Skip to content
NIS2 › NIS2 Compliance

NIS2 implementation guide: 12 steps from requirements to compliance

A free, ungated NIS2 implementation guide with deliverables for every step, the ten minimum requirements, reporting deadlines and a complete NIS2 compliance checklist.

NIS2 implementation roadmap: a path rising through four milestones for documentation, people, security measures and continuous review to a finish flag

Table of Contents

    Most organisations covered by NIS2 already know they have to act. What they're missing is a plan that turns the legal text into work: who signs off what, which documents the supervisory authority will ask for, and what has to happen in the first 24 hours when something goes wrong.

    This NIS2 implementation guide gives you that plan. It splits the work into 12 steps, links each step to the requirements in the NIS2 Directive and lists the deliverables each step should produce. Every step ends with a checklist that separates what the law requires from what the authorities recommend.

    The guide is free, with no form to fill in. The complete NIS2 compliance checklist is at the end, ready to copy into a spreadsheet or your GRC tool. We use Denmark as the worked example because the Danish authorities have published unusually detailed guidance, but the steps work in any EU member state. If you're new to the directive, start with our introduction to NIS2.

    The short answer: what NIS2 implementation involves

    NIS2 compliance means meeting four sets of obligations. You register with the authorities. You put appropriate and proportionate cybersecurity risk-management measures in place, built around the ten minimum measures in Article 21. You report significant incidents within 24 hours, 72 hours and one month under Article 23. And your management body approves and oversees the measures under Article 20.

    In practice that's a programme of twelve steps that typically takes 6 to 12 months for a mid-sized organisation without a mature information security management system. Order matters. Scope and registration come first because they carry legal deadlines and decide who supervises you. Governance comes next because the law puts management on the hook. The ten measures follow. And the work doesn't end, because Article 21 also requires you to assess whether your measures are effective.

    Important: the obligations apply whether or not you've registered. Skipping registration doesn't take you out of scope. It just adds a second breach.

    The four core NIS2 obligations shown as connected cards: registration, cybersecurity risk-management measures, incident reporting and management approval

    NIS2 at a glance: law, deadlines and fines

    The directive sets the same core obligations everywhere. Registration portals, authorities and penalty procedures are national. Here's how it looks in Denmark.

    Topic What applies Source
    Legal basis Directive (EU) 2022/2555. Implemented in Denmark by the NIS2 Act, Act no. 434 of 6 May 2025 Danish NIS2 Act
    In force 1 July 2025 in Denmark Section 33(1)
    Registration On virk.dk. Deadline 1 October 2025 for entities in scope at entry into force, otherwise two weeks after coming into scope Sections 10 and 33(3)
    Incident reporting Early warning within 24 hours, notification within 72 hours, final report within one month Article 23, section 13
    Management Approve measures, oversee implementation, attend training Article 20, section 7
    Fines in Denmark Criminal fines set by the courts. The explanatory notes to the bill indicate a maximum of EUR 10 million or 2% of global turnover for essential entities and EUR 7 million or 1.4% for important entities, whichever is higher Bill L 141, explanatory notes
    Supervision Proactive for essential entities (audits, inspections). Reactive for important entities Sections 21 and 24

    Denmark has no administrative fines, so NIS2 penalties go through the criminal courts. The figures above are maximums described in the bill's explanatory notes rather than amounts written into the act, and there's no case law yet. Treat them as ceilings, not price tags.

    Outside Denmark: check your national transposition law and your competent authority's website before you copy any deadline from this table. The European Commission keeps an overview on its NIS2 policy page.

    The 10 NIS2 requirements in Article 21

    Article 21(2) lists ten minimum measures. In the Danish act they appear in section 6(1). The table shows the core requirement for each measure according to SAMSIK's guidance, the ISO/IEC 27001:2022 references the guidance points to, and the step in this guide where you deal with it.

