NIS2 › NIS2 Compliance
NIS2 Introduction
Modules
.legal AI
All AI features →Integrations
See all integrations →Platform & features
Understand the rules
See it in action
All customer stories →Plan your switch
Stay up to date
Most organisations covered by NIS2 already know they have to act. What they're missing is a plan that turns the legal text into work: who signs off what, which documents the supervisory authority will ask for, and what has to happen in the first 24 hours when something goes wrong.
This NIS2 implementation guide gives you that plan. It splits the work into 12 steps, links each step to the requirements in the NIS2 Directive and lists the deliverables each step should produce. Every step ends with a checklist that separates what the law requires from what the authorities recommend.
The guide is free, with no form to fill in. The complete NIS2 compliance checklist is at the end, ready to copy into a spreadsheet or your GRC tool. We use Denmark as the worked example because the Danish authorities have published unusually detailed guidance, but the steps work in any EU member state. If you're new to the directive, start with our introduction to NIS2.
NIS2 compliance means meeting four sets of obligations. You register with the authorities. You put appropriate and proportionate cybersecurity risk-management measures in place, built around the ten minimum measures in Article 21. You report significant incidents within 24 hours, 72 hours and one month under Article 23. And your management body approves and oversees the measures under Article 20.
In practice that's a programme of twelve steps that typically takes 6 to 12 months for a mid-sized organisation without a mature information security management system. Order matters. Scope and registration come first because they carry legal deadlines and decide who supervises you. Governance comes next because the law puts management on the hook. The ten measures follow. And the work doesn't end, because Article 21 also requires you to assess whether your measures are effective.
Important: the obligations apply whether or not you've registered. Skipping registration doesn't take you out of scope. It just adds a second breach.

The directive sets the same core obligations everywhere. Registration portals, authorities and penalty procedures are national. Here's how it looks in Denmark.
| Topic | What applies | Source |
|---|---|---|
| Legal basis | Directive (EU) 2022/2555. Implemented in Denmark by the NIS2 Act, Act no. 434 of 6 May 2025 | Danish NIS2 Act |
| In force | 1 July 2025 in Denmark | Section 33(1) |
| Registration | On virk.dk. Deadline 1 October 2025 for entities in scope at entry into force, otherwise two weeks after coming into scope | Sections 10 and 33(3) |
| Incident reporting | Early warning within 24 hours, notification within 72 hours, final report within one month | Article 23, section 13 |
| Management | Approve measures, oversee implementation, attend training | Article 20, section 7 |
| Fines in Denmark | Criminal fines set by the courts. The explanatory notes to the bill indicate a maximum of EUR 10 million or 2% of global turnover for essential entities and EUR 7 million or 1.4% for important entities, whichever is higher | Bill L 141, explanatory notes |
| Supervision | Proactive for essential entities (audits, inspections). Reactive for important entities | Sections 21 and 24 |
Denmark has no administrative fines, so NIS2 penalties go through the criminal courts. The figures above are maximums described in the bill's explanatory notes rather than amounts written into the act, and there's no case law yet. Treat them as ceilings, not price tags.
Outside Denmark: check your national transposition law and your competent authority's website before you copy any deadline from this table. The European Commission keeps an overview on its NIS2 policy page.
Article 21(2) lists ten minimum measures. In the Danish act they appear in section 6(1). The table shows the core requirement for each measure according to SAMSIK's guidance, the ISO/IEC 27001:2022 references the guidance points to, and the step in this guide where you deal with it.
