Executive guide
A practical NIS 2 checklist for European essential and important entities
Five phases and twenty concrete actions, from scoping and gap analysis to risk management, incident reporting deadlines and steady-state audit readiness. Built from real engagements running NIS 2 and CyberFundamentals programs across European organizations.
Confirm whether NIS 2 applies and set the governance baseline
Before any technical work, establish whether you are in scope as an essential or important entity, and put accountable governance in place. The directive holds management personally responsible, so board awareness is a prerequisite rather than an afterthought.
Determine NIS 2 applicability
Map your sector under Annexes I and II, your headcount and your turnover against the size-cap rule. Document the decision in writing, including subsidiaries and EU establishments.
Register with the national competent authority
In Belgium this is the CCB. Deadlines and registration portals differ per Member State. Track the legal entity, sector and contact details that must be kept current.
Assign accountable management
Name a board-level owner for cybersecurity risk. Approve the cybersecurity policy at management level and minute the decision, because supervisory authorities will ask for evidence.
Provide management training
Deliver recurring NIS 2 training to the management body so they can identify and assess risks and the impact of cybersecurity measures on the services provided.
Run a structured gap analysis against the Article 21 measures
Article 21 lists the ten minimum cybersecurity risk-management measures. A gap analysis turns the legal text into a measurable baseline, so you can prioritize remediation by risk rather than by appetite.
Map current controls to the ten Article 21 domains
Cover risk analysis and policies, incident handling, business continuity, supply chain, secure acquisition, effectiveness assessment, basic cyber hygiene and training, cryptography, human-resources security and access control, and multi-factor authentication.
Benchmark against an established framework
Use CyberFundamentals in Belgium, ISO/IEC 27001, or NIST CSF 2.0 as the operating model. NIS 2 does not prescribe a framework, but supervisory authorities expect a recognized one.
Score maturity, not just presence
For each control, rate design and operating effectiveness separately. A control that exists on paper but is not measured cannot be defended in an audit.
Translate gaps into a prioritized roadmap
Convert findings into a multi-year remediation plan with owners, budget envelopes and quarterly milestones tied to risk reduction rather than project completion.
Implement an all-hazards, proportionate risk approach
NIS 2 requires an all-hazards approach proportionate to your risk exposure, your size, and the likelihood and severity of incidents. Risk management is the connective tissue between governance and controls.
Maintain an asset and service inventory
Catalog the essential and important services in scope, the supporting systems and data, and their dependencies on third parties, including cloud providers and managed service providers.
Operate a documented risk assessment cycle
Identify, analyze, evaluate and treat risks at least annually and after major change. Tie residual risk acceptance to the responsible member of the management body.
Manage supply chain risk explicitly
Assess the cybersecurity practices of direct suppliers and service providers. Contractually require security obligations, incident notification and right-to-audit for critical vendors.
Test the effectiveness of measures
Run penetration tests, tabletop exercises and disaster-recovery rehearsals. Article 21(2)(f) requires policies and procedures to assess effectiveness, not merely to have measures in place.
Meet the 24-hour, 72-hour and one-month deadlines
Reporting is where most organizations are caught off guard. NIS 2 mandates a layered notification timeline to the CSIRT or competent authority, so your incident response playbook has to be wired for these clocks from day one.
Submit an early warning within 24 hours
Notify the CSIRT or competent authority within 24 hours of becoming aware of a significant incident, indicating whether it is suspected to be caused by unlawful or malicious acts or could have cross-border impact.
File an incident notification within 72 hours
Update the initial notification with an assessment of the incident, including severity and impact, and where available, indicators of compromise.
Deliver a final report within one month
Provide a detailed description of the incident, its severity and impact, the type of threat or root cause, applied and ongoing mitigations, and any cross-border impact.
Define your significant-incident triggers in advance
Pre-agree the operational thresholds, such as financial loss, downtime, affected users and data categories, that trigger the reporting workflow, so on-call teams escalate without hesitating.
Embed continuous improvement and audit readiness
Compliance is a steady state, not a milestone. Build the operating rhythm that keeps evidence current and lets you face a supervisory audit without a fire drill.
Run continuous awareness and cyber hygiene programs
Deliver role-based training, phishing exercises and secure-development practices. Track completion and effectiveness metrics, not just attendance.
Keep evidence audit-ready
Centralize policies, risk registers, board minutes, training records, incident logs and test results in a single evidence repository mapped to the Article 21 controls.
Review and update annually
Reassess the policy set, the risk landscape and the supplier register at least once a year and after material change. Document the review decision.
Rehearse the supervisory interaction
Run mock inspections covering on-site audits, requests for evidence and management interviews. Authorities can issue binding instructions and administrative fines, so preparation is itself a control.
NIS 2 questions teams ask first
Who must comply with NIS 2?
Medium and large entities across 18 sectors, classified as essential or important. These include energy, transport, banking, health, digital infrastructure, public administration, managed service providers, food, manufacturing, postal services, waste management, chemicals and research. Smaller entities can also be in scope where a Member State designates them.
What is the deadline for NIS 2 compliance?
The transposition deadline for Member States was 17 October 2024. Belgium transposed NIS 2 through the law of 26 April 2024, in force from 18 October 2024. Several Member States were late, so the national law that applies to you, and the date it started applying, depend on where you are established.
How does NIS 2 differ from ISO 27001 or CyberFundamentals?
NIS 2 is a legal obligation. ISO 27001 and CyberFundamentals are frameworks you can adopt to meet it. In Belgium, CyberFundamentals maps directly onto the Article 21 measures and is the route the CCB verifies against.
What training is required under NIS 2?
Article 20 requires members of the management body to follow training sufficient to identify risks and assess cybersecurity practices. Article 21(2)(g) extends a similar obligation to staff through ongoing cyber hygiene and security awareness programs.
Get clarity on your cyber risk
In one session, we identify your top risks and what to do next.
- No generic advice
- No technical overload
- Direct executive insight
For IT leaders, CISOs, and management teams at European organizations. Complimentary — no commitment.