    # NIS2 requirement Core must-do ISO 27001:2022 Step
    1 Risk analysis and information system security policies Approved security policy, documented risk assessments, accepted residual risk 6.1-6.2, 8.2-8.3, A.5.1 6, 7
    2 Incident handling Approved procedures to detect, analyse, respond and report. Protected logs A.5.24, A.8.15-8.16 9
    3 Business continuity, backup, disaster recovery, crisis management Risk-based continuity procedures, backup including configuration A.5.29-5.30, A.8.13-8.14 10
    4 Supply chain security Supplier procedures, risk per supplier, agreements A.5.19-5.21 8
    5 Security in acquisition, development and maintenance, including vulnerability handling Documented procedures and vulnerability handling A.8.8, A.8.25-8.32 7
    6 Assessing the effectiveness of measures Policy for continuous assessment, risk-based testing 9.1, 9.3, A.8.34 12
    7 Cyber hygiene and training Basic hygiene, training policy 7.2-7.3, A.6.3 11
    8 Cryptography and encryption Policy matching state of the art A.8.24 7
    9 HR security, access control and asset management Access control including privileged rights, asset management A.5.9-5.18, A.6.1-6.7 4, 7
    10 MFA, secured communication, emergency communication MFA where relevant with periodic review A.5.17, A.8.5 7, 10

    The ISO mapping helps you reuse work, but it isn't equivalence. ENISA says so explicitly about its own mapping, and SAMSIK writes that following a standard is no guarantee you meet the requirements. An ISO 27001 certificate won't cover the reporting deadlines, registration, documented management training, customer notification or the all-hazards and societal-impact perspective. Our comparison of NIS2 and ISO 27001 goes through the gaps in detail.

    The official guidance worth reading

    If you want primary sources rather than vendor summaries, these are the documents to read. SAMSIK (the Danish Agency for Civil Protection and Emergency Management) has published four cross-sector guides and one for municipalities. They're in Danish, but they're the most concrete NIS2 implementation guidance any EU authority has released so far.

    Guidance Published What you'll use it for
    SAMSIK: scope 2025 Scope, size criteria, jurisdiction and supplier relationships
    SAMSIK: management's role and duties May 2025 Approval, oversight, training, delegation and personal sanctions
    SAMSIK: implementing cybersecurity measures June 2025 The ten measures with must, should and may levels and standard references
    SAMSIK: incident reporting June 2025 Significance criteria, examples, decision tree and report content
    SAMSIK: guidance for municipalities July 2025 Municipal context, including home care and outsourced services
    ENISA Technical Implementation Guidance June 2025 Implementation advice, evidence examples and framework mapping
    Implementing Regulation (EU) 2024/2690 In force 7 November 2024 Binding technical requirements for digital providers, and a benchmark for everyone else

    SAMSIK's measures guidance uses three levels. Must is a requirement you have to be able to document. Should is a recommendation, and if you don't follow it you must be able to explain why, with reference to the state of the art, cost and risk. May is an example of a possible solution. The checklists below use the same labels.

    NIS2 implementation in 12 steps

    Each step follows the same pattern: what the law asks, what the guidance adds, the deliverables you should end up with and a checklist marked Must or Should.

    Step What you do Deliverable
    1 Confirm scope and category Scope assessment memo
    2 Register with the authorities Registration receipt and change procedure
    3 Anchor with the management body Board resolution, RACI, training records
    4 Map services, systems and dependencies Service list, asset register, dependency map
    5 Gap analysis against Article 21 Gap report and approved action plan
    6 Assess and treat risks Risk policy, register, treatment plan
    7 Policies and technical measures Policy set, MFA, logging, patching
    8 Supply chain security Supplier tiers, assessments, contract clauses
    9 Incident handling and reporting Procedure, thresholds, report templates
    10 Continuity and crisis management Continuity plan, tested backups, crisis plan
    11 Training and cyber hygiene Training policy and records
    12 Effectiveness and audit readiness Test programme, review, evidence folder

    Step 1: Confirm whether you're in scope, and as what

    Start by writing down why you are, or aren't, covered. NIS2 applies to public and private entities of a type listed in Annex I (sectors of high criticality) or Annex II (other critical sectors) of the directive. Size decides the category in most cases.

    • Essential entities are Annex I entities with at least 250 employees, or with annual turnover above EUR 50 million and a balance sheet above EUR 43 million.
    • Important entities are Annex I or II entities with at least 50 employees, or with turnover and balance sheet both above EUR 10 million, that aren't essential.
    • Some entities are covered regardless of size, for example qualified trust service providers, top-level domain registries, DNS service providers, central government bodies and entities designated as critical under the CER Directive.

    Count employees and financials using the EU SME definition, which means partner and linked enterprises in your group count too. That's where many scope assessments go wrong. A 40-person subsidiary of a 600-person group is rarely a small company in NIS2 terms.