| # | NIS2 requirement | Core must-do | ISO 27001:2022 | Step |
|---|---|---|---|---|
| 1 | Risk analysis and information system security policies | Approved security policy, documented risk assessments, accepted residual risk | 6.1-6.2, 8.2-8.3, A.5.1 | 6, 7 |
| 2 | Incident handling | Approved procedures to detect, analyse, respond and report. Protected logs | A.5.24, A.8.15-8.16 | 9 |
| 3 | Business continuity, backup, disaster recovery, crisis management | Risk-based continuity procedures, backup including configuration | A.5.29-5.30, A.8.13-8.14 | 10 |
| 4 | Supply chain security | Supplier procedures, risk per supplier, agreements | A.5.19-5.21 | 8 |
| 5 | Security in acquisition, development and maintenance, including vulnerability handling | Documented procedures and vulnerability handling | A.8.8, A.8.25-8.32 | 7 |
| 6 | Assessing the effectiveness of measures | Policy for continuous assessment, risk-based testing | 9.1, 9.3, A.8.34 | 12 |
| 7 | Cyber hygiene and training | Basic hygiene, training policy | 7.2-7.3, A.6.3 | 11 |
| 8 | Cryptography and encryption | Policy matching state of the art | A.8.24 | 7 |
| 9 | HR security, access control and asset management | Access control including privileged rights, asset management | A.5.9-5.18, A.6.1-6.7 | 4, 7 |
| 10 | MFA, secured communication, emergency communication | MFA where relevant with periodic review | A.5.17, A.8.5 | 7, 10 |
The ISO mapping helps you reuse work, but it isn't equivalence. ENISA says so explicitly about its own mapping, and SAMSIK writes that following a standard is no guarantee you meet the requirements. An ISO 27001 certificate won't cover the reporting deadlines, registration, documented management training, customer notification or the all-hazards and societal-impact perspective. Our comparison of NIS2 and ISO 27001 goes through the gaps in detail.
If you want primary sources rather than vendor summaries, these are the documents to read. SAMSIK (the Danish Agency for Civil Protection and Emergency Management) has published four cross-sector guides and one for municipalities. They're in Danish, but they're the most concrete NIS2 implementation guidance any EU authority has released so far.
| Guidance | Published | What you'll use it for |
|---|---|---|
| SAMSIK: scope | 2025 | Scope, size criteria, jurisdiction and supplier relationships |
| SAMSIK: management's role and duties | May 2025 | Approval, oversight, training, delegation and personal sanctions |
| SAMSIK: implementing cybersecurity measures | June 2025 | The ten measures with must, should and may levels and standard references |
| SAMSIK: incident reporting | June 2025 | Significance criteria, examples, decision tree and report content |
| SAMSIK: guidance for municipalities | July 2025 | Municipal context, including home care and outsourced services |
| ENISA Technical Implementation Guidance | June 2025 | Implementation advice, evidence examples and framework mapping |
| Implementing Regulation (EU) 2024/2690 | In force 7 November 2024 | Binding technical requirements for digital providers, and a benchmark for everyone else |
SAMSIK's measures guidance uses three levels. Must is a requirement you have to be able to document. Should is a recommendation, and if you don't follow it you must be able to explain why, with reference to the state of the art, cost and risk. May is an example of a possible solution. The checklists below use the same labels.
Each step follows the same pattern: what the law asks, what the guidance adds, the deliverables you should end up with and a checklist marked Must or Should.
| Step | What you do | Deliverable |
|---|---|---|
| 1 | Confirm scope and category | Scope assessment memo |
| 2 | Register with the authorities | Registration receipt and change procedure |
| 3 | Anchor with the management body | Board resolution, RACI, training records |
| 4 | Map services, systems and dependencies | Service list, asset register, dependency map |
| 5 | Gap analysis against Article 21 | Gap report and approved action plan |
| 6 | Assess and treat risks | Risk policy, register, treatment plan |
| 7 | Policies and technical measures | Policy set, MFA, logging, patching |
| 8 | Supply chain security | Supplier tiers, assessments, contract clauses |
| 9 | Incident handling and reporting | Procedure, thresholds, report templates |
| 10 | Continuity and crisis management | Continuity plan, tested backups, crisis plan |
| 11 | Training and cyber hygiene | Training policy and records |
| 12 | Effectiveness and audit readiness | Test programme, review, evidence folder |
Start by writing down why you are, or aren't, covered. NIS2 applies to public and private entities of a type listed in Annex I (sectors of high criticality) or Annex II (other critical sectors) of the directive. Size decides the category in most cases.
