EUComply

Aug 23, 2026 · 9 min read · NIS2

NIS2 Compliance Checklist for SaaS Companies (2026)

Many SaaS founders assume NIS2 only applies to banks and utilities. It doesn't. If you sell software to EU businesses, chances are your customers are asking about it — and some of them need you to be compliant before they can sign.

Not legal advice. This is a practical engineering-oriented checklist based on the public text of Directive (EU) 2022/2555. For formal obligations, consult the directive itself and your national transposition law.

Step 1: Are you actually in scope?

NIS2 distinguishes between essential entities (large energy, transport, banking, health, digital infrastructure providers) and important entities — which includes most other medium and large companies operating in the EU. The size thresholds follow the standard SME definition:

If none of that applies today, treat this checklist as preparation for your customers' vendor reviews — which is where most SaaS companies feel NIS2 first.

Step 2: The ten measures of Art. 21 — mapped to SaaS practice

Article 21 lists the risk-management measures member states must require. Here is what each means for a typical SaaS company:

Art. 21 requirementWhat it looks like in a SaaS company
Risk analysis & information system security policiesA written security policy, a threat model for your product, documented acceptance of major risks
Incident handlingA documented process: detect → triage → contain → notify (see Step 4) → post-mortem. Test it once a year.
Business continuity, backup, disaster recoveryTested backups with defined RTO/RPO, a DR plan that isn't just a wiki page nobody has read
Supply chain securityVendor register, security review of critical dependencies, DPA/security clauses with sub-processors
Security in acquisition, development and maintenanceSecure SDLC basics: dependency scanning, code review, secrets management, vulnerability disclosure policy
Policies to assess effectiveness of measuresPeriodic testing — pentest reports, tabletop exercises, metrics reviewed by management
Cyber hygiene and trainingSecurity training at onboarding and annually, MFA everywhere, patch discipline
Cryptography / encryption policiesTLS everywhere, encryption at rest for customer data, key management that is actually written down
HR security, access control, asset managementLeast-privilege access, offboarding checklists, an inventory of systems holding customer data
MFA / secured communicationsMulti-factor authentication for admin access and internal systems (explicitly required)

Where to start if you can only do three things this quarter

  1. MFA on everything — cheapest control with the highest impact, and explicitly named in the directive.
  2. Write down incident handling — regulators judge you on process, not perfection. One page beats nothing.
  3. Fix the technical baseline of your public site — HTTPS/HSTS, security headers, no trackers firing before consent. This is what automated checks measure, and it's what shows up in your customers' scans of your domain.

Step 3: Supply chain cuts both ways

The most underrated part of NIS2 for SaaS: your position in two supply chains at once.

Step 4: Incident reporting timelines

If you're an in-scope entity, significant incidents trigger a three-stage clock:

You cannot improvise this during an outage. Decide today who declares an incident, who writes the notifications, and where the authority contact details live.

Step 5: Documentation is the deliverable

Regulators and enterprise buyers don't audit your infrastructure directly — they audit your evidence. For each Art. 21 measure, keep something reviewable: the policy document, the test result, the training log, the signed vendor clause. A quarterly compliance narrative that maps evidence to requirements turns "we're probably fine" into a defensible answer.

Check the technical baseline now

EUComply scans any website for the externally visible parts of the baseline: TLS/HSTS, security headers, consent mechanisms, legal pages, and pre-consent trackers. Free, no sign-up, works on any stack.

Run a free scan →

EUComply Pro ($79/yr) generates auditor-ready PDF reports and NIS2 vendor clause templates.

Further reading

How does EUComply compare with the established tools? See our head-to-head comparison — pricing, features and where each one falls short.