Self-assessment checklist

Where does your organisation stand on NIS2?

Fifteen questions for a quick self-assessment. They are no substitute for a formal review, but they show you where to look first. Your answers stay in your browser: nothing is sent or stored.

Download the PDF (1 page) No sign-up required.

Scope and registration

Have you checked whether your organisation falls within NIS2 scope by sector and size, or receives NIS2 requirements anyway as a supplier to in-scope entities?
If you are in scope, is your registration with the national authority (in Italy, the ACN platform) complete and renewed each year, with a designated point of contact?

Governance

Has the management body approved the security measures, and does it oversee their implementation?
Have senior managers received training on cybersecurity risk management?
Are cybersecurity roles and responsibilities assigned and documented?

Risks and security measures

Is there a documented, up-to-date risk assessment based on an inventory of systems, data and services?
Is multi-factor authentication enabled for email, remote access and administrator accounts?
Are backups isolated from the main network, and are restores tested regularly?
Are vulnerabilities and security updates handled through a defined process and timescales?
Is there a business continuity and crisis management plan?
Do all staff receive regular cyber hygiene training?

Supply chain

Have critical suppliers been identified and assessed, with security requirements written into contracts?

Incidents

Is there an incident management procedure with roles, severity criteria and contacts?
Could you report a significant incident to the national CSIRT on time: early warning within 24 hours, notification within 72 hours, final report within one month?

Assurance

Is the effectiveness of the measures checked regularly through audits, tests or exercises?

References: Directive (EU) 2022/2555 (NIS2) and, for Italy, Legislative Decree no. 138 of 4 September 2024. This checklist is for information only and is not legal advice. For current obligations and deadlines, check your national authority (in Italy, the National Cybersecurity Agency, acn.gov.it).