Count employees and financials using the EU SME definition, which means partner and linked enterprises in your group count too. That's where many scope assessments go wrong. A 40-person subsidiary of a 600-person group is rarely a small company in NIS2 terms.
Deliverable: a scope assessment memo stating sector, sub-sector, size, category (essential or important), competent authority, any sector-specific law and the services and systems in scope. Keep it on file. It's the first thing a supervisory authority will ask for.
Registration is a legal deadline, so it comes early. In Denmark you register through a digital form on virk.dk using MitID Erhverv, and the form is routed automatically to your sector authority. Entities in scope when the Danish act took effect had to register by 1 October 2025. An entity that comes into scope later has two weeks.
Have this information ready before you open the form: legal name, address and contact details (email, phone and your public IP address ranges), sector and sub-sector, the EU member states where you provide services, and your size and turnover. Digital providers such as cloud, data centre and managed service providers must also give their places of business and any EU representative.
Changes must be reported within two weeks under section 10(3) of the Danish act. The virk.dk introduction page mentions three months, but that's the deadline for the digital providers in section 9. Plan for two weeks.
Deliverable: registration receipt, the authority's confirmation of your category, and a named owner who updates the registration when something changes.
Article 20 of the directive, section 7 of the Danish act, gives the management body three duties. It must approve the cybersecurity risk-management measures, oversee their implementation and attend training. If you have both a board and an executive board, the management body is the board. In public authorities it's the top administrative management.
SAMSIK's guidance on management's role and duties adds useful detail. The board can delegate work to a committee, but it keeps collective responsibility. Training has no prescribed format or content, and not every member needs a course, but the board as a whole must have the necessary skills and you must be able to document the training. For oversight, the guidance suggests a half-yearly management report with status on objectives, action plans and KPIs, such as the number of significant incidents and target times for fixing critical vulnerabilities.
For essential entities there's a personal sanction too. The authority can, as a last resort, temporarily ban a person at CEO level from management functions. It doesn't apply to public authorities.
Deliverables: board resolution with minutes, programme mandate, RACI, named risk owners, reporting cadence and training records. Read more in our article on NIS2 training requirements.
NIS2 protects the network and information systems that support the services you provide in your sector. That includes operational technology (OT) and IoT, not just office IT. It's also not necessarily the same scope as your ISO 27001 certificate.
SAMSIK's measures guidance treats asset management as a must, while the asset inventory itself is listed as an example (a 'may'). In practice you can't assess risk or prioritise patching without one, so build it.
Deliverables: list of in-scope services, asset register with owners, classification by confidentiality, integrity and availability, and a dependency map that shows which suppliers and systems each critical service relies on.
Now compare what you have with what the ten minimum measures require. Do it measure by measure and requirement by requirement. SAMSIK's measures guidance is the most practical benchmark available because it marks every point as must, should or may. Two other tools help: ENISA's NIS2 Technical Implementation Guidance (June 2025), which includes a mapping to ISO 27001, NIST CSF 2.0 and other frameworks, and the questionnaire SAMSIK published for its 2026 supervision of Danish municipalities, which shows what an authority actually asks.
Every 'should' you decide not to follow needs a documented reason, based on the state of the art, cost and risk. That rule turns the gap analysis into evidence rather than a to-do list.
Deliverable: gap report per measure with status (met, partly met, not met), existing evidence, owner and priority, plus a management-approved action plan.
Article 21 builds on risk assessment. Two things make the NIS2 version different from a typical ISO 27001 assessment. It takes an all-hazards approach, so physical events, power failures and human error count alongside cyberattacks. And it looks at harm to others, meaning your customers and society, not only at your own risk appetite.
SAMSIK requires a risk management policy approved by relevant management, documented risk assessments and formal acceptance of residual risk by the risk owner. Our NIS2 risk assessment guide walks through the method step by step, and the risk assessment matrix article covers scoring.
