Fill in the details
0/1360 of 136 completed
Type below - the document on the right updates as you go.
The clauses below are blurred in the preview. Fill in your details, then pay once to unlock the full document and download it as Word & PDF.
Proceed to payment →🔒 Secure & private · ⚡ Instant download after payment · One-time payment · no subscription
NIS2 & CSDDD COMPLIANCE SELF-ASSESSMENT CHECKLIST
ORGANISATION IDENTITY
- Entity name: ________
- Sector / principal activity: ________
- Organisation size (headcount / turnover / balance sheet): ________
- Assessment date: ________
- Responsible officer: ________
PART 1 — NIS2 DIRECTIVE (EU) 2022/2555
Scope determination
| Requirement | Status | Owner | Evidence | Target date |
|---|---|---|---|---|
| Determine whether the entity is an "essential entity" or an "important entity" | ________ | ________ | ________ | ________ |
| Confirm which sector(s) in Annex I (sectors of high criticality) apply | ________ | ________ | ________ | ________ |
| Confirm which sector(s) in Annex II (other critical sectors) apply | ________ | ________ | ________ | ________ |
| Verify size-cap thresholds and any size-cap exemptions | ________ | ________ | ________ | ________ |
Cybersecurity risk-management measures (Art. 21)
| Requirement | Status | Owner | Evidence | Target date |
|---|---|---|---|---|
| Policies on risk analysis and information system security | ________ | ________ | ________ | ________ |
| Incident handling | ________ | ________ | ________ | ________ |
| Business continuity, backup management and disaster recovery, and crisis management | ________ | ________ | ________ | ________ |
| Supply-chain security, including security aspects with direct suppliers and service providers | ________ | ________ | ________ | ________ |
| Security in acquisition, development and maintenance of systems, including vulnerability handling and disclosure | ________ | ________ | ________ | ________ |
| Policies and procedures to assess the effectiveness of risk-management measures | ________ | ________ | ________ | ________ |
| Basic cyber hygiene practices and cybersecurity training | ________ | ________ | ________ | ________ |
| Policies and procedures on the use of cryptography and, where appropriate, encryption | ________ | ________ | ________ | ________ |
| Human resources security, access control policies and asset management | ________ | ________ | ________ | ________ |
| Use of multi-factor authentication (MFA) or continuous authentication and secured communications | ________ | ________ | ________ | ________ |
Incident reporting obligations (Art. 23)
| Requirement | Status | Owner | Evidence | Target date |
|---|---|---|---|---|
| Process to submit an early warning to the CSIRT / competent authority within 24 hours of becoming aware of a significant incident | ________ | ________ | ________ | ________ |
| Process to submit an incident notification within 72 hours | ________ | ________ | ________ | ________ |
| Process to submit a final report no later than one month after the incident notification | ________ | ________ | ________ | ________ |
| Process to notify recipients of services of significant incidents, where appropriate | ________ | ________ | ________ | ________ |
Governance and management-body accountability (Art. 20)
| Requirement | Status | Owner | Evidence | Target date |
|---|---|---|---|---|
| Management body approves the cybersecurity risk-management measures | ________ | ________ | ________ | ________ |
| Management body oversees implementation of the measures | ________ | ________ | ________ | ________ |
| Management-body members follow cybersecurity training | ________ | ________ | ________ | ________ |
Registration with the competent authority
| Requirement | Status | Owner | Evidence | Target date |
|---|---|---|---|---|
| Register the entity and submit required information to the competent authority | ________ | ________ | ________ | ________ |
| Keep registration details (contacts, IP ranges, Member States of operation) up to date | ________ | ________ | ________ | ________ |
PART 2 — CORPORATE SUSTAINABILITY DUE DILIGENCE DIRECTIVE (EU) 2024/1760
Scope and integration
| Requirement | Status | Owner | Evidence | Target date |
|---|---|---|---|---|
| Determine whether the company meets the employee and net-turnover thresholds bringing it within scope | ________ | ________ | ________ | ________ |
| Integrate due diligence into policies and risk-management systems, including a due diligence policy | ________ | ________ | ________ | ________ |
Risk-based due diligence process (Arts. 5–16)
| Requirement | Status | Owner | Evidence | Target date |
|---|---|---|---|---|
| Identify and assess actual and potential adverse human-rights and environmental impacts in own operations, subsidiaries and the chain of activities | ________ | ________ | ________ | ________ |
| Prevent and mitigate potential adverse impacts | ________ | ________ | ________ | ________ |
| Bring actual adverse impacts to an end and minimise their extent | ________ | ________ | ________ | ________ |
| Establish and maintain a complaints / notification mechanism | ________ | ________ | ________ | ________ |
| Monitor the effectiveness of the due diligence policy and measures (periodic assessment) | ________ | ________ | ________ | ________ |
| Publicly communicate on due diligence (annual statement) | ________ | ________ | ________ | ________ |
| Adopt and put into effect a climate-change transition plan compatible with limiting global warming to 1.5°C | ________ | ________ | ________ | ________ |
SUMMARY & SIGN-OFF
- Overall compliance status: ________
- Reviewer: ________
- Next review date: ________
Fields you complete are inserted into the document live. This template is general guidance only - not legal advice.