), no vulnerability management programme (e), no effectiveness assessment (f), training is informal or absent (g), no cryptography policy (h), no access control review process (i), and MFA — if deployed at all — covers email only rather than all privileged accounts and remote access (j).
Penalty exposure: Maximum. Under Article 34 of the directive, essential entities infringing Article 21 face administrative fines up to €10,000,000 or 2% of total worldwide annual turnover (whichever is higher). Important entities face up to €7,000,000 or 1.4% of global annual turnover. Management body members can be held personally accountable for non-compliance under Article 20 of the directive. [2]
Level 2: Developing / Documented
Level 2 organisations have begun their NIS2 compliance journey. A gap analysis has typically been completed, and the scope of what’s missing is understood. Policies exist — an IT security policy, a basic incident response procedure — but they are often drafted from a template, not yet formally adopted by management, inconsistently followed across the organisation, and not regularly reviewed. Some technical controls are in place beyond the Level 1 baseline: MFA on privileged accounts, a basic supplier list, ad hoc training sessions.
Article 21(2) compliance status: Partial. Controls exist for most domains but fail the evidence test. An auditor asking for the last management-signed risk assessment review, the most recent business continuity plan restoration test record, or the supplier security clause register will find either no document or an informal file that does not constitute structured audit evidence.
This is where the majority of SMEs entering NIS2 scope currently sit. The HvS-Consulting NIS2 self-assessment framework identified the defining SME pattern: technically secure in terms of controls, but documentation lacking — “the biggest hurdle for SMEs.” The tools and policies exist in draft; the governance layer that converts them into compliance evidence does not.
Level 3: Defined / Implemented — The NIS2 Minimum
Level 3 is the compliance threshold NIS2 competent authorities expect. All Article 21(2)(a)–(j) measures are addressed with operating controls, documented in current policies approved by the management body, and supported by evidence of consistent implementation.
Three requirements distinguish Level 3 from Level 2:
1. Management body approval (Article 21(1)): A formal record — board minutes, a signed approval, or equivalent — must confirm that management has approved cybersecurity risk-management measures and oversees their implementation. This is not an IT function responsibility. The directive places ownership at board level, and management can be held personally accountable for infringements.
2. Evidence of operation: Controls must demonstrably be working, not merely exist on paper. A risk assessment policy is Level 2. A signed, dated risk assessment with an annual review log, identified risk owners, and treatment plans is Level 3. The distinction that emerged from 2025 pre-audit findings was consistent: “The result is not a lack of security activity. It is a lack of evidence of security activity.” [7]
3. Organisation-wide consistency: Controls must operate across all departments, not just in the IT team. Supplier security requirements must appear as contractual clauses, not informal expectations.
What Level 3 requires in practice:
- Current, management-approved risk assessment with annual review cycle and management sign-off record
- Incident response procedure that has been tested; test record and regulator notification templates in place
- Business continuity and disaster recovery plans with documented recovery time objectives and a completed restoration test
- Supplier register with security clauses in all material contracts and annual due-diligence records
- MFA deployed across all privileged accounts and all remote access — with evidence of coverage
- Cryptography policy covering data at rest and in transit, with a key management procedure
- Training programme with attendance records and at least one phishing simulation completed
- Access reviews conducted at defined intervals with sign-off records
- Vulnerability management process with defined patching windows and tracked exceptions
ENISA’s Technical Implementation Guidance for Article 21 (published June 2025) provides evidence examples for each measure and maps requirements directly to ISO/IEC 27001:2022 and the NIST Cybersecurity Framework — a practical cross-reference for organisations already working within either standard. [8]
Before reaching Level 3, every organisation must complete a formal NIS2 risk assessment. Without a documented risk assessment, no Article 21 compliance programme has a valid foundation — the risk assessment is the upstream document from which all other controls and priorities are derived.