Deliverables: risk management policy, risk register, risk treatment plan and signed acceptance of residual risk.
This is the longest step and where most of the budget goes. It covers measures 1, 5, 7, 8, 9 and 10 in Article 21. The core documents are an information security policy approved by the management body, an access control policy covering privileged rights, a cryptography policy that matches the state of the art and procedures for acquisition, development, maintenance and disposal of systems.
On the technical side, SAMSIK requires multi-factor or continuous authentication where relevant, with a periodic, documented review of where it's used. Logs must be kept, reviewed and protected against tampering. Vulnerabilities must be identified, assessed and handled through a defined procedure.
Worth knowing: several measures people assume are mandatory are only recommendations or examples in SAMSIK's guidance. That includes testing backups, the detailed content and yearly update of the security policy, contract clauses with suppliers, the asset inventory, vulnerability scanning and background checks. Don't skip them. Supervisors will expect you to follow them or explain why not.
Deliverables: approved policy set, cyber hygiene baseline, MFA rollout and review log, patch and vulnerability procedure, logging set-up and joiner, mover and leaver process.
Measure 4 covers supply chain security, and it's where NIS2 reaches organisations that aren't in scope themselves. You must have procedures for managing direct suppliers, assess the risk each one poses and make agreements that make your requirements stick. SAMSIK's scope guidance confirms that suppliers outside NIS2 can expect proportionate requirements from customers who are inside it.
Two practical points get missed. First, your suppliers must alert you fast enough for you to meet your own 24-hour deadline, so the incident clause in the contract needs a time limit. Second, if a supplier runs your systems and reports incidents on your behalf, the responsibility for reporting on time still sits with you. Our article on vendor audits covers how to follow up.
Deliverables: supplier list with criticality tiers, risk assessment per critical supplier, standard security clauses (requirements, incident notification, audit rights, exit) and a follow-up plan.
Article 23 sets the reporting clock. An incident is significant if it has caused, or can cause, severe operational disruption or financial loss for you, or considerable material or non-material damage to others.
| Report | Deadline | Content |
|---|---|---|
| Early warning | Within 24 hours of becoming aware | Whether the incident is suspected to be caused by unlawful or malicious acts, and whether it could have cross-border impact |
| Incident notification | Within 72 hours of becoming aware | Initial assessment, severity, impact and indicators of compromise where available |
| Intermediate report | On request from the CSIRT or authority | Relevant status updates |
| Final report | No later than one month after the incident notification | Detailed description, root cause, mitigation applied and any cross-border impact. If the incident is still ongoing, send a progress report and the final report within one month of handling it |
SAMSIK's guidance on incident reporting makes the definition usable. It recommends that you set your own objective thresholds, for example for downtime or financial loss. Its example is a loss above 1% of annual turnover, defined in your own risk assessment. Exfiltration of trade secrets is always significant. A threat actor sitting in your systems to cause disruption later should be treated as significant. Planned maintenance isn't reported.
In Denmark you report once on virk.dk, and the form goes to both your sector authority and the CSIRT. You can tick a box to notify the Danish Data Protection Agency (Datatilsynet) about a personal data breach at the same time. The CSIRT replies within 24 hours of the early warning. You must also notify recipients of your services without undue delay if the incident is likely to affect them. See our article on security breaches for how the NIS2 and GDPR deadlines run side by side.
Digital providers have fixed thresholds in Implementing Regulation (EU) 2024/2690. A direct financial loss above EUR 500,000 or 5% of turnover, whichever is lower, counts as significant. For managed service providers, complete unavailability for more than 30 minutes does.

Deliverables: approved incident procedure, significance criteria with your own thresholds, decision tree, reporting roles with 24/7 access to the reporting portal, templates for each report, GDPR triage and customer communication.
