NIS2 Compliance Checklist: Article 21 Control and Evidence Review
Review the 10 NIS2 cybersecurity risk-management measures, the controls behind them, and the evidence your team should be able to produce.
- 13-page printable checklist
- All 10 Article 21 measures
- Control and evidence guidance
- Implementation status and readiness checks
The policy exists. The evidence is somewhere else.
Security work happens across IT, security, HR, procurement, and operations. Proving Article 21 controls are actually in place, on demand, is a different job.
What's inside the NIS2 Compliance Checklist
All 10 Article 21 measures in one place
Review the full set of NIS2 cybersecurity risk-management measures in a single printable checklist.
Control and evidence guidance
Each measure is broken into concrete controls with the records, approvals, configurations, test results, and other evidence you should be able to produce.
Implementation status tracking
Mark each control as Implemented, Partial, Not started, or N/A so open work stays visible and does not vanish into somebody's notes.
Final readiness and remediation review
Run one last check across open gaps, owners, target dates, accepted risks, and evidence before an internal or regulatory review.
Article 21 works better when the control and the proof live in the same conversation
Use the PDF checklist to review implementation and evidence across all 10 measures.
Download the NIS2 Compliance ChecklistTwo different jobs, covered by two different resources
The NIS2 Self-Assessment Toolkit measures overall readiness and helps you find where to start. The NIS2 Compliance Checklist reviews Article 21 controls and evidence in detail.
Go deeper than the Article 21 headings
Go deeper than the Article 21 headings
Article 21 lists 10 required areas. The checklist breaks them into practical controls that security and compliance teams can actually review.
Check evidence, not policy wording
A written requirement tells you what should happen. Configuration records, completed reviews, tests, approvals, logs, and remediation records help show what actually happened.
Keep implementation status visible
Separate controls that are implemented from those that are partial, not started, or genuinely not applicable.
Find stale controls before somebody else does
Suppliers change. Employees leave. Infrastructure moves. A control that was correct during the previous review can quietly stop matching the environment.
Need more context around a control in the checklist? Start here.
Review the core NIS2 obligations and what they mean in practice.
Read the NIS2 requirements guideBuild the response workflow behind the incident-handling controls.
NIS2 Incident Response Plan TemplateAssess suppliers, document risk, and keep review evidence.
NIS2 Supplier Risk Assessment TemplateFrequently asked questions
What is this NIS2 compliance checklist actually for?
For teams that already know NIS2 applies and need to check whether Article 21 controls are really in place, evidenced, and ready for review.
Does it cover the full NIS2 Directive?
No. It focuses on the 10 cybersecurity risk-management measures in Article 21. Applicability, national transposition, reporting duties, and supervisory requirements need separate review.
Is this a NIS2 compliance checklist PDF?
Yes. It is a 13-page printable PDF with control tables, evidence prompts, status tracking, readiness checks, and a final remediation review.
Can we use it before an audit or regulatory review?
Yes. It is useful for checking controls, locating evidence, and spotting unfinished work before somebody external asks for it.
What if a control exists but the evidence does not?
Mark it Partial. "We definitely do this" becomes a weak answer surprisingly fast when nobody can find the record, approval, test result, or configuration that proves it.
How is this different from the NIS2 Self-Assessment Toolkit?
The Self-Assessment Toolkit scores readiness and highlights priorities. This checklist goes deeper into Article 21 controls and the evidence behind them. Use the assessment to find gaps, then use this checklist to work through them.
A checklist can reveal missing controls and missing evidence
Q-Sec can review your Article 21 controls, evidence gaps, and remediation priorities.