    Deliverable: a scope assessment memo stating sector, sub-sector, size, category (essential or important), competent authority, any sector-specific law and the services and systems in scope. Keep it on file. It's the first thing a supervisory authority will ask for.

    • ☐ [Must] Match your activities to Annex I or II, down to sub-sector level
    • ☐ [Must] Calculate size under the SME definition, including partner and linked enterprises
    • ☐ [Must] Check the size-independent rules (Article 2(2)-(4) of the directive, section 4(3) of the Danish act)
    • ☐ [Must] Identify your competent authority (in Denmark, see SAMSIK's list of sector authorities)
    • ☐ [Should] Check whether sector-specific law takes precedence, such as DORA for financial entities or national energy and telecoms rules
    • ☐ [Should] Use an official self-assessment tool where one exists (Denmark has NIS 2-tjek)
    • ☐ [Should] Have legal or compliance sign off the conclusion

    Step 2: Register with the authorities

    Registration is a legal deadline, so it comes early. In Denmark you register through a digital form on virk.dk using MitID Erhverv, and the form is routed automatically to your sector authority. Entities in scope when the Danish act took effect had to register by 1 October 2025. An entity that comes into scope later has two weeks.

    Have this information ready before you open the form: legal name, address and contact details (email, phone and your public IP address ranges), sector and sub-sector, the EU member states where you provide services, and your size and turnover. Digital providers such as cloud, data centre and managed service providers must also give their places of business and any EU representative.

    Changes must be reported within two weeks under section 10(3) of the Danish act. The virk.dk introduction page mentions three months, but that's the deadline for the digital providers in section 9. Plan for two weeks.

    Deliverable: registration receipt, the authority's confirmation of your category, and a named owner who updates the registration when something changes.

    • ☐ [Must] Get MitID Erhverv (or your national equivalent) in place
    • ☐ [Must] Collect name, address, contacts, public IP ranges, sector, member states and size data
    • ☐ [Must] Submit the registration and save the receipt
    • ☐ [Must] Report changes within two weeks
    • ☐ [Should] Name an owner for the registration and add an annual check to your compliance calendar

    Step 3: Anchor NIS2 with the management body

    Article 20 of the directive, section 7 of the Danish act, gives the management body three duties. It must approve the cybersecurity risk-management measures, oversee their implementation and attend training. If you have both a board and an executive board, the management body is the board. In public authorities it's the top administrative management.

    SAMSIK's guidance on management's role and duties adds useful detail. The board can delegate work to a committee, but it keeps collective responsibility. Training has no prescribed format or content, and not every member needs a course, but the board as a whole must have the necessary skills and you must be able to document the training. For oversight, the guidance suggests a half-yearly management report with status on objectives, action plans and KPIs, such as the number of significant incidents and target times for fixing critical vulnerabilities.

    For essential entities there's a personal sanction too. The authority can, as a last resort, temporarily ban a person at CEO level from management functions. It doesn't apply to public authorities.

    Deliverables: board resolution with minutes, programme mandate, RACI, named risk owners, reporting cadence and training records. Read more in our article on NIS2 training requirements.

    • ☐ [Must] Identify who your management body is
    • ☐ [Must] Have the management body approve the NIS2 programme and the measures, and minute it
    • ☐ [Must] Run management training and keep the certificates or attendance records
    • ☐ [Should] Set up a fixed management report, for example every six months, with KPIs
    • ☐ [Should] If you delegate to a committee, document how the board oversees the committee

    Step 4: Map services, systems and dependencies

    NIS2 protects the network and information systems that support the services you provide in your sector. That includes operational technology (OT) and IoT, not just office IT. It's also not necessarily the same scope as your ISO 27001 certificate.

    SAMSIK's measures guidance treats asset management as a must, while the asset inventory itself is listed as an example (a 'may'). In practice you can't assess risk or prioritise patching without one, so build it.

    Deliverables: list of in-scope services, asset register with owners, classification by confidentiality, integrity and availability, and a dependency map that shows which suppliers and systems each critical service relies on.