Level 4: Managed / Measured
Level 4 moves from compliance to operational security management. Controls are not just in place — they are measured. Key performance indicators (KPIs) and key risk indicators (KRIs) track performance across every Article 21 domain: patch cadence and compliance percentage, mean time to detect (MTTD), mean time to respond (MTTR), MFA deployment rate, percentage of suppliers formally assessed, training completion rates by role.
Management receives structured security reports on a monthly or quarterly cadence. SIEM or equivalent monitoring generates alerts with defined response SLAs. Internal audits are conducted systematically, with findings tracked to closure. Annual penetration testing with remediation tracking is standard.
This level satisfies Article 21(2)(f) — “policies and procedures to assess the effectiveness of cybersecurity risk-management measures” — at a demonstrably high standard. Competent authorities conducting proactive supervision of essential entities will look for Level 4 evidence as indicative of genuine operational maturity beyond a paper-compliance baseline.
What Level 4 organisations add beyond Level 3:
- Defined KPIs per Article 21 domain, reported to management on a structured schedule
- Board-level security dashboard with at least monthly reporting
- SIEM with defined alert thresholds and documented response SLAs
- Annual internal audit of security controls with corrective action tracking to closure
- Annual external penetration test with tracked remediation
- Quantified risk scores with trend analysis
Level 5: Optimising / Continuous Improvement
Level 5 integrates security into the organisation’s core business processes. Threat intelligence feeds directly into control updates — new threat patterns trigger policy reviews and technology adjustments, not just incident responses. Security metrics drive investment decisions at board level. Automation handles routine security operations, freeing teams for proactive threat hunting and strategic programme improvement.
Level 5 organisations actively participate in sector information-sharing mechanisms aligned with NIS2 Article 29, contributing to and drawing from threat intelligence across their sector. Year-on-year MTTD and MTTR improvements are documented with root-cause analysis to explain the improvement drivers.
For most NIS2-scoped organisations, Level 5 is a long-term strategic aspiration, not a near-term compliance goal. NIS2 Article 21 compliance requires Level 3. Resources committed beyond that threshold are investments in operational resilience and competitive positioning — valuable, but not required to avoid enforcement action.
Where Most Organisations Are Starting
The majority of organisations entering NIS2 scope are at Level 1 or Level 2 — with isolated pockets of Level 3 in domains where prior regulatory requirements (GDPR, sector-specific rules) forced documentation discipline.
ENISA’s NIS360 2024 assessment placed six sectors in the “risk zone”: ICT service management, Space, Public administrations, Maritime, Health, and Gas. The common finding across these sectors was insufficient cybersecurity maturity relative to criticality — not absence of technical controls, but absence of systematic documentation, management governance, and operational evidence. [3]
Pre-audit findings across the EU in 2025 confirmed the same pattern. Organisations were not typically failing on technical security infrastructure. They were failing on evidence. The auditor requirement — structured, timestamped, version-controlled documentation showing controls were designed, approved, implemented, tested, and reviewed — was consistently absent even where the controls themselves were functioning.
The practical implication: the path from Level 2 to Level 3 is primarily a governance and documentation task, not a technology investment. Most SMEs already have approximately 60–70% of the required technical controls in place. The deficit is the management approval layer, systematic documentation, and structured evidence retention that converts existing controls into audit-ready compliance artefacts.
The single largest gating factor is management commitment. Without a board or senior management formally approving the cybersecurity programme, Article 21(1) cannot be satisfied — regardless of how sophisticated the technical infrastructure is.
