EUComply

NIS2 Compliance Checklist 2026: A Practical 10-Step Guide

Aug 26, 2026 · 12 min read · ← All guides

Contents
  1. What is NIS2?
  2. Who needs to comply?
  3. The 10 mandatory security pillars
  4. Incident reporting obligations
  5. What NIS2 means for your website
  6. Free NIS2 website security scan
  7. NIS2 compliance checklist
  8. Penalties & enforcement

1. What is NIS2?

The Network and Information Security Directive 2 (NIS2) — Directive (EU) 2022/2555 — is the EU's updated cybersecurity framework that entered into force in October 2024. It replaces the original 2016 NIS Directive and significantly expands both the scope of organisations that must comply and the security requirements they must meet.

NIS2 focuses on three things: cybersecurity risk management, incident reporting, and supply chain security. Unlike GDPR which protects personal data, NIS2 protects the network and information systems that underpin critical services and important sectors in the EU economy.

Key change from NIS1: NIS2 applies to a much wider range of sectors (now 15 instead of 7), introduces a clear size-cap rule (medium and large entities), removes the distinction between "operators of essential services" and "digital service providers," and imposes significantly higher penalties — up to €10 million or 2% of global annual turnover.

2. Who needs to comply?

NIS2 applies to medium and large enterprises (50+ employees AND €10M+ annual turnover) operating in any of these 15 sectors:

High-criticality sectorsOther critical sectors
Energy (electricity, oil, gas, hydrogen)Postal & courier services
Digital infrastructure (IXPs, DNS, TLD registries)Waste management
Transport (air, rail, water, road)Manufacturing of medical devices
Banking & financial market infrastructureManufacturing of critical products (chemicals, machinery, electronics)
Health (hospitals, healthcare providers)Digital providers (marketplaces, search engines, social media platforms)
Drinking water & wastewaterFood manufacturing & processing
Public administration (governments at all levels)
Space

What about small businesses? If you are a small business (under 50 employees or under €10M turnover), you are not directly subject to NIS2 — but you are likely indirectly affected as a supplier to NIS2-covered entities. Your larger clients will require you to demonstrate cybersecurity controls as part of their supply chain security obligations under NIS2 Art. 21.

Important: If your business operates in one of these sectors, you are legally required to comply. "Not being in the EU" is not a defence — NIS2 applies to any entity providing services to EU customers in the covered sectors, regardless of where the entity is headquartered.

3. The 10 mandatory security pillars

NIS2 Article 21 requires all covered entities to implement proportionate technical, operational and organisational measures across ten areas:

  1. Risk analysis & cybersecurity policies — Formal, documented risk assessments and a company-wide cybersecurity policy.
  2. Incident handling — Detection, analysis, containment and response procedures with assigned roles.
  3. Business continuity & crisis management — Backup procedures, disaster recovery plans, and crisis communication protocols.
  4. Supply chain security — Vendor risk assessments, security requirements for suppliers, and monitoring of third-party access.
  5. Network & information system security — Firewalls, secure configuration, patch management, endpoint protection, and segmentation.
  6. Access control & authentication — Multi-factor authentication (MFA), least-privilege access, identity management, and privileged account monitoring.
  7. Encryption & cryptographic controls — Data encryption at rest and in transit, certificate management, and secure key storage.
  8. Human resources security & training — Cybersecurity awareness training, phishing simulations, and security policies embedded in employment contracts.
  9. Physical & environmental security — Access controls to facilities, CCTV, visitor management, and protection of critical hardware.
  10. Vulnerability handling & disclosure — Regular vulnerability scanning, a documented disclosure process, and a remediation timeline.
Documentation is key: Under NIS2's accountability principle, you must be able to demonstrate compliance, not just implement it. Every measure should have documented evidence — policies, logs, audit trails, and reports.

4. Incident reporting obligations

NIS2 mandates a structured 4-stage incident reporting timeline:

StepDeadlineRequirement
1. Early warningWithin 24 hoursNotify your CSIRT (Computer Security Incident Response Team) of any significant incident. Include initial assessment of severity and impact.
2. Incident notificationWithin 72 hoursSubmit a detailed report with cause, systems affected, exploited vulnerabilities, indicators of compromise (IOCs), and an initial impact assessment.
3. Intermediate reportOn requestProvide status updates as investigation progresses. The CSIRT may request additional data.
4. Final reportWithin 30 daysSubmit a complete incident report including root cause, remediation actions taken, evidence of recovery, and measures to prevent recurrence.

What qualifies as a "significant incident"? Any incident that has caused or is capable of causing severe operational disruption, financial loss, or harm to other entities or individuals. When in doubt, report — the penalty for failing to report is often more severe than the penalty for the underlying security gap.

5. What NIS2 means for your website

While NIS2 focuses on organisational cybersecurity posture, your public-facing website is one of the first places auditors and regulators will look. Here's what they check:

HTTPS & HSTS (Art. 21(2)(g) — Encryption)

All websites serving NIS2-covered entities must enforce TLS encryption. Your certificate must be valid, current, and configured correctly. HSTS (HTTP Strict Transport Security) headers should be present to prevent downgrade attacks. Mixed-content warnings (HTTP resources loaded on an HTTPS page) are a clear indicator of incomplete encryption.

