The policy says privileged access is reviewed every quarter. Security says the review happened. IT has a ticket. The owner remembers approving something. The evidence is apparently "somewhere in Teams."
Everybody agrees the control exists. Nobody can show the full trail.
That gap between "the policy says" and "here's the proof" is exactly what a working NIS2 Compliance Checklist is built to catch — and it shows up far more often than most security and compliance teams expect.
NIS2's Article 21 gives organisations 10 cybersecurity risk-management measures. On paper, that reads like a short list. The practical work sits underneath each measure: current risk assessments, incident records, supplier reviews, restore tests, access approvals, vulnerability remediation, MFA coverage, and management decisions.
A sentence in a policy tells you what should happen. Evidence tells you whether it did. And evidence gets old surprisingly fast.
| Common NIS2 readiness problem | What the team actually needs |
|---|---|
| Article 21 measures are covered at the policy level, but implementation is difficult to verify | Specific controls mapped to evidence |
| Security work happens across IT, security, HR, procurement, and operations | One review structure for controls and proof |
| A control is considered complete because someone says it is working | Evidence that shows what is actually implemented |
| Gaps are found during reviews but tracked inconsistently | Clear implementation status and follow-up |
| Supplier, access, system, and risk changes make old evidence stale | A repeatable control and evidence review |
Free guide
Review all 10 Article 21 measures against actual evidence
A free 13-page checklist that breaks each measure into controls, expected evidence, and an implementation status you can act on.
Download the NIS2 Compliance ChecklistNothing about a stale control looks dramatic until someone asks you to prove it today.
A supplier risk assessment from three years ago may describe a company that barely exists anymore — different ownership, different infrastructure, different subcontractors. An access review can be technically complete while two old admin accounts are still active, quietly outside the scope of the last check. A backup job can run successfully every single night without anyone knowing whether the restore actually works.
None of these are dramatic failures. They are the ordinary, unglamorous way a control that was correct at the last review quietly stops matching the environment it's supposed to protect.
Article 21's 10 measures are broad by design — risk analysis, incident handling, business continuity, supply chain security, security in acquisition and development, policies to assess effectiveness, cyber hygiene and training, cryptography, HR security and access control, and multi-factor authentication among them. A written requirement under any of these tells you what should happen. Configuration records, completed reviews, test results, approvals, logs, and remediation records tell you whether it did.
The practical fix isn't more policy. It's a review structure that keeps control status and evidence status separate, so "implemented," "partial," "not started," and "not applicable" stay visible instead of collapsing into a single reassuring "yes, we do that."
Free tool
Not sure which Article 21 areas need attention first?
The NIS2 Self-Assessment Toolkit scores overall readiness and flags priorities before you dig into individual controls.
Use the NIS2 Self-Assessment ToolkitThe checklist works alongside a few other NIS2 resources, depending on what you're checking:
It's for teams that already know NIS2 applies to them and need to check whether Article 21 controls are really in place, evidenced, and ready for review — not for determining whether NIS2 applies in the first place.
No. It focuses on the 10 cybersecurity risk-management measures in Article 21. Applicability, national transposition, incident reporting duties, and supervisory requirements need separate review — start with the NIS2 Requirements Guide linked above.
Mark it partial. "We definitely do this" becomes a weak answer surprisingly fast when nobody can find the record, approval, test result, or configuration that proves it — and that's a far better outcome to discover internally than during a regulatory review.
A self-assessment scores overall readiness and highlights priority areas using weighted questions. A control-and-evidence checklist goes deeper into a defined scope — in this case Article 21 — and asks what proof exists for each specific control. Use the assessment to find where to start, then the checklist to work through the gaps.
Looking beyond the checklist?
Q-Sec can review your Article 21 controls, evidence gaps, and remediation priorities directly.