    • ☐ [Must] List the services that make you an in-scope entity
    • ☐ [Must] Define how assets are managed throughout their lifecycle
    • ☐ [Should] Map systems, data, locations and OT components behind each service
    • ☐ [Should] Classify assets and name an owner for each
    • ☐ [Should] Record dependencies on external suppliers and cloud services

    Step 5: Run a gap analysis against Article 21

    Now compare what you have with what the ten minimum measures require. Do it measure by measure and requirement by requirement. SAMSIK's measures guidance is the most practical benchmark available because it marks every point as must, should or may. Two other tools help: ENISA's NIS2 Technical Implementation Guidance (June 2025), which includes a mapping to ISO 27001, NIST CSF 2.0 and other frameworks, and the questionnaire SAMSIK published for its 2026 supervision of Danish municipalities, which shows what an authority actually asks.

    Every 'should' you decide not to follow needs a documented reason, based on the state of the art, cost and risk. That rule turns the gap analysis into evidence rather than a to-do list.

    Deliverable: gap report per measure with status (met, partly met, not met), existing evidence, owner and priority, plus a management-approved action plan.

    • ☐ [Must] Assess every must requirement as met, partly met or not met
    • ☐ [Must] Document the reasoning for any should recommendation you don't follow
    • ☐ [Should] Map existing ISO 27001 or NIST CSF evidence to each measure
    • ☐ [Should] Prioritise gaps by risk and get the action plan approved by management

    Step 6: Assess and treat risks

    Article 21 builds on risk assessment. Two things make the NIS2 version different from a typical ISO 27001 assessment. It takes an all-hazards approach, so physical events, power failures and human error count alongside cyberattacks. And it looks at harm to others, meaning your customers and society, not only at your own risk appetite.

    SAMSIK requires a risk management policy approved by relevant management, documented risk assessments and formal acceptance of residual risk by the risk owner. Our NIS2 risk assessment guide walks through the method step by step, and the risk assessment matrix article covers scoring.

    Deliverables: risk management policy, risk register, risk treatment plan and signed acceptance of residual risk.

    • ☐ [Must] Adopt a risk management policy approved by relevant management
    • ☐ [Must] Carry out and document risk assessments
    • ☐ [Must] Have risk owners accept residual risk
    • ☐ [Should] Include physical, environmental and human threats, not just cyber
    • ☐ [Should] Include impact on customers and society in the consequence scale
    • ☐ [Should] Use your national threat assessment for your sector as input

    Step 7: Put policies and technical measures in place

    This is the longest step and where most of the budget goes. It covers measures 1, 5, 7, 8, 9 and 10 in Article 21. The core documents are an information security policy approved by the management body, an access control policy covering privileged rights, a cryptography policy that matches the state of the art and procedures for acquisition, development, maintenance and disposal of systems.

    On the technical side, SAMSIK requires multi-factor or continuous authentication where relevant, with a periodic, documented review of where it's used. Logs must be kept, reviewed and protected against tampering. Vulnerabilities must be identified, assessed and handled through a defined procedure.

    Worth knowing: several measures people assume are mandatory are only recommendations or examples in SAMSIK's guidance. That includes testing backups, the detailed content and yearly update of the security policy, contract clauses with suppliers, the asset inventory, vulnerability scanning and background checks. Don't skip them. Supervisors will expect you to follow them or explain why not.

    Deliverables: approved policy set, cyber hygiene baseline, MFA rollout and review log, patch and vulnerability procedure, logging set-up and joiner, mover and leaver process.

    • ☐ [Must] Information security policy approved by the management body
    • ☐ [Must] Access control policy including privileged accounts
    • ☐ [Must] Cryptography policy and procedures matching the state of the art
    • ☐ [Must] Procedures for vulnerability handling and secure acquisition, development and disposal
    • ☐ [Must] MFA or continuous authentication where relevant, with periodic documented review
    • ☐ [Must] Logs kept, reviewed and protected against tampering
    • ☐ [Should] Review the security policy at least once a year

    Step 8: Secure your supply chain

    Measure 4 covers supply chain security, and it's where NIS2 reaches organisations that aren't in scope themselves. You must have procedures for managing direct suppliers, assess the risk each one poses and make agreements that make your requirements stick. SAMSIK's scope guidance confirms that suppliers outside NIS2 can expect proportionate requirements from customers who are inside it.

    Two practical points get missed. First, your suppliers must alert you fast enough for you to meet your own 24-hour deadline, so the incident clause in the contract needs a time limit. Second, if a supplier runs your systems and reports incidents on your behalf, the responsibility for reporting on time still sits with you. Our article on vendor audits covers how to follow up.