Measure 3 covers backup, disaster recovery and crisis management. SAMSIK requires continuity procedures based on your risk assessment and backup of all relevant data, including configuration. You must also assess whether you need redundancy and a crisis management plan.
Testing a restore is formally a 'should', but a backup you've never restored is a hope, not a control. Ransomware is the scenario to test against, so keep at least one copy offline or logically separated.
Deliverables: continuity plan with recovery time and recovery point objectives for critical services, backup procedure, redundancy assessment, crisis management plan and alternative communication channels.
Measure 7 requires basic cyber hygiene and training. Management training sits in Article 20 and was covered in step 3. For everyone else you need a training policy and a programme that matches roles. IT staff, administrators with privileged access and the people who file incident reports need more than the annual phishing module.
Our articles on awareness training and NIS2 training requirements cover formats and documentation.
Deliverables: training policy, role-based training plan, attendance records and a short evaluation of whether the training changed behaviour.
Measure 6 requires you to assess whether your measures actually work. SAMSIK asks for a policy and procedures for continuous assessment, a risk-based view of what to test and how often, and acceptance of residual risk by the risk owner. That's what turns a project into a management system.
Supervision is the other reason. Authorities can ask for documentation at any time. Essential entities face proactive supervision with audits and on-site inspections. Important entities are supervised reactively when there are signs of non-compliance. In 2026 SAMSIK began survey-based supervision of all 98 Danish municipalities, which shows the shift from guidance to control.
Deliverables: effectiveness policy, test programme (for example vulnerability scanning and penetration tests based on risk), internal or external audit, annual management review and an evidence folder with policies, minutes, logs, training records and registration receipts.
Nordlys Elektronik A/S and its CISO, Mette Holm, are fictional. We invented them for this article.
Nordlys makes electronic components in Jutland. It has 180 employees, annual turnover of EUR 40 million and a balance sheet of EUR 28 million, with no parent company. Manufacturing of computer, electronic and optical products is in Annex II, so Nordlys is in scope. With more than 50 employees it's an important entity. It's below 250 employees and below the EUR 50 million turnover threshold, so it isn't essential.
That gives Mette three facts to plan around. SAMSIK is the supervisory authority. Supervision is reactive, so an inspection will usually follow a complaint, an incident or other indications. And the maximum fine indicated in the explanatory notes is EUR 7 million, because 1.4% of EUR 40 million is only EUR 560,000 and the higher figure applies.
In step 9 Mette sets Nordlys's significance threshold at a financial loss above 1% of turnover, which is EUR 400,000. Here's what happens when ransomware stops production on a Monday morning.
| Time | What happens | Obligation |
|---|---|---|
| Monday 08:00 | Encrypted servers found, production stopped. Expected loss over three days is EUR 600,000 | Clock starts. The incident is significant because it's above the threshold |
| Tuesday 08:00 at the latest | Early warning filed on virk.dk. Malicious act suspected, no cross-border impact known | 24-hour early warning |
| Tuesday | Two customers told their deliveries will be late | Notify affected recipients without undue delay |
| Thursday 08:00 at the latest | Incident notification with initial assessment and indicators of compromise. HR files were on an encrypted server, so the GDPR box is ticked | 72-hour notification, plus 72-hour notification to Datatilsynet |
| Within one month of Thursday | Final report with root cause, mitigation and lessons learned | Final report |
The incident went well for one reason. The thresholds, roles and templates existed before Monday. Without them, Mette's team would have spent the first day arguing about whether the incident was significant at all.
The estimates below are based on experience with mid-sized organisations that don't yet have a mature ISMS. They aren't from any official source. An organisation with ISO 27001 in place can often halve the middle phases.
| Phase | Steps | Typical duration |
|---|---|---|
| Scope, registration and governance | 1-3 | 2-4 weeks |
| Mapping, gap analysis and risk assessment | 4-6 | 1-3 months |
| Measures, supply chain, incidents and continuity | 7-10 | 3-9 months, running in parallel |
| Training and effectiveness | 11-12 | Ongoing, with an annual cycle |
Here's the full NIS2 requirements checklist in one place, with no form or email required. Copy it into Excel or your GRC tool and assign an owner and a date to each line.
