NIS2 in 3 sentences

NIS2 is the EU cybersecurity law. It requires essential and important entities to prove control over their ICT supply chain. Managed service providers face personal management bans and fines up to EUR 10 million or 2 percent of turnover.

  • NIS2 scope: Essential entities include managed service providers and managed security service providers under Annex I sector 9
  • Management liability: Article 20 makes management bodies personally liable for cybersecurity risk management failures
  • The fix: Own your infrastructure. Remove external provider dependencies from your critical ICT supply chain

Note: This is a simplified checklist. Refer to the official NIS2 Directive (EU) 2022/2555 for full requirements. Consult legal counsel for compliance advice.

NIS2 cybersecurity checklist

Check each item that applies to your ICT supply chain. NIS2 requires documented control over critical systems and supply chain security.

Cybersecurity gap assessment
Not Started
0 of 8 answered
NIS2 cybersecurity requirements
Does your management body approve and oversee cybersecurity risk management measures?NIS2 Article 20
Article 20 makes your management body personally liable for cybersecurity risk management. If you are an MSSP or managed service provider under NIS2 Annex I sector 9, your board must approve measures and oversee implementation. One failure means your name is on the enforcement notice. NIS2 Article 32(6) can ban you from acting as a manager.
Do you have documented supply chain security measures for every direct ICT provider?NIS2 Article 21
Article 21 requires supply chain security measures. Your managed service provider does not provide them. Their standard contract does not cover NIS2 requirements. You signed their terms. You inherited the gap. Your auditor will find it.
Can you report significant incidents within 24 hours to the competent authority?NIS2 Article 23
Article 23 requires incident reporting within 24 hours. Your provider does not meet this timeline. You are liable for their failure. Your supervisory authority will ask for your incident records. You will not have them.
Do you control your own business continuity and disaster recovery measures?NIS2 Article 21
Article 21 requires business continuity and disaster recovery measures. Your provider runs your systems. You do not control the backup strategy. You do not control the recovery time objective. Your continuity plan is their plan. That is not enough.
Can you prove to the competent authority that you control your own ICT systems?NIS2 Article 32
Article 32 gives competent authorities powers to suspend certifications and ban CEOs from management. Your provider holds your certification. You cannot show the authority that you control your own systems. Your CEO is exposed.
Do you maintain an asset inventory and control access policies for all critical ICT systems?NIS2 Article 21
Article 21 requires access control policies and asset management. Your provider manages access to your systems. You do not have an asset inventory. You do not control the access policy. Your regulator will ask who has access. You will point at a third party.
Are you prepared for administrative fines up to EUR 10 million or 2 percent of turnover?NIS2 Article 34
Article 34 sets fines up to EUR 10 million or 2 percent of worldwide turnover for essential entities. Your provider is the weak link. Their failure is your failure. Your board signed the contract. Your board takes the fine.
Do you enforce multi-factor authentication and secured communications on infrastructure you own?NIS2 Article 21
Article 21 requires multi-factor authentication and secured communications. Your provider enforces these controls. You do not own the policy. You do not own the implementation. You cannot show the regulator that your critical communications are independently secured.
Why your board needs to see this
Your CEO can be banned

NIS2 says your CEO and board are personally on the hook for cybersecurity. If you fail, regulators can ban your CEO from running any company. Your name goes on the public notice.

Your cloud contract is the gap

NIS2 says you must control every ICT provider you use. If you rent your systems from a big cloud company, they will not change their contract for you. That is a compliance gap you cannot close.

Fine: EUR 10M or 2%

NIS2 fines go up to EUR 10 million or 2% of your global turnover. Your cloud provider is the weak link. Their failure is your fine.

If you are an MSSP or managed service provider under NIS2 Annex I sector 9, this applies to you today. If you serve regulated clients, DORA Article 28 and Article 30 contractual flow-down catches you too. Check your DORA exposure.

Worried about NIS2, DORA, AI Act or GDPR?

These regulations ask the same question. Who controls the systems you depend on. Our sovereign platform gives you the answer. You.

GDPR Checklist Your DORA Register AI Act Checklist

No sales pressure. A clear look at your numbers, your dependencies, and your options.