    Deliverables: supplier list with criticality tiers, risk assessment per critical supplier, standard security clauses (requirements, incident notification, audit rights, exit) and a follow-up plan.

    • ☐ [Must] Procedures for supplier management covering direct suppliers
    • ☐ [Must] Risk assessment of each relevant supplier
    • ☐ [Must] Agreements that secure your security requirements
    • ☐ [Should] Tier suppliers by criticality and set proportionate requirements
    • ☐ [Should] Require incident notification within a fixed number of hours
    • ☐ [Should] Agree who reports if operations are outsourced, knowing that responsibility stays with you

    Step 9: Build incident handling and reporting

    Article 23 sets the reporting clock. An incident is significant if it has caused, or can cause, severe operational disruption or financial loss for you, or considerable material or non-material damage to others.

    Report Deadline Content
    Early warning Within 24 hours of becoming aware Whether the incident is suspected to be caused by unlawful or malicious acts, and whether it could have cross-border impact
    Incident notification Within 72 hours of becoming aware Initial assessment, severity, impact and indicators of compromise where available
    Intermediate report On request from the CSIRT or authority Relevant status updates
    Final report No later than one month after the incident notification Detailed description, root cause, mitigation applied and any cross-border impact. If the incident is still ongoing, send a progress report and the final report within one month of handling it

    SAMSIK's guidance on incident reporting makes the definition usable. It recommends that you set your own objective thresholds, for example for downtime or financial loss. Its example is a loss above 1% of annual turnover, defined in your own risk assessment. Exfiltration of trade secrets is always significant. A threat actor sitting in your systems to cause disruption later should be treated as significant. Planned maintenance isn't reported.

    In Denmark you report once on virk.dk, and the form goes to both your sector authority and the CSIRT. You can tick a box to notify the Danish Data Protection Agency (Datatilsynet) about a personal data breach at the same time. The CSIRT replies within 24 hours of the early warning. You must also notify recipients of your services without undue delay if the incident is likely to affect them. See our article on security breaches for how the NIS2 and GDPR deadlines run side by side.

    Digital providers have fixed thresholds in Implementing Regulation (EU) 2024/2690. A direct financial loss above EUR 500,000 or 5% of turnover, whichever is lower, counts as significant. For managed service providers, complete unavailability for more than 30 minutes does.

    NIS2 incident reporting timeline with 24-hour early warning, 72-hour notification and one-month final report alongside the GDPR 72-hour notification

    Deliverables: approved incident procedure, significance criteria with your own thresholds, decision tree, reporting roles with 24/7 access to the reporting portal, templates for each report, GDPR triage and customer communication.

    • ☐ [Must] Documented, approved procedures to detect, analyse, respond to and report incidents
    • ☐ [Must] Access to the skills needed to judge whether an incident is significant
    • ☐ [Must] Report within 24 hours, 72 hours and one month
    • ☐ [Must] Notify affected service recipients without undue delay
    • ☐ [Should] Set your own thresholds for downtime and financial loss
    • ☐ [Should] Make sure at least two people can file a report around the clock
    • ☐ [Should] Run a tabletop exercise that includes the GDPR track

    Step 10: Plan for business continuity and crisis management

    Measure 3 covers backup, disaster recovery and crisis management. SAMSIK requires continuity procedures based on your risk assessment and backup of all relevant data, including configuration. You must also assess whether you need redundancy and a crisis management plan.

    Testing a restore is formally a 'should', but a backup you've never restored is a hope, not a control. Ransomware is the scenario to test against, so keep at least one copy offline or logically separated.

    Deliverables: continuity plan with recovery time and recovery point objectives for critical services, backup procedure, redundancy assessment, crisis management plan and alternative communication channels.

    • ☐ [Must] Continuity procedures based on the risk assessment
    • ☐ [Must] Backup of all relevant data, including configuration
    • ☐ [Must] Assessment of redundancy needs and a crisis management plan
    • ☐ [Should] Test restores and document the results
    • ☐ [Should] Keep offline or separated backups
    • ☐ [Should] Set up emergency communication that works if email and Teams are down

    Step 11: Train staff and build cyber hygiene

    Measure 7 requires basic cyber hygiene and training. Management training sits in Article 20 and was covered in step 3. For everyone else you need a training policy and a programme that matches roles. IT staff, administrators with privileged access and the people who file incident reports need more than the annual phishing module.

