- Technical and methodological Article 21 requirements for specified digital infrastructure, ICT service management, digital provider, and trust service entities.
"technical and methodological requirements"
A practical NIS2 checklist for confirming whether an entity is in scope, how it is classified, which governance and cybersecurity measures apply, and what evidence should be ready.
Based on Directive (EU) 2022/2555, Commission implementation material, Implementing Regulation (EU) 2024/2690, and ENISA technical implementation guidance.
Structured answer sets in this page tree.
Cited legal and guidance references.
Use this checklist only after identifying the legal entity and service. First determine whether the entity is outside scope or belongs to the defined by Article 3, and retain the Annex mapping, size or special-case route, Member State basis, and classification evidence. The remaining checks give legal, security, compliance, risk, operations, and management teams verifiable conditions, owners, and evidence for governance, Article 21 measures, Article 23 reporting, national implementation, and reassessment.
Start with the legal scope test. NIS2 generally applies to public or private entities of a type listed in Annex I or Annex II that are medium-sized or larger and provide services or carry out activities in the Union. Article 2 also contains specific size-independent cases.
Do not treat sector labels as enough on their own. The checklist record should identify the entity, service, Member States, Annex sector or subsector, size-rule conclusion, and any special scope trigger or exclusion.
After scope, classify the entity as essential or important. This drives supervision and enforcement handling, so the classification should be traceable to Article 3 rather than copied from an internal risk tier.
Keep registration information ready because Member States must maintain lists of and entities providing domain name registration services. Specified digital and ICT providers also have a separate Article 27 registry path. National mechanisms determine how information is submitted.
NIS2 compliance is not only a security-team task. Article 20 requires management bodies of to approve cybersecurity risk-management measures, oversee implementation, and follow training.
The checklist should therefore include governance evidence that links board or executive approval to the Article 21 measure set and to the services affected by NIS2.
Article 21 requires appropriate and proportionate technical, operational, and organisational measures to manage risks to network and information systems and to prevent or minimise incident impact.
Use one checklist row per measure family. Each row should show the risk it addresses, the control owner, implementation status, evidence, exceptions, review date, and management approval where needed.
The checklist should make incident reporting operational before an incident occurs. Article 23 requires notification of significant incidents to the CSIRT or competent authority and sets staged reporting points tied to awareness of the significant incident.
Keep authority reporting separate from recipient communications, law-enforcement escalation, public disclosure, and sector-specific reporting. Where appropriate, Article 23 requires recipient notice when a significant incident is likely to adversely affect the service and, where applicable, practical measures or remedies for recipients potentially affected by a significant cyber threat.
Close the review only when each conclusion has a cited reason and each action has an owner and evidence. The file should align scope, classification, Article 4 overlap, jurisdiction, registration, governance, controls, incident reporting, and national implementation.
Reopen the checklist when business facts change, not only on an annual calendar. New services, Member States, suppliers, infrastructure, incidents, acquisitions, or national transposition changes can alter the file.
Sorena can help convert this checklist into a cited NIS2 scope memo, Article 21 control matrix, Article 23 reporting workflow, and management-body evidence pack.
Ask questions tied to cited sources about NIS2 scope, Article 21 measures, Article 23 reporting, and implementation evidence using the cited sources on this page.
Review your NIS2 checklist, source gaps, control evidence, and incident-reporting workflow with Sorena.
"technical and methodological requirements"
"high common level of cybersecurity across the Union"
"referred to in Annex I or II"
"approve the cybersecurity risk-management measures"
"appropriate and proportionate technical, operational and organisational measures"
"within 72 hours"
"Essential and important entities"
"all necessary, appropriate and proportionate corrective measures"
"planned intervals"
"The early warning should be followed by an incident notification"
"essential and important entities"