NIS2 implementation checklist: 
EU core requirements

The NIS2 directive sets the baseline, the new bare minimum, for cybersecurity resilience across the EU. If you’re an essential or important entity, that means strict operational requirements you can’t negotiate your way out of.

We’ve taken the legal text of the NIS2 directive and turned it into something you can actually work with — a project plan, not a wall of legalese. This gives you a preliminary framework that works across EU jurisdictions, so you don’t miss the essentials while you’re busy sorting out country-specific details.

    Download checklist

    Fill out the form below to receive your free, downloadable checklist.

    Please be informed that when you click Download PDF, Innowise will process your personal data in accordance with our Datenschutzerklärung um Ihnen die gewünschten Informationen zukommen zu lassen.

    Why NIS2 compliance is critical

    Depending on your classification, messing up NIS2 compliance can be costly. Management can also be held personally liable. The directive defines two tiers of maximum fines:

    For essential entities

    ≥ €10 million

    or 2 percent of your global annual turnover, whichever is higher

    For important entities

    ≥ €7 million

    or 1.4 percent of global annual turnover, whichever is higher

    Who this checklist is for

    • Management boards and directors
    • CISOs, IT security professionals, and IT managers
    • Compliance, risk, and legal teams
    • Operations executives within regulated industries
    • Data protection officers and privacy leads

    What NIS2 implementation checklist helps you do

    What you’ll assess using this checklist

    01

    Self-identification

    02

    Regulatory registration

    03

    Governance and accountability

    04

    ISMS and security measures

    05

    Incident reporting workflow

    06

    Communication obligations

    07

    Audit readiness

    08

    Gaps and priorities

    Important note on national implementation

    This checklist covers what’s consistent across the EU, but each Member State has its own implementing law. Use this as your foundation, then layer on the country-specific stuff for each jurisdiction you operate in.

    If you’d rather not figure it out alone, Innowise is here to help you understand where you stand with NIS2

      arrow