Skip to main content
Free resource · NIS2 Article 21

NIS2 Compliance Checklist: Article 21 Control and Evidence Review

Review the 10 NIS2 cybersecurity risk-management measures, the controls behind them, and the evidence your team should be able to produce.

  • 13-page printable checklist
  • All 10 Article 21 measures
  • Control and evidence guidance
  • Implementation status and readiness checks
— 01 · The challenge

The policy exists. The evidence is somewhere else.

Security work happens across IT, security, HR, procurement, and operations. Proving Article 21 controls are actually in place, on demand, is a different job.

Common NIS2 readiness problem
What the team needs
Article 21 measures are covered at the policy level, but implementation is difficult to verify
Specific controls mapped to evidence
Security work happens across IT, security, HR, procurement, and operations
One review structure for controls and proof
A control is considered complete because someone says it is working
Evidence that shows what is actually implemented
Gaps are found during reviews but tracked inconsistently
Clear implementation status and follow-up
Supplier, access, system, and risk changes make old evidence stale
A repeatable control and evidence review
— 02 · Inside the download

What's inside the NIS2 Compliance Checklist

All 10 Article 21 measures in one place

Review the full set of NIS2 cybersecurity risk-management measures in a single printable checklist.

Control and evidence guidance

Each measure is broken into concrete controls with the records, approvals, configurations, test results, and other evidence you should be able to produce.

Implementation status tracking

Mark each control as Implemented, Partial, Not started, or N/A so open work stays visible and does not vanish into somebody's notes.

Final readiness and remediation review

Run one last check across open gaps, owners, target dates, accepted risks, and evidence before an internal or regulatory review.

Article 21 works better when the control and the proof live in the same conversation

Use the PDF checklist to review implementation and evidence across all 10 measures.

Download the NIS2 Compliance Checklist
— 03 · Full review or first assessment?

Two different jobs, covered by two different resources

The NIS2 Self-Assessment Toolkit measures overall readiness and helps you find where to start. The NIS2 Compliance Checklist reviews Article 21 controls and evidence in detail.

NIS2 Self-Assessment Toolkit
NIS2 Compliance Checklist
Measures overall readiness
Reviews Article 21 controls in detail
Uses questions and weighted scoring
Uses controls, expected evidence, and status
Identifies weak areas and priorities
Helps verify implementation and collect proof
Best for finding where to start
Best for working through the gaps
— 04 · Why teams use this checklist

Go deeper than the Article 21 headings

Go deeper than the Article 21 headings

Article 21 lists 10 required areas. The checklist breaks them into practical controls that security and compliance teams can actually review.

Check evidence, not policy wording

A written requirement tells you what should happen. Configuration records, completed reviews, tests, approvals, logs, and remediation records help show what actually happened.

Keep implementation status visible

Separate controls that are implemented from those that are partial, not started, or genuinely not applicable.

Find stale controls before somebody else does

Suppliers change. Employees leave. Infrastructure moves. A control that was correct during the previous review can quietly stop matching the environment.

— 05 · Related NIS2 resources

Need more context around a control in the checklist? Start here.

NIS2 requirements

Review the core NIS2 obligations and what they mean in practice.

Read the NIS2 requirements guide
Incident response

Build the response workflow behind the incident-handling controls.

NIS2 Incident Response Plan Template
Supplier security

Assess suppliers, document risk, and keep review evidence.

NIS2 Supplier Risk Assessment Template
— 06 · FAQ

Frequently asked questions

What is this NIS2 compliance checklist actually for?

For teams that already know NIS2 applies and need to check whether Article 21 controls are really in place, evidenced, and ready for review.

Does it cover the full NIS2 Directive?

No. It focuses on the 10 cybersecurity risk-management measures in Article 21. Applicability, national transposition, reporting duties, and supervisory requirements need separate review.

Is this a NIS2 compliance checklist PDF?

Yes. It is a 13-page printable PDF with control tables, evidence prompts, status tracking, readiness checks, and a final remediation review.

Can we use it before an audit or regulatory review?

Yes. It is useful for checking controls, locating evidence, and spotting unfinished work before somebody external asks for it.

What if a control exists but the evidence does not?

Mark it Partial. "We definitely do this" becomes a weak answer surprisingly fast when nobody can find the record, approval, test result, or configuration that proves it.

How is this different from the NIS2 Self-Assessment Toolkit?

The Self-Assessment Toolkit scores readiness and highlights priorities. This checklist goes deeper into Article 21 controls and the evidence behind them. Use the assessment to find gaps, then use this checklist to work through them.

— Looking beyond the checklist?

A checklist can reveal missing controls and missing evidence

Q-Sec can review your Article 21 controls, evidence gaps, and remediation priorities.

Talk to a NIS2 specialist