    Our articles on awareness training and NIS2 training requirements cover formats and documentation.

    Deliverables: training policy, role-based training plan, attendance records and a short evaluation of whether the training changed behaviour.

    • ☐ [Must] Basic cyber hygiene practices in place
    • ☐ [Must] Policy for training employees
    • ☐ [Should] Annual training for all staff
    • ☐ [Should] Extra training for IT, privileged users and the reporting team
    • ☐ [Should] Keep training records ready for supervision

    Step 12: Measure effectiveness and stay audit-ready

    Measure 6 requires you to assess whether your measures actually work. SAMSIK asks for a policy and procedures for continuous assessment, a risk-based view of what to test and how often, and acceptance of residual risk by the risk owner. That's what turns a project into a management system.

    Supervision is the other reason. Authorities can ask for documentation at any time. Essential entities face proactive supervision with audits and on-site inspections. Important entities are supervised reactively when there are signs of non-compliance. In 2026 SAMSIK began survey-based supervision of all 98 Danish municipalities, which shows the shift from guidance to control.

    Deliverables: effectiveness policy, test programme (for example vulnerability scanning and penetration tests based on risk), internal or external audit, annual management review and an evidence folder with policies, minutes, logs, training records and registration receipts.

    • ☐ [Must] Policy and procedures for assessing the effectiveness of measures
    • ☐ [Must] Risk-based decision on what to test and how often
    • ☐ [Should] Annual management review and audit
    • ☐ [Should] Evidence folder that can be handed over quickly
    • ☐ [Should] Monitor new national guidance and EU changes, and update the registration

    Worked example: Nordlys Elektronik A/S

    Nordlys Elektronik A/S and its CISO, Mette Holm, are fictional. We invented them for this article.

    Nordlys makes electronic components in Jutland. It has 180 employees, annual turnover of EUR 40 million and a balance sheet of EUR 28 million, with no parent company. Manufacturing of computer, electronic and optical products is in Annex II, so Nordlys is in scope. With more than 50 employees it's an important entity. It's below 250 employees and below the EUR 50 million turnover threshold, so it isn't essential.

    That gives Mette three facts to plan around. SAMSIK is the supervisory authority. Supervision is reactive, so an inspection will usually follow a complaint, an incident or other indications. And the maximum fine indicated in the explanatory notes is EUR 7 million, because 1.4% of EUR 40 million is only EUR 560,000 and the higher figure applies.

    In step 9 Mette sets Nordlys's significance threshold at a financial loss above 1% of turnover, which is EUR 400,000. Here's what happens when ransomware stops production on a Monday morning.

    Time What happens Obligation
    Monday 08:00 Encrypted servers found, production stopped. Expected loss over three days is EUR 600,000 Clock starts. The incident is significant because it's above the threshold
    Tuesday 08:00 at the latest Early warning filed on virk.dk. Malicious act suspected, no cross-border impact known 24-hour early warning
    Tuesday Two customers told their deliveries will be late Notify affected recipients without undue delay
    Thursday 08:00 at the latest Incident notification with initial assessment and indicators of compromise. HR files were on an encrypted server, so the GDPR box is ticked 72-hour notification, plus 72-hour notification to Datatilsynet
    Within one month of Thursday Final report with root cause, mitigation and lessons learned Final report

    The incident went well for one reason. The thresholds, roles and templates existed before Monday. Without them, Mette's team would have spent the first day arguing about whether the incident was significant at all.

    How long does NIS2 implementation take?

    The estimates below are based on experience with mid-sized organisations that don't yet have a mature ISMS. They aren't from any official source. An organisation with ISO 27001 in place can often halve the middle phases.

    Phase Steps Typical duration
    Scope, registration and governance 1-3 2-4 weeks
    Mapping, gap analysis and risk assessment 4-6 1-3 months
    Measures, supply chain, incidents and continuity 7-10 3-9 months, running in parallel
    Training and effectiveness 11-12 Ongoing, with an annual cycle

