NIS2 Self-Assessment Checklist: 47 Questions the CIR Annex Asks — and 3 It Never Does
No regulator will score your NIS2 compliance for you. Ireland’s NCSC states it plainly: “It is not the role of the NCSC to confirm if entities are, or are not, in scope of the NIS2 Directive. This determination must be made by the entity as they know the specifics of their business.” [3] The same logic runs through supervision — the authority asks for evidence, and you are the one who has to know whether it exists.
So the assessment has to come from you. This one has 50 questions. Forty-seven of them are simply the named sub-sections of the CIR 2024/2690 Annex [1] turned into things you can answer yes, partly, or no. Three of them cover ground the Annex leaves uncovered — and those three are the reason most published NIS2 checklists have holes in exactly the same places.
Before You Score: Who the CIR Annex Actually Binds
The Annex is binding law for eleven categories of entity, and a benchmark for everyone else. Article 1 of the Implementing Regulation limits it to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, online marketplaces, online search engines, social networking services platforms, and trust service providers. [1]
If you are not on that list, Article 21(2)(a)–(j) of the NIS2 Directive still binds you, but the Annex does not. Use it anyway — it is the only text the Commission has written describing what those ten measures look like in practice, and national guidance is converging on it. Just score it knowing which column you are in.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
| Your entity | What the CIR Annex is to you | How to read a low score |
|---|---|---|
| One of the 11 categories in CIR Article 1 | Binding technical law | A gap is a compliance finding |
| Any other essential or important entity | The best available benchmark, not law | A gap is a risk you should be able to justify |
If you are not certain which side of that line you sit on, settle scope first — our guide to NIS2 scope, sectors and size thresholds works through the tests, and the full CIR 2024/2690 walkthrough covers what the Regulation adds on top of Article 21.
The Scoring Rule Everyone Else Skips: Qualified vs Unqualified
Score each question 2 for yes, 1 for partly, 0 for no. That part is ordinary. What is not ordinary is that in the CIR Annex, a zero does not always mean the same thing — because the Annex hedges some requirements and not others.
Counted across the Annex’s 47 sub-sections, the word “shall” appears 211 times. Against that sit 58 escape clauses: “where appropriate” 44 times, “where applicable” 10 times, and “to the extent feasible” 4 times. They are not evenly spread. 32 sub-sections contain at least one escape clause. Fifteen contain none at all.
That distinction has a legal consequence, and it is written into Article 2(2) of the Regulation. Where the Annex says “where appropriate”, “where applicable” or “to the extent feasible” and the entity considers the requirement does not apply, it shall “in a comprehensible manner document its reasoning to that effect”. [1] So on a qualified requirement you have a lawful third answer: not done, reasoning documented. On an unqualified one you do not — there is no clause to hang the exemption on.
| Score | Award it when | Evidence a reviewer would accept |
|---|---|---|
| 2 | Implemented and you can produce evidence today | Approved document, dated review, log extract, signed record |
| 1 | Partly done: the practice exists but is undocumented, unapproved, or unreviewed | Draft, ad-hoc practice, evidence you would have to reconstruct |
| 0 | Not done — or done nowhere you could show | Nothing |
| 2 (excluded) | Qualified sub-sections only. Not applicable, with reasoning documented under CIR Art 2(2) | The written reasoning itself |
The distribution is worth knowing before you start. Sections 1 (security policy), 4 (business continuity) and 13 (physical security) contain no unqualified sub-sections at all — every one of them is hedged. Six of the fifteen unqualified sub-sections sit in Sections 11 and 12, access control and asset management. The Annex, in other words, is most negotiable about continuity and buildings, and least negotiable about who has an account and what you own.
The 47 Questions, by CIR Annex Section
Each row gives the sub-section it comes from, the Article 21(2) letter it serves, and whether the Annex hedges it. Answer honestly on evidence, not intent — the test is whether you could produce something today, not whether someone is working on it.
