Skip to content

    Executive guide

    A practical NIS 2 checklist for European essential and important entities

    Five phases and twenty concrete actions, from scoping and gap analysis to risk management, incident reporting deadlines and steady-state audit readiness. Built from real engagements running NIS 2 and CyberFundamentals programs across European organizations.

    Book your 30-min risk session
    Phase 01 · Scope and governance

    Confirm whether NIS 2 applies and set the governance baseline

    Before any technical work, establish whether you are in scope as an essential or important entity, and put accountable governance in place. The directive holds management personally responsible, so board awareness is a prerequisite rather than an afterthought.

    • Determine NIS 2 applicability

      Map your sector under Annexes I and II, your headcount and your turnover against the size-cap rule. Document the decision in writing, including subsidiaries and EU establishments.

    • Register with the national competent authority

      In Belgium this is the CCB. Deadlines and registration portals differ per Member State. Track the legal entity, sector and contact details that must be kept current.

    • Assign accountable management

      Name a board-level owner for cybersecurity risk. Approve the cybersecurity policy at management level and minute the decision, because supervisory authorities will ask for evidence.

    • Provide management training

      Deliver recurring NIS 2 training to the management body so they can identify and assess risks and the impact of cybersecurity measures on the services provided.

    Phase 02 · Gap analysis

    Run a structured gap analysis against the Article 21 measures

    Article 21 lists the ten minimum cybersecurity risk-management measures. A gap analysis turns the legal text into a measurable baseline, so you can prioritize remediation by risk rather than by appetite.

    • Map current controls to the ten Article 21 domains

      Cover risk analysis and policies, incident handling, business continuity, supply chain, secure acquisition, effectiveness assessment, basic cyber hygiene and training, cryptography, human-resources security and access control, and multi-factor authentication.

    • Benchmark against an established framework

      Use CyberFundamentals in Belgium, ISO/IEC 27001, or NIST CSF 2.0 as the operating model. NIS 2 does not prescribe a framework, but supervisory authorities expect a recognized one.

    • Score maturity, not just presence

      For each control, rate design and operating effectiveness separately. A control that exists on paper but is not measured cannot be defended in an audit.

    • Translate gaps into a prioritized roadmap

      Convert findings into a multi-year remediation plan with owners, budget envelopes and quarterly milestones tied to risk reduction rather than project completion.

    Phase 03 · Risk management

    Implement an all-hazards, proportionate risk approach

    NIS 2 requires an all-hazards approach proportionate to your risk exposure, your size, and the likelihood and severity of incidents. Risk management is the connective tissue between governance and controls.

    • Maintain an asset and service inventory

      Catalog the essential and important services in scope, the supporting systems and data, and their dependencies on third parties, including cloud providers and managed service providers.

    • Operate a documented risk assessment cycle

      Identify, analyze, evaluate and treat risks at least annually and after major change. Tie residual risk acceptance to the responsible member of the management body.

    • Manage supply chain risk explicitly

      Assess the cybersecurity practices of direct suppliers and service providers. Contractually require security obligations, incident notification and right-to-audit for critical vendors.

    • Test the effectiveness of measures

      Run penetration tests, tabletop exercises and disaster-recovery rehearsals. Article 21(2)(f) requires policies and procedures to assess effectiveness, not merely to have measures in place.

    Phase 04 · Incident reporting

    Meet the 24-hour, 72-hour and one-month deadlines

    Reporting is where most organizations are caught off guard. NIS 2 mandates a layered notification timeline to the CSIRT or competent authority, so your incident response playbook has to be wired for these clocks from day one.

    • Submit an early warning within 24 hours

      Notify the CSIRT or competent authority within 24 hours of becoming aware of a significant incident, indicating whether it is suspected to be caused by unlawful or malicious acts or could have cross-border impact.

    • File an incident notification within 72 hours

      Update the initial notification with an assessment of the incident, including severity and impact, and where available, indicators of compromise.

    • Deliver a final report within one month

      Provide a detailed description of the incident, its severity and impact, the type of threat or root cause, applied and ongoing mitigations, and any cross-border impact.

    • Define your significant-incident triggers in advance

      Pre-agree the operational thresholds, such as financial loss, downtime, affected users and data categories, that trigger the reporting workflow, so on-call teams escalate without hesitating.

    Phase 05 · Operate and improve

    Embed continuous improvement and audit readiness

    Compliance is a steady state, not a milestone. Build the operating rhythm that keeps evidence current and lets you face a supervisory audit without a fire drill.

    • Run continuous awareness and cyber hygiene programs

      Deliver role-based training, phishing exercises and secure-development practices. Track completion and effectiveness metrics, not just attendance.

    • Keep evidence audit-ready

      Centralize policies, risk registers, board minutes, training records, incident logs and test results in a single evidence repository mapped to the Article 21 controls.

    • Review and update annually

      Reassess the policy set, the risk landscape and the supplier register at least once a year and after material change. Document the review decision.

    • Rehearse the supervisory interaction

      Run mock inspections covering on-site audits, requests for evidence and management interviews. Authorities can issue binding instructions and administrative fines, so preparation is itself a control.

    Frequently asked

    NIS 2 questions teams ask first

    Who must comply with NIS 2?

    Medium and large entities across 18 sectors, classified as essential or important. These include energy, transport, banking, health, digital infrastructure, public administration, managed service providers, food, manufacturing, postal services, waste management, chemicals and research. Smaller entities can also be in scope where a Member State designates them.

    What is the deadline for NIS 2 compliance?

    The transposition deadline for Member States was 17 October 2024. Belgium transposed NIS 2 through the law of 26 April 2024, in force from 18 October 2024. Several Member States were late, so the national law that applies to you, and the date it started applying, depend on where you are established.

    How does NIS 2 differ from ISO 27001 or CyberFundamentals?

    NIS 2 is a legal obligation. ISO 27001 and CyberFundamentals are frameworks you can adopt to meet it. In Belgium, CyberFundamentals maps directly onto the Article 21 measures and is the route the CCB verifies against.

    What training is required under NIS 2?

    Article 20 requires members of the management body to follow training sufficient to identify risks and assess cybersecurity practices. Article 21(2)(g) extends a similar obligation to staff through ongoing cyber hygiene and security awareness programs.

    Get clarity on your cyber risk

    In one session, we identify your top risks and what to do next.

    • No generic advice
    • No technical overload
    • Direct executive insight
    Book your 30-min risk session

    For IT leaders, CISOs, and management teams at European organizations. Complimentary — no commitment.

    Book your 30-min risk session