Security headers (Art. 21(2)(e) — Network security)

Content Security Policy (CSP), X-Content-Type-Options, Referrer-Policy, X-Frame-Options, and Permissions-Policy headers are the minimum baseline. Missing headers are visible to anyone who inspects your site — including an auditor's penetration testing tools.

Cookie consent & tracking (Art. 21(2)(a) — Risk analysis)

Third-party scripts and tracking technologies running on your site create a supply-chain attack surface. Google Analytics, Meta Pixel, Hotjar, and similar tools load JavaScript from external domains — if any of those are compromised, your site becomes the vector. NIS2 supply-chain security (Art. 21(2)(d)) requires you to know what third-party code runs on your site.

Third-party scripts (Art. 21(2)(d) — Supply chain security)

Every external domain your site connects to is a potential supply-chain risk. The more third-party scripts loading before consent, the more attack surface you expose without documented control.

Legal pages & disclosures (Art. 21(2)(c) — Business continuity

An imprint/impressum and accessibility statement with operational contact details are expected. If regulators cannot identify who operates the site, they cannot assess your incident response readiness.

Free check: You can test your website against these visible NIS2 indicators right now. Enter your URL into the EUComply scanner — it checks HTTPS strength, security headers, third-party scripts, and cookie consent in under 10 seconds. No installation or sign-up required.

6. Free NIS2 website security scan

Use the scanner below to check your website's visible security posture — the things any NIS2 auditor would spot on first inspection. It's free, takes under 10 seconds, and requires no installation.

Run a free NIS2 website scan →

Enter any URL — works on all platforms. No sign-up.

7. NIS2 compliance checklist

Use this checklist to assess your readiness. Each item maps to a specific NIS2 Article and the type of evidence you should have ready:

#RequirementNIS2 Art.EvidenceDeadline
1Documented cybersecurity risk assessment21(2)(a)Risk register, methodology, findings, remediation planOngoing
2Written cybersecurity policy21(2)(a)Policies signed by leadership, review cadenceImmediate
3Incident detection & response plan21(2)(b), 23IR playbooks, roles matrix, escalation treeImmediate
4Business continuity & disaster recovery plan21(2)(c)BCP document, backup verification, recovery testsQ4 2026
5Supply chain vendor risk assessment21(2)(d)Vendor list, risk scores, contracts with security clausesQ4 2026
6Network security (firewall, segmentation, patching)21(2)(e)Network diagram, patch log, vulnerability scan resultsOngoing
7MFA on all privileged accounts21(2)(f)MFA provider config, user audit, exception listImmediate
8Encryption in transit (TLS) + at rest21(2)(g)TLS certificate inventory, encryption policyImmediate
9Cybersecurity awareness training21(2)(h)Training records, phish test results, completion ratesQ4 2026
10Physical security controls21(2)(i)Access logs, CCTV coverage, visitor policyQ4 2026
11Vulnerability scanning & disclosure process21(2)(j)Scan schedule, findings tracker, remediation SLAOngoing
12Incident reporting procedure (24h / 72h / 30d)23Notification template, CSIRT contact, escalation flowImmediate
13Security headers on public website21(2)(e+g)Live headers check (CSP, HSTS, XFO, XCTO)Immediate
14HTTPS enforced (no fallback to HTTP)21(2)(g)HSTS header, preload status, SSL Labs ratingImmediate
15Third-party script inventory21(2)(d)List of external domains loaded, purpose, risk ratingQ4 2026

How to use this checklist: Start with items marked "Immediate" — they can be assessed in minutes using the free scanner. The "Ongoing" items require a recurring process you operationalise once. "Q4 2026" items need dedicated projects — start planning now.

8. Penalties & enforcement

NIS2 introduces a tiered penalty structure that is substantially higher than the original NIS Directive:

Entity typeMaximum fineAlso applies to
Essential entities (high-criticality sectors)€10,000,000 or 2% of global annual turnover (whichever is higher)Managers can be held personally liable for failing to implement measures
Important entities (other critical sectors)€7,000,000 or 1.4% of global annual turnover (whichever is higher)Same personal liability for management

Beyond fines, regulators can issue binding instructions to remediate identified gaps, suspend data processing activities, and publicly name non-compliant entities. Reputational damage from enforcement actions often exceeds the fine itself — especially for entities that rely on trust as a competitive differentiator.

Enforcement is accelerating. EU member states were required to transpose NIS2 into national law by 17 October 2024. Most have done so, and regulators are actively conducting compliance reviews. The first wave of enforcement actions began in mid-2025, focused on entities in the energy, transport, and digital infrastructure sectors. Expect pressure on all other sectors through 2026–2027.

Start with what you can check for free

Your website's security posture is the easiest thing to assess right now — no internal meetings, no budget approval, no vendor selection. Enter your URL into EUComply and know within seconds whether your public-facing TLS, headers, and third-party risk profile raise red flags for a NIS2 auditor.

Check your site now →

Keep reading