    Eight common NIS2 misconceptions

    • "We're only a supplier, so it doesn't affect us." Customers in scope must set proportionate requirements for their direct suppliers. Managed service and cloud providers may also be in scope in their own right.
    • "We haven't registered, so we're not covered." The obligations apply regardless, and not registering is a breach in itself.
    • "Our IT provider handles reporting." A provider can file on your behalf, but you're responsible for reporting on time.
    • "Our ISO 27001 certificate is enough." It's a strong foundation, not a guarantee. Deadlines, registration, management training and the societal perspective are missing.
    • "The fine is EUR 10 million no matter what." That's the maximum for essential entities. In Denmark the courts set the actual fine.
    • "Every board member needs a certified course." The board as a whole must have the skills, and training must be documented. No specific course or certificate is required.
    • "We must appoint two security officers." Some guides say so, but it isn't a requirement in the directive or the Danish act.
    • "NIS2 is just about IT." It covers the systems behind your services, including OT, and takes an all-hazards view of risk.

    Free NIS2 compliance checklist

    Here's the full NIS2 requirements checklist in one place, with no form or email required. Copy it into Excel or your GRC tool and assign an owner and a date to each line.

    Scope and registration

    • ☐ [Must] Scope assessed and documented: sector, size, essential or important, sector-specific law
    • ☐ [Must] Competent authority identified
    • ☐ [Must] Registered, receipt saved, changes reported within two weeks

    Management

    • ☐ [Must] Management body identified
    • ☐ [Must] Measures approved by the management body
    • ☐ [Must] Oversight through regular reporting
    • ☐ [Must] Management training completed and documented

    The ten measures

    • ☐ [Must] 1. Security policy and risk management policy, risk register, accepted residual risk
    • ☐ [Must] 2. Incident procedure, logging and monitoring
    • ☐ [Must] 3. Continuity plan, backup, redundancy assessment, crisis management
    • ☐ [Must] 4. Supplier procedure, risk assessment of direct suppliers, agreements
    • ☐ [Must] 5. Secure acquisition, development, maintenance and disposal, vulnerability handling
    • ☐ [Must] 6. Policy and procedures for assessing effectiveness, risk-based testing
    • ☐ [Must] 7. Cyber hygiene baseline and training policy
    • ☐ [Must] 8. Cryptography policy
    • ☐ [Must] 9. HR security, access control including privileged rights, asset management
    • ☐ [Must] 10. MFA where relevant with periodic review, emergency communication assessed

    Reporting

    • ☐ [Must] Significance criteria and own thresholds defined
    • ☐ [Must] Reporting roles and 24/7 portal access in place
    • ☐ [Should] Templates for 24-hour, 72-hour and one-month reports
    • ☐ [Should] GDPR breach track integrated
    • ☐ [Must] Procedure for notifying service recipients

    Follow-up

    • ☐ [Should] Evidence folder ready for supervision
    • ☐ [Should] Annual management review and audit
    • ☐ [Should] New guidance and EU changes monitored

    What's coming: proposed NIS2 changes in 2026 and 2027

    None of the following changes the law today, but they affect how you build your processes.

    • Targeted NIS2 amendments. On 20 January 2026 the Commission proposed changes alongside a revised Cybersecurity Act. They include a new small mid-cap category that would generally be treated as important entities, adjustments to scope and collection of ransomware data. Adoption is expected in late 2026 or 2027 at the earliest.
    • Single reporting entry point. The Digital Omnibus, proposed on 19 November 2025, would create one EU entry point for incident reporting under NIS2, GDPR, DORA and CER. It's still being negotiated.
    • Common reporting templates. The NIS Cooperation Group adopted common templates in May 2026, and the EDPB has consulted on a matching GDPR template.

    The practical takeaway is to build one internal triage process for NIS2, GDPR and DORA now, so you can switch portals later without redesigning anything.

    How .legal supports NIS2 implementation

    Most of the twelve steps produce documents that have to stay connected: risks that point to assets, measures that point to risks, suppliers that point to services, and evidence that points to all of it. That's hard to keep together in spreadsheets once the programme runs for more than a year.

    In .legal's Frameworks module the NIS2 requirements are already mapped, so you can track status per measure, assign tasks and reuse ISO 27001 evidence where it overlaps. Risk management and vendor management cover steps 6 and 8 in the same platform. You can see the NIS2 mapping and risk assessment demo or book a demo to walk through your own case.

    Still have questions?

    Ask Johannes directly. He runs most of our demos personally. Book him here.

    Frequently asked questions about NIS2 implementation

    What is NIS2 compliance?