Governance and risk — Sections 1–2, Article 21(2)(a)
| # | Question | Clause | Hedged? |
|---|---|---|---|
| 1 | Is your information security policy formally approved by the management body, with the approval date recorded in the document itself? | 1.1 | Yes |
| 2 | Does at least one named person report directly to the management body on network and information system security? | 1.2 | Yes |
| 3 | Have you documented a risk assessment and a risk treatment plan, with residual risk formally accepted by the management body? | 2.1 | Yes |
| 4 | Do you review compliance with your own policies at planned intervals and report the result upward? | 2.2 | No |
| 5 | Has an independent reviewer — someone outside the line authority of what they review — assessed your security approach? | 2.3 | No |
Incidents and continuity — Sections 3–4, Article 21(2)(b)–(c)
| # | Question | Clause | Hedged? |
|---|---|---|---|
| 6 | Does your incident handling policy assign roles and cover detection, analysis, containment, recovery, documentation and reporting? | 3.1 | Yes |
| 7 | Do you keep a risk-based list of assets subject to logging, with logs protected, backed up and alarm thresholds defined? | 3.2 | Yes |
| 8 | Is there a simple route for employees, suppliers and customers to report suspicious events? | 3.3 | Yes |
| 9 | Do you assess events against predefined criteria and re-examine recurring incidents quarterly? | 3.4 | No |
| 10 | Are containment, eradication and recovery documented as procedures — and tested at planned intervals? | 3.5 | Yes |
| 11 | Do post-incident reviews identify root cause and feed changes back into your risk treatment? | 3.6 | Yes |
| 12 | Is your business continuity and disaster recovery plan grounded in a documented business impact analysis? | 4.1 | Yes |
| 13 | Are backups held off the production network at sufficient distance, integrity-checked, and restore-tested? | 4.2 | Yes |
| 14 | Does your crisis process name the communication route to your CSIRT and competent authority? | 4.3 | Yes |
Supply chain and engineering — Sections 5–6, Article 21(2)(d)–(e)
| # | Question | Clause | Hedged? |
|---|---|---|---|
| 15 | Do supplier contracts carry incident-notification duties, audit rights, and security requirements that flow through to subcontractors? | 5.1 | Yes |
| 16 | Do you maintain a current registry of direct suppliers with a contact point and the products or services each provides? | 5.2 | No |
| 17 | Does procurement set security requirements and require update support for the product’s whole lifetime, or replacement after end of support? | 6.1 | Yes |
| 18 | Are secure development rules written down and applied to outsourced development as well as in-house work? | 6.2 | No |
| 19 | Are secure configurations defined, enforced by tooling, and monitored for drift? | 6.3 | Yes |
| 20 | Are changes tested and impact-assessed before implementation, with emergency deviations documented afterwards? | 6.4 | Yes |
| 21 | Is security testing scoped by risk assessment, with criticality and mitigating actions recorded? | 6.5 | Yes |
| 22 | Are patches applied within a reasonable time — and is every decision not to patch documented and substantiated? | 6.6 | No |
| 23 | Is your network architecture documented and current, with remote and service-provider access explicitly controlled and time-bound? | 6.7 | Yes |
| 24 | Are production, development and administration networks separated, with critical systems in secured zones? | 6.8 | Yes |
| 25 | Do you detect or prevent malicious and unauthorised software across your systems? | 6.9 | Yes |
| 26 | Do you monitor vulnerability sources and publish a disclosure route aligned to your national coordinated vulnerability disclosure policy? | 6.10 | Yes |
People, access, assets and premises — Sections 8, 10–13
| # | Question | Clause | Art 21(2) | Hedged? |
|---|---|---|---|---|
| 27 | Does your awareness programme repeat over time, cover new starters, and reach suppliers as well as staff? | 8.1 | (g) | Yes |
| 28 | Have you identified which roles need security-specific training — and assessed whether the training worked? | 8.2 | (g) | No |
| 29 | Do employees, suppliers and the management body have documented, accepted security responsibilities? | 10.1 | (i) | No |
| 30 | Are background checks defined by role and completed before the person starts in that role? | 10.2 | (i) | Yes |
