NIS2 & CSDDD Compliance Self-Assessment Checklist

Valid in European Union

Create your NIS2 & CSDDD Compliance Self-Assessment Checklist for use in European Union. Answer a few plain-English questions and the document fills in automatically as you go - then download it in Word and PDF, ready to sign or share.

  • Answer 136 simple questions - the document fills in as you go
  • Live preview: watch your document update in real time
  • Download as Word (.docx) and PDF
  • Edit your answers and re-download anytime

How it works

  1. 1Answer a few simple questions
  2. 2Preview your document live
  3. 3Pay once - download in Word & PDF

Below you can preview the NIS2 & CSDDD Compliance Self-Assessment Checklist, complete it by answering a few plain-English questions, and download a ready-to-sign copy in Word and PDF — tailored for use in European Union.

What the NIS2 & CSDDD Compliance Self-Assessment Checklist includes

This template is organised into the following sections:

Frequently asked questions

What is a NIS2 & CSDDD Compliance Self-Assessment Checklist?

A NIS2 & CSDDD Compliance Self-Assessment Checklist is a ready-to-use legal template for European Union. You complete it by answering a few plain-English questions, then download the finished document in Word and PDF.

What does the NIS2 & CSDDD Compliance Self-Assessment Checklist cover?

The NIS2 & CSDDD Compliance Self-Assessment Checklist is organised into sections covering ORGANISATION IDENTITY, Entity name, Sector / principal activity, Organisation size (headcount / turnover / balance sheet), Assessment date, so the important points are captured in a clear, consistent structure.

What formats can I download?

You can download your completed NIS2 & CSDDD Compliance Self-Assessment Checklist as an editable Microsoft Word (.docx) file and as a PDF.

Can I edit the document later?

Yes — save it to your account and you can re-open, edit and re-download it at any time.

Prepared and reviewed by the LegalDocs team.

Document preview

NIS2 & CSDDD COMPLIANCE SELF-ASSESSMENT CHECKLIST

ORGANISATION IDENTITY

  • Entity name: ________
  • Sector / principal activity: ________
  • Organisation size (headcount / turnover / balance sheet): ________
  • Assessment date: ________
  • Responsible officer: ________

PART 1 — NIS2 DIRECTIVE (EU) 2022/2555

Scope determination

RequirementStatusOwnerEvidenceTarget date
Determine whether the entity is an "essential entity" or an "important entity"________________________________
Confirm which sector(s) in Annex I (sectors of high criticality) apply________________________________
Confirm which sector(s) in Annex II (other critical sectors) apply________________________________
Verify size-cap thresholds and any size-cap exemptions________________________________

Cybersecurity risk-management measures (Art. 21)

RequirementStatusOwnerEvidenceTarget date
Policies on risk analysis and information system security________________________________
Incident handling________________________________
Business continuity, backup management and disaster recovery, and crisis management________________________________
Supply-chain security, including security aspects with direct suppliers and service providers________________________________
Security in acquisition, development and maintenance of systems, including vulnerability handling and disclosure________________________________
Policies and procedures to assess the effectiveness of risk-management measures________________________________
Basic cyber hygiene practices and cybersecurity training________________________________
Policies and procedures on the use of cryptography and, where appropriate, encryption________________________________
Human resources security, access control policies and asset management________________________________
Use of multi-factor authentication (MFA) or continuous authentication and secured communications________________________________

Incident reporting obligations (Art. 23)

RequirementStatusOwnerEvidenceTarget date
Process to submit an early warning to the CSIRT / competent authority within 24 hours of becoming aware of a significant incident________________________________
Process to submit an incident notification within 72 hours________________________________
Process to submit a final report no later than one month after the incident notification________________________________
Process to notify recipients of services of significant incidents, where appropriate________________________________

Governance and management-body accountability (Art. 20)

RequirementStatusOwnerEvidenceTarget date
Management body approves the cybersecurity risk-management measures________________________________
Management body oversees implementation of the measures________________________________
Management-body members follow cybersecurity training________________________________

Registration with the competent authority

RequirementStatusOwnerEvidenceTarget date
Register the entity and submit required information to the competent authority________________________________
Keep registration details (contacts, IP ranges, Member States of operation) up to date________________________________

PART 2 — CORPORATE SUSTAINABILITY DUE DILIGENCE DIRECTIVE (EU) 2024/1760

Scope and integration

RequirementStatusOwnerEvidenceTarget date
Determine whether the company meets the employee and net-turnover thresholds bringing it within scope________________________________
Integrate due diligence into policies and risk-management systems, including a due diligence policy________________________________

Risk-based due diligence process (Arts. 5–16)

RequirementStatusOwnerEvidenceTarget date
Identify and assess actual and potential adverse human-rights and environmental impacts in own operations, subsidiaries and the chain of activities________________________________
Prevent and mitigate potential adverse impacts________________________________
Bring actual adverse impacts to an end and minimise their extent________________________________
Establish and maintain a complaints / notification mechanism________________________________
Monitor the effectiveness of the due diligence policy and measures (periodic assessment)________________________________
Publicly communicate on due diligence (annual statement)________________________________
Adopt and put into effect a climate-change transition plan compatible with limiting global warming to 1.5°C________________________________

SUMMARY & SIGN-OFF

  • Overall compliance status: ________
  • Reviewer: ________
  • Next review date: ________

Fields you complete are inserted into the document live. This template is general guidance only - not legal advice.