    NIS2 compliance means that an organisation covered by Directive (EU) 2022/2555 has registered with its national authority, has put the ten minimum cybersecurity risk-management measures in Article 21 in place, can report significant incidents within 24 hours, 72 hours and one month, and has a management body that approves and oversees the measures. There's no certificate. You show compliance through documentation when the authority asks for it.

    Does NIS2 apply to us if we're only a supplier to an in-scope organisation?

    Not directly, unless you're in an Annex I or II sector yourself and meet the size criteria. Managed service providers, cloud providers and data centres often are. If you aren't in scope, you'll still feel NIS2 through your customers, who must assess the risk you pose and set proportionate security requirements in their contracts with you.

    How long does NIS2 implementation take?

    For a mid-sized organisation without a mature ISMS, expect 6 to 12 months to get the core in place. Scope, registration and governance can be done in a few weeks. Policies, technical measures and supplier work take longest. Organisations with ISO 27001 can usually move faster because much of the documentation can be reused.

    Is there a free NIS2 compliance checklist in Excel or PDF?

    Yes. The checklist in this guide is free and ungated, and you can copy it straight into Excel or a GRC tool. It follows the ten measures in Article 21 plus registration, management duties and reporting, and each item is marked as a legal requirement or a recommendation based on the Danish authority's guidance.

    Is ISO 27001 enough for NIS2 compliance?

    No. ISO 27001 covers much of the technical and organisational work, but it doesn't include the 24-hour, 72-hour and one-month reporting deadlines, registration, documented management training or notification of your customers. NIS2 also takes an all-hazards view and looks at harm to society, and your NIS2 scope may be wider than your certified ISO scope.

    What's the difference between essential and important entities?

    Both have the same obligations to implement measures and report incidents. The difference is supervision and fines. Essential entities face proactive supervision with audits and inspections and higher maximum fines. Important entities are supervised reactively, after indications of non-compliance. Category depends mainly on sector and size, with some entities essential regardless of size.

    What happens if we miss the 24-hour early warning?

    Late reporting is a breach of the reporting duty and can be penalised. Report as soon as you can anyway, and document when you became aware of the incident and why the report was delayed. The 24-hour clock runs from when you become aware of a significant incident, which is why pre-agreed thresholds and roles matter so much.

    Do board members need a certified NIS2 course?

    No specific course or certificate is required. The management body must attend training so that, as a group, it has the skills to understand and assess cybersecurity risks and their impact. Not every member needs the same course, but you must be able to document the training, for example with attendance records or course certificates.

    Does Implementing Regulation (EU) 2024/2690 apply to us?

    It applies directly to DNS providers, top-level domain registries, cloud and data centre providers, content delivery networks, managed service and managed security service providers, online marketplaces, search engines, social networks and trust service providers. For other entities it isn't binding, but it's a useful benchmark for what good looks like.

    How does NIS2 interact with GDPR and DORA?

    One incident can trigger both a NIS2 report to the authority and CSIRT and a GDPR notification to the data protection authority, each with its own clock. In Denmark one form on virk.dk can cover both. Financial entities follow DORA instead of NIS2, because DORA is the more specific law, and in Denmark they don't register under the NIS2 Act.

    Still unsure?

    Ask Johannes directly, he runs most demos personally

    Book him here
    Processing activities

    .legal compliance platform

    Run your NIS2 programme in one place

    Turn the twelve steps into tracked work. .legal maps your controls to the ten NIS2 measures, keeps the risk register and supplier assessments current, and gives management the documentation the authority will ask for.

    • NIS2 requirements mapped to controls, owners and evidence
    • Risk assessment and risk register with management approval
    • Supplier assessments and security requirements in one place
    • Incident log ready for the 24-hour, 72-hour and one-month reports
    • EU-hosted and ISAE-certified
    +400 companies use .legal
    Region Sjælland
    Aarhus Universitet
    aj_vaccines_logo
    Realdania
    Right People
    IO Gates
    PLO
    Finans Danmark
    geia-food
    Evida
    Klasselotteriet
    NRGI1
    BLUE WATER SHIPPING
    Karnov
    Ingvard Christensen
    VP Securities
    AH Industries
    Lægeforeningen
    InMobile
    AK Nygart
    DEIF
    DMJX
    Axel logo
    qUINT Logo
    KAUFMANN (1)
    SMILfonden-logo
    kurhotel_skodsborg
    nemlig.com
    Molecule Consultancy
    Novicell