| 31 | Do contracts define which security duties survive termination or a change of role? | 10.3 | (i) | No |
| 32 | Is there a communicated disciplinary process for security policy violations? | 10.4 | (i) | Yes |
| 33 | Do your access control policies cover physical access and system-to-system access, not user logins alone? | 11.1 | (i) | Yes |
| 34 | Are access rights granted on least privilege, revoked on role change, logged, and reviewed at planned intervals? | 11.2 | (i) | No |
| 35 | Do administrators hold separate administration accounts, individualised and restricted as far as possible? | 11.3 | (i) | No |
| 36 | Are administration systems used only for administration, separated from other software, and protected by authentication and encryption? | 11.4 | (i) | No |
| 37 | Is every identity unique and tied to one person, with shared identities explicitly approved and documented? | 11.5 | (i) | No |
| 38 | Do you force credential resets after repeated failed attempts, terminate inactive sessions, and require separate credentials for privileged accounts? | 11.6 | (i) | Yes |
| 39 | Is multi-factor or continuous authentication applied where your asset classification calls for it? | 11.7 | (j) | Yes |
| 40 | Do all in-scope assets carry a classification level tied to confidentiality, integrity, authenticity and availability? | 12.1 | (i) | Yes |
| 41 | Does an asset-handling policy cover the whole lifecycle, through to irretrievable deletion or destruction? | 12.2 | (i) | Yes |
| 42 | Is removable media blocked by default and permitted only where an organisational reason exists? | 12.3 | (i) | Yes |
| 43 | Is your asset inventory complete, accurate, current — and are changes recorded traceably? | 12.4 | (i) | No |
| 44 | Are assets in personnel custody deposited, returned or deleted on termination, and is that documented? | 12.5 | (i) | No |
| 45 | Are power, cooling and telecommunications protected, monitored, and tested against failure? | 13.1 | (c) | Yes |
| 46 | Have you set control thresholds for physical and environmental threats, and do you alert when they are breached? | 13.2 | (e) | Yes |
| 47 | Are security perimeters set by risk assessment, with premises continuously monitored for unauthorised physical access? | 13.3 | (i) | Yes |
Where a row exposes a real gap, the measure-level guides go deeper than a single question can — the full Article 21 breakdown maps each CIR section to its verbatim sub-requirements.
The 3 Questions the Annex Never Asks
Two of the Annex’s thirteen sections carry no sub-headings at all. Section 7 (effectiveness assessment) and Section 9 (cryptography) are written as flat runs of numbered points, so a checklist built by walking the Annex’s named sub-sections silently skips Article 21(2)(f) and (h) entirely. That is not a hypothetical failure mode — it is what you get from a mechanical read of the structure.
The third gap is larger. Article 21(2)(j) names three things: multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communication systems within the entity. Search the whole CIR Annex and “voice” appears zero times, “video” zero times, and “emergency communication” zero times. [1] Section 11 is the only section that cites point (j), and it reaches it solely through multi-factor authentication at 11.7. Two of point (j)’s three limbs have no technical specification anywhere in the Regulation — but they sit in the Directive’s own list of measures all the same, qualified there only by “where appropriate”. [2]
| # | Question | Source | Hedged? |
|---|---|---|---|
| 48 | Have you defined what gets measured, by which method, when, and who analyses the result — and do you review that policy? | CIR Section 7 · Art 21(2)(f) | Yes |
| 49 | Does your cryptography policy set algorithm type and strength by asset classification, and cover the full key lifecycle from generation to destruction? | CIR Section 9 · Art 21(2)(h) | Yes |
| 50 | Are voice, video and text communications secured — and is there a secured emergency communication system inside the entity for use when normal channels are down? | Art 21(2)(j) only | Yes |
Question 50 is the one to watch during an incident. Point (j) is where you prove you can still coordinate when the network you are defending is the network you would normally coordinate over. Nothing in the Annex tells you what “secured” means there, which means the reasoning is yours to write down.