Evidence Requirements by Maturity Level
This table maps each Article 21 domain to the evidence auditors expect at Levels 2, 3, and 4. Level 3 is the minimum. Anything to the left of Level 3 is not audit-ready.
| Article 21 Domain | Level 2 (Developing) | Level 3 (Minimum — Required) | Level 4 (Measured) |
|---|---|---|---|
| Risk analysis (a) | Draft risk register; no management sign-off | Signed, dated risk assessment; management approval record; annual review log with identified owners and treatment plans | Quantified risk scores with trend data; integrated risk register tied to control effectiveness metrics |
| Incident handling (b) | Draft incident procedure; informal incident log | Tested incident procedure with test record; incident log with timelines; regulator notification templates ready | SIEM logs with defined SLAs; MTTD and MTTR tracked; post-incident reviews documented with action closure |
| Business continuity (c) | BCP document; restoration never tested | Tested BCP and DR plan; documented recovery time objectives; restoration test record with management sign-off | Automated failover evidence; measured recovery times vs. RTO targets; annual test cycle with improvement tracking |
| Supply chain (d) | Supplier list without security requirements | Supplier register; security clauses in all material contracts; annual due-diligence records per supplier | Structured risk scores per supplier; fourth-party mapping; automated vendor risk platform evidence |
| Access control, cryptography, MFA (h)(i)(j) | Password policy; MFA on email only; informal access list | MFA on all privileged accounts and remote access with evidence of coverage; quarterly access reviews with sign-off; encryption policy with key management procedure; asset register | MFA coverage dashboards; privileged access management (PAM) tool logs; key rotation compliance metrics |
| Training and cyber hygiene (g) | One-time training session; no formal records | Annual training plan with attendance records; at least one phishing simulation with results documented | Training completion rates tracked by role; phishing click-rate trends year on year; skills gap analysis |
Level 3 is not about having these documents — it is about having them current, signed, and demonstrably in use. An incident procedure last updated in 2022 that has never been tested does not meet Level 3, regardless of its content. Evidence must be timestamped, version-controlled, and traceable to real operational activity. [6]
For a structured approach to assembling audit evidence across all Article 21 domains, our NIS2 audit preparation guide details what competent authorities examine during supervisory activities.
How to Score Your Organisation
Score your organisation on each of the six Article 21 domains below using this five-point rubric:
| Score | Label | What This Means |
|---|---|---|
| 1 | Initial | No formal process. Controls are ad hoc, person-dependent, and undocumented. |
| 2 | Developing | Process exists but is not consistently documented, not management-approved, or not uniformly applied across the organisation. |
| 3 | Defined | Documented, management-approved, consistently implemented, with evidence of operation available for audit. |
| 4 | Managed | Measured with KPIs. Metrics reported to management on a structured schedule. Internally audited with tracked corrective actions. |
| 5 | Optimising | Continuously improved. Threat intelligence integrated. Automation in use. Benchmarked against sector peers. |
Six domains to score:
- Risk analysis and security policy — Art. 21(2)(a)
- Incident handling — Art. 21(2)(b)
- Business continuity and disaster recovery — Art. 21(2)(c)
- Supply chain security — Art. 21(2)(d)
- Access control, cryptography, and MFA — Art. 21(2)(h)(i)(j)
- Training and cyber hygiene — Art. 21(2)(g)
Critical scoring rule: NIS2 auditors assess each domain independently. A score of 4 in incident handling does not offset a score of 1 in supply chain security. Your overall compliance readiness is determined by your lowest-scoring domain — the domain with the weakest evidence is the compliance gap that creates regulatory exposure.
How to Advance to the Next Level
Focus on your lowest-scoring domain first. Attempting to advance all domains simultaneously spreads effort too thin and rarely produces audit-ready evidence in any. Move the weakest domain up one level before addressing others.
