Your answers are saved on this device — never on our servers · Sign in

Fill in the details

0/136

0 of 136 completed

Type below - the document on the right updates as you go.

The clauses below are blurred in the preview. Fill in your details, then pay once to unlock the full document and download it as Word & PDF.

Proceed to payment

🔒 Secure & private · ⚡ Instant download after payment · One-time payment · no subscription

NIS2 & CSDDD Compliance Self-Assessment Checklist

NIS2 & CSDDD COMPLIANCE SELF-ASSESSMENT CHECKLIST

ORGANISATION IDENTITY

  • Entity name: ________
  • Sector / principal activity: ________
  • Organisation size (headcount / turnover / balance sheet): ________
  • Assessment date: ________
  • Responsible officer: ________

PART 1 — NIS2 DIRECTIVE (EU) 2022/2555

Scope determination

RequirementStatusOwnerEvidenceTarget date
Determine whether the entity is an "essential entity" or an "important entity"________________________________
Confirm which sector(s) in Annex I (sectors of high criticality) apply________________________________
Confirm which sector(s) in Annex II (other critical sectors) apply________________________________
Verify size-cap thresholds and any size-cap exemptions________________________________

Cybersecurity risk-management measures (Art. 21)

RequirementStatusOwnerEvidenceTarget date
Policies on risk analysis and information system security________________________________
Incident handling________________________________
Business continuity, backup management and disaster recovery, and crisis management________________________________
Supply-chain security, including security aspects with direct suppliers and service providers________________________________
Security in acquisition, development and maintenance of systems, including vulnerability handling and disclosure________________________________
Policies and procedures to assess the effectiveness of risk-management measures________________________________
Basic cyber hygiene practices and cybersecurity training________________________________
Policies and procedures on the use of cryptography and, where appropriate, encryption________________________________
Human resources security, access control policies and asset management________________________________
Use of multi-factor authentication (MFA) or continuous authentication and secured communications________________________________

Incident reporting obligations (Art. 23)

RequirementStatusOwnerEvidenceTarget date
Process to submit an early warning to the CSIRT / competent authority within 24 hours of becoming aware of a significant incident________________________________
Process to submit an incident notification within 72 hours________________________________
Process to submit a final report no later than one month after the incident notification________________________________
Process to notify recipients of services of significant incidents, where appropriate________________________________

Governance and management-body accountability (Art. 20)

RequirementStatusOwnerEvidenceTarget date
Management body approves the cybersecurity risk-management measures________________________________
Management body oversees implementation of the measures________________________________
Management-body members follow cybersecurity training________________________________

Registration with the competent authority

RequirementStatusOwnerEvidenceTarget date
Register the entity and submit required information to the competent authority________________________________
Keep registration details (contacts, IP ranges, Member States of operation) up to date________________________________

PART 2 — CORPORATE SUSTAINABILITY DUE DILIGENCE DIRECTIVE (EU) 2024/1760

Scope and integration

RequirementStatusOwnerEvidenceTarget date
Determine whether the company meets the employee and net-turnover thresholds bringing it within scope________________________________
Integrate due diligence into policies and risk-management systems, including a due diligence policy________________________________

Risk-based due diligence process (Arts. 5–16)

RequirementStatusOwnerEvidenceTarget date
Identify and assess actual and potential adverse human-rights and environmental impacts in own operations, subsidiaries and the chain of activities________________________________
Prevent and mitigate potential adverse impacts________________________________
Bring actual adverse impacts to an end and minimise their extent________________________________
Establish and maintain a complaints / notification mechanism________________________________
Monitor the effectiveness of the due diligence policy and measures (periodic assessment)________________________________
Publicly communicate on due diligence (annual statement)________________________________
Adopt and put into effect a climate-change transition plan compatible with limiting global warming to 1.5°C________________________________

SUMMARY & SIGN-OFF

  • Overall compliance status: ________
  • Reviewer: ________
  • Next review date: ________

Fields you complete are inserted into the document live. This template is general guidance only - not legal advice.