Reading Your Score: Four Bands and the Zero That Caps Them
Fifty questions at two points each gives a maximum of 100. Treat the total as a planning number, not a verdict — the bands below describe what an organisation at that level can typically produce on request, which is the thing supervision actually tests.
| Score | Band | What it means in practice |
|---|---|---|
| 0–49 | Initial | Security work happens, but little of it is documented, approved or reviewed. You could not assemble an evidence pack. |
| 50–74 | Developing | Core policies exist. Review cycles, independent assurance and supplier controls are the usual weak points. |
| 75–89 | Defined | The programme is documented and running. Gaps are specific and known rather than structural. |
| 90–100 | Audit-ready | Every measure is evidenced, reviewed on a cycle, and every exclusion has written reasoning behind it. |
One hard cap. If any of the fifteen unhedged sub-sections scores 0, do not claim a band above Developing, whatever your total says. A high average built on a missing asset inventory or unmanaged privileged accounts is an average concealing a finding — and those fifteen are precisely the requirements with no “where appropriate” to fall back on. Article 21(4) of the Directive is unambiguous on what happens next: an entity that finds it does not comply “takes, without undue delay, all necessary, appropriate and proportionate corrective measures”. [2] Finding it and doing nothing is its own failure.
This is a triage instrument, not a substitute for structured remediation. Once you know where the zeros are, our five-phase gap analysis with RAG-scored remediation turns them into a plan, and the five-level maturity model tracks the same programme over years rather than a single sitting.
What to Fix First — by Role, Before Your First Audit
Four people will read the same score and correctly draw four different conclusions.
If you own IT security: start with the fifteen unhedged questions, then Section 11. Four of the six unhedged access-control and asset-management sub-sections are things a competent team usually does but rarely evidences — separate admin accounts, unique identities, reviewed access rights, a traceable inventory. Converting practice into evidence is faster than building controls.
If you run a smaller entity without a security team: ignore the total for now and count only the zeros. Questions 1, 3, 6, 12 and 43 are the five that everything else references — policy approval, risk assessment, incident handling, continuity, asset inventory. Our minimum-viable-compliance analysis works through how much of the Annex is genuinely unavoidable at small scale.
If you own compliance: your deliverable is not the score, it is the documented reasoning behind every exclusion. Each of the 32 hedged sub-sections you have decided not to implement needs a written justification under CIR Article 2(2) — and an undocumented exclusion is indistinguishable from a gap when an authority asks for evidence of implementation. [3]
If you sit on the board: the number to carry into the meeting is the count of unhedged zeros, not the score out of 100. It is the only figure here that maps directly to a finding. The 90-day audit preparation plan sets out what evidence has to exist before an inspection, and what a first audit looks like differs sharply between essential and important entities.
Frequently Asked Questions
Does a low score mean my organisation is non-compliant?
No. This instrument measures whether you can evidence each measure today; compliance is determined by your national competent authority against your national transposition, taking proportionality into account under Article 21(1). A low score means you would struggle to produce evidence on request — which is a real problem, but it is not a legal finding.
We are not one of the eleven entity types in CIR Article 1. Is this still worth scoring?
Yes, with one adjustment. The Annex is not binding on you, so treat every question as a benchmark rather than a rule, and treat the hedged/unhedged split as guidance on where regulators are likely to expect least flexibility. Article 21(2)(a)–(j) itself still binds you regardless.
How is this different from a gap analysis?
Scope and effort. This is a sitting of an hour or two that tells you roughly where you are and which sub-sections to look at. A gap analysis inventories actual controls, maps them clause by clause, and produces a costed remediation roadmap with owners and dates. Score first, then analyse — running a full gap analysis before you know your weak sections wastes the expensive part of the exercise.
How often should we re-score?
The Annex repeatedly requires review “at planned intervals” and after significant incidents or significant changes to operations or risks. Re-scoring annually, and again after any significant incident, keeps the self-assessment on the same cycle the Regulation already imposes on the underlying policies.
Can we score a requirement as “not applicable”?
Only on the 32 hedged sub-sections, and only if you write down why. CIR Article 2(2) requires the entity to document its reasoning “in a comprehensible manner”. On the fifteen unhedged sub-sections there is no such route in the text.
Sources
- Commission Implementing Regulation (EU) 2024/2690 — technical and methodological requirements, Article 1, Article 2(2), and the Annex (linked above), EUR-Lex.
- Directive (EU) 2022/2555 (NIS2) — Article 21(1), 21(2)(a)–(j) and 21(4) (linked above), EUR-Lex.
- National Cyber Security Centre (Ireland) — NIS2 Frequently Asked Questions.
- ENISA — Technical Implementation Guidance on cybersecurity risk-management measures, which follows the CIR Annex structure and sets out evidence artefacts per Annex point.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