None of the following changes the law today, but they affect how you build your processes.
The practical takeaway is to build one internal triage process for NIS2, GDPR and DORA now, so you can switch portals later without redesigning anything.
Most of the twelve steps produce documents that have to stay connected: risks that point to assets, measures that point to risks, suppliers that point to services, and evidence that points to all of it. That's hard to keep together in spreadsheets once the programme runs for more than a year.
In .legal's Frameworks module the NIS2 requirements are already mapped, so you can track status per measure, assign tasks and reuse ISO 27001 evidence where it overlaps. Risk management and vendor management cover steps 6 and 8 in the same platform. You can see the NIS2 mapping and risk assessment demo or book a demo to walk through your own case.
Ask Johannes directly. He runs most of our demos personally. Book him here.
NIS2 compliance means that an organisation covered by Directive (EU) 2022/2555 has registered with its national authority, has put the ten minimum cybersecurity risk-management measures in Article 21 in place, can report significant incidents within 24 hours, 72 hours and one month, and has a management body that approves and oversees the measures. There's no certificate. You show compliance through documentation when the authority asks for it.
Not directly, unless you're in an Annex I or II sector yourself and meet the size criteria. Managed service providers, cloud providers and data centres often are. If you aren't in scope, you'll still feel NIS2 through your customers, who must assess the risk you pose and set proportionate security requirements in their contracts with you.
For a mid-sized organisation without a mature ISMS, expect 6 to 12 months to get the core in place. Scope, registration and governance can be done in a few weeks. Policies, technical measures and supplier work take longest. Organisations with ISO 27001 can usually move faster because much of the documentation can be reused.
Yes. The checklist in this guide is free and ungated, and you can copy it straight into Excel or a GRC tool. It follows the ten measures in Article 21 plus registration, management duties and reporting, and each item is marked as a legal requirement or a recommendation based on the Danish authority's guidance.
No. ISO 27001 covers much of the technical and organisational work, but it doesn't include the 24-hour, 72-hour and one-month reporting deadlines, registration, documented management training or notification of your customers. NIS2 also takes an all-hazards view and looks at harm to society, and your NIS2 scope may be wider than your certified ISO scope.
Both have the same obligations to implement measures and report incidents. The difference is supervision and fines. Essential entities face proactive supervision with audits and inspections and higher maximum fines. Important entities are supervised reactively, after indications of non-compliance. Category depends mainly on sector and size, with some entities essential regardless of size.
Late reporting is a breach of the reporting duty and can be penalised. Report as soon as you can anyway, and document when you became aware of the incident and why the report was delayed. The 24-hour clock runs from when you become aware of a significant incident, which is why pre-agreed thresholds and roles matter so much.
No specific course or certificate is required. The management body must attend training so that, as a group, it has the skills to understand and assess cybersecurity risks and their impact. Not every member needs the same course, but you must be able to document the training, for example with attendance records or course certificates.
It applies directly to DNS providers, top-level domain registries, cloud and data centre providers, content delivery networks, managed service and managed security service providers, online marketplaces, search engines, social networks and trust service providers. For other entities it isn't binding, but it's a useful benchmark for what good looks like.
One incident can trigger both a NIS2 report to the authority and CSIRT and a GDPR notification to the data protection authority, each with its own clock. In Denmark one form on virk.dk can cover both. Financial entities follow DORA instead of NIS2, because DORA is the more specific law, and in Denmark they don't register under the NIS2 Act.
This guide covers the whole programme in twelve steps. These articles go into the parts that take the longest: risk assessment, management training and the overlap with ISO 27001.
.legal compliance platform
Turn the twelve steps into tracked work. .legal maps your controls to the ten NIS2 measures, keeps the risk register and supplier assessments current, and gives management the documentation the authority will ask for.
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.