Level 1 → Level 2:
- Assign a named owner to each Article 21 domain — individual accountability is the prerequisite for any documentation discipline
- Draft a policy for each domain using a structured template as the starting point
- Begin systematic logging: incidents, access reviews, training attendance, supplier interactions
- Commission a baseline risk assessment — even a lightweight, scoped version is sufficient to establish the foundation
- Create a supplier inventory listing all vendors with access to systems, networks, or sensitive data
Level 2 → Level 3 (the critical compliance threshold):
- Obtain management body formal approval of all security policies — a board minute, signed approval form, or equivalent record is required; this step cannot be skipped
- Test every key process at least once and document the outcome: run a tabletop business continuity exercise, conduct a full access review, simulate an incident notification to the competent authority
- Standardise controls across the entire organisation, including all departments outside IT
- Ensure supplier security requirements appear as contractual clauses in all material third-party agreements — informal expectations are not audit evidence
- Deploy MFA universally on all privileged accounts and all remote access, with evidence of coverage (a screenshot, a report, or a PAM tool export)
This is the transition with the highest compliance value per unit of effort. Reaching Level 3 closes the enforcement exposure that Level 1 and Level 2 carry. The timeline for a focused SME with existing technical controls is three to six months, provided management buy-in is secured at the outset.
Level 3 → Level 4:
- Define KPIs for each control domain: patch compliance percentage, MTTD, MTTR, MFA deployment rate, supplier assessment coverage
- Implement SIEM or structured log monitoring with defined alert thresholds and response SLAs
- Establish a monthly or quarterly board security reporting cadence with standardised metrics
- Commission an annual internal audit of security controls with findings tracked to closure
- Schedule an annual external penetration test with remediation tracked to completion
The Level 3 → Level 4 transition is a multi-year programme for most organisations. It delivers significant value for essential entities under proactive supervision from competent authorities, but it is not a legal requirement to demonstrate Article 21 compliance. Once Level 3 is stable, the risk of enforcement action is substantially reduced.
Frequently Asked Questions
What maturity level does NIS2 actually require?
The directive does not use the term “maturity level.” In practice, the documentation, governance, and evidence standards of Article 21 — combined with the management body approval obligation of Article 21(1) and the evidence expectations emerging from 2025 supervisory activities — map to what practitioners call Level 3: Defined / Implemented. All controls must be documented, management-approved, operating, and evidenced on demand.
What are the penalties for non-compliance with Article 21?
Essential entities face administrative fines up to €10,000,000 or 2% of total worldwide annual turnover (whichever is higher) under Article 34. Important entities face up to €7,000,000 or 1.4% of global annual turnover. Fines apply when Article 21 or Article 23 obligations are infringed. Management body members can be held personally accountable under Article 20.
Can a small organisation realistically reach Level 3?
Yes. Article 21(1)’s proportionality principle means a 60-person firm needs documented, management-approved controls appropriate for its specific risk profile — not the same infrastructure as a 10,000-person enterprise. The primary investment is time spent on documentation and governance. Three to six months is achievable for most focused SMEs with existing technical controls.
Is self-assessment sufficient, or do we need an external audit?
For important entities: self-assessment forms the baseline. Competent authorities may trigger supervisory activities following an incident or suspected non-compliance. For essential entities: proactive supervision is standard, meaning external audits and penetration tests are expected at Level 3 and above to demonstrate controls are genuinely operating.
How does NIS2 maturity assessment relate to ISO 27001?
ISO 27001 certification demonstrates a management system. NIS2 compliance demonstrates that specific Article 21 measures are operating and evidenced. The two overlap substantially — ENISA’s Technical Implementation Guidance maps Article 21 requirements directly to ISO/IEC 27001:2022 controls — but NIS2 compliance is a regulatory obligation with penalty consequences, not a voluntary certification.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources
- NIS 2 Directive, Article 21: Cybersecurity risk-management measures — nis-2-directive.com
- NIS 2 Directive, Article 34: Administrative fines — nis-2-directive.com
- ENISA NIS360 2024: Cybersecurity Maturity and Criticality of NIS2 Sectors — ENISA
- Security Maturity Models: Levels, Assessment, and Benefits — Linford & Company
- NIS2 Audit Countdown — June 2026: What You Must Prove — 6clicks
- NIS2 Compliance Checklist (2026): Evidence to Keep — Folderit
- What NIS2 Audits Will Look Like in 2026 — and How Organisations Can Prepare — Diamatix
- NIS2 Technical Implementation Guidance — ENISA (June 2025)
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
