NIS2 & CSDDD Compliance Self-Assessment Checklist

Designed for use in European Union

Create your NIS2 & CSDDD Compliance Self-Assessment Checklist for use in European Union. Answer a few plain-English questions and the document fills in automatically as you go - then download it in Word and PDF, ready to sign or share.

  • Answer 136 simple questions - the document fills in as you go
  • Live preview: watch your document update in real time
  • Download as Word (.docx) and PDF
  • Edit your answers and re-download anytime

How it works

  1. 1Answer a few simple questions
  2. 2Preview your document live
  3. 3Pay once - download in Word & PDF

Below you can preview the NIS2 & CSDDD Compliance Self-Assessment Checklist, complete it by answering a few plain-English questions, and download a ready-to-sign copy in Word and PDF - tailored for use in European Union.

What the NIS2 & CSDDD Compliance Self-Assessment Checklist includes

This template is organised into the following sections:

Frequently asked questions

What is a NIS2 & CSDDD Compliance Self-Assessment Checklist?

A NIS2 & CSDDD Compliance Self-Assessment Checklist is a ready-to-use legal template for European Union. You complete it by answering a few plain-English questions, then download the finished document in Word and PDF.

What does the NIS2 & CSDDD Compliance Self-Assessment Checklist cover?

The NIS2 & CSDDD Compliance Self-Assessment Checklist is organised into sections covering ORGANISATION IDENTITY, PART 1 — NIS2 DIRECTIVE (EU) 2022/2555, Scope determination, Cybersecurity risk-management measures (Art. 21), Incident reporting obligations (Art. 23), so the important points are captured in a clear, consistent structure.

What formats can I download?

You can download your completed NIS2 & CSDDD Compliance Self-Assessment Checklist as an editable Microsoft Word (.docx) file and as a PDF.

Can I edit the document later?

Yes - save it to your account and you can re-open, edit and re-download it at any time.

Is a NIS2 & CSDDD Compliance Self-Assessment Checklist legally binding?

Once it is properly completed and signed by everyone involved, a NIS2 & CSDDD Compliance Self-Assessment Checklist is generally legally binding in European Union, provided it meets the legal requirements that apply to this type of document.

What laws apply to a NIS2 & CSDDD Compliance Self-Assessment Checklist in European Union?

A NIS2 & CSDDD Compliance Self-Assessment Checklist should comply with the laws in force in European Union. This template is built around the provisions such situations commonly require, but the rules can vary by region and change over time, so check the current requirements for your case.

Do I need a lawyer to use a NIS2 & CSDDD Compliance Self-Assessment Checklist?

For most standard situations you can complete the NIS2 & CSDDD Compliance Self-Assessment Checklist yourself using the guided questionnaire. For high-value, unusual or high-risk matters, it is sensible to have a qualified lawyer review the finished document.

How do I sign the NIS2 & CSDDD Compliance Self-Assessment Checklist?

Download the completed NIS2 & CSDDD Compliance Self-Assessment Checklist as Word or PDF and sign it as required in European Union. Depending on the document this may involve a handwritten or electronic signature, and some documents also need witnesses.

Is the NIS2 & CSDDD Compliance Self-Assessment Checklist free?

You can preview the NIS2 & CSDDD Compliance Self-Assessment Checklist and fill it in for free. A one-time fee applies only when you download the finished, ready-to-sign document in Word and PDF.

How long does it take to complete a NIS2 & CSDDD Compliance Self-Assessment Checklist?

Most people finish the NIS2 & CSDDD Compliance Self-Assessment Checklist in just a few minutes by answering the plain-English questions. You can save your progress and come back to it at any time.

Prepared and reviewed by the LegalDocs team.

Document preview

NIS2 & CSDDD COMPLIANCE SELF-ASSESSMENT CHECKLIST

ORGANISATION IDENTITY

  • Entity name: ________
  • Sector / principal activity: ________
  • Organisation size (headcount / turnover / balance sheet): ________
  • Assessment date: ________
  • Responsible officer: ________

PART 1 — NIS2 DIRECTIVE (EU) 2022/2555

Scope determination

RequirementStatusOwnerEvidenceTarget date
Determine whether the entity is an "essential entity" or an "important entity"________________________________
Confirm which sector(s) in Annex I (sectors of high criticality) apply________________________________
Confirm which sector(s) in Annex II (other critical sectors) apply________________________________
Verify size-cap thresholds and any size-cap exemptions________________________________

Cybersecurity risk-management measures (Art. 21)

RequirementStatusOwnerEvidenceTarget date
Policies on risk analysis and information system security________________________________
Incident handling________________________________
Business continuity, backup management and disaster recovery, and crisis management________________________________
Supply-chain security, including security aspects with direct suppliers and service providers________________________________
Security in acquisition, development and maintenance of systems, including vulnerability handling and disclosure________________________________
Policies and procedures to assess the effectiveness of risk-management measures________________________________
Basic cyber hygiene practices and cybersecurity training________________________________
Policies and procedures on the use of cryptography and, where appropriate, encryption________________________________
Human resources security, access control policies and asset management________________________________
Use of multi-factor authentication (MFA) or continuous authentication and secured communications________________________________

Incident reporting obligations (Art. 23)

RequirementStatusOwnerEvidenceTarget date
Process to submit an early warning to the CSIRT / competent authority within 24 hours of becoming aware of a significant incident________________________________
Process to submit an incident notification within 72 hours________________________________
Process to submit a final report no later than one month after the incident notification________________________________
Process to notify recipients of services of significant incidents, where appropriate________________________________

Governance and management-body accountability (Art. 20)

RequirementStatusOwnerEvidenceTarget date
Management body approves the cybersecurity risk-management measures________________________________
Management body oversees implementation of the measures________________________________
Management-body members follow cybersecurity training________________________________

Registration with the competent authority

RequirementStatusOwnerEvidenceTarget date
Register the entity and submit required information to the competent authority________________________________
Keep registration details (contacts, IP ranges, Member States of operation) up to date________________________________

PART 2 — CORPORATE SUSTAINABILITY DUE DILIGENCE DIRECTIVE (EU) 2024/1760

Scope and integration

RequirementStatusOwnerEvidenceTarget date
Determine whether the company meets the employee and net-turnover thresholds bringing it within scope________________________________
Integrate due diligence into policies and risk-management systems, including a due diligence policy________________________________

Risk-based due diligence process (Arts. 5–16)

RequirementStatusOwnerEvidenceTarget date
Identify and assess actual and potential adverse human-rights and environmental impacts in own operations, subsidiaries and the chain of activities________________________________
Prevent and mitigate potential adverse impacts________________________________
Bring actual adverse impacts to an end and minimise their extent________________________________
Establish and maintain a complaints / notification mechanism________________________________
Monitor the effectiveness of the due diligence policy and measures (periodic assessment)________________________________
Publicly communicate on due diligence (annual statement)________________________________
Adopt and put into effect a climate-change transition plan compatible with limiting global warming to 1.5°C________________________________

SUMMARY & SIGN-OFF

  • Overall compliance status: ________
  • Reviewer: ________
  • Next review date: ________

Fields you complete are inserted into the document live. This template is general guidance only - not legal advice.