Fill in the details
0/1360 of 136 completed
Type below - the document on the right updates as you go.
NIS2 & CSDDD Compliance Self-Assessment Checklist
NIS2 & CSDDD COMPLIANCE SELF-ASSESSMENT CHECKLIST
ORGANISATION IDENTITY
- Entity name: ________
- Sector / principal activity: ________
- Organisation size (headcount / turnover / balance sheet): ________
- Assessment date: ________
- Responsible officer: ________
PART 1 — NIS2 DIRECTIVE (EU) 2022/2555
Scope determination
| Requirement | Status | Owner | Evidence | Target date |
|---|---|---|---|---|
| Determine whether the entity is an "essential entity" or an "important entity" | ________ | ________ | ________ | ________ |
| Confirm which sector(s) in Annex I (sectors of high criticality) apply | ________ | ________ | ________ | ________ |
| Confirm which sector(s) in Annex II (other critical sectors) apply | ________ | ________ | ________ | ________ |
| Verify size-cap thresholds and any size-cap exemptions | ________ | ________ | ________ | ________ |
Cybersecurity risk-management measures (Art. 21)
| Requirement | Status | Owner | Evidence | Target date |
|---|---|---|---|---|
| Policies on risk analysis and information system security | ________ | ________ | ________ | ________ |
| Incident handling | ________ | ________ | ________ | ________ |
| Business continuity, backup management and disaster recovery, and crisis management | ________ | ________ | ________ | ________ |
| Supply-chain security, including security aspects with direct suppliers and service providers | ________ | ________ | ________ | ________ |
| Security in acquisition, development and maintenance of systems, including vulnerability handling and disclosure | ________ | ________ | ________ | ________ |
| Policies and procedures to assess the effectiveness of risk-management measures | ________ | ________ | ________ | ________ |
| Basic cyber hygiene practices and cybersecurity training | ________ | ________ | ________ | ________ |
| Policies and procedures on the use of cryptography and, where appropriate, encryption | ________ | ________ | ________ | ________ |
| Human resources security, access control policies and asset management | ________ | ________ | ________ | ________ |
| Use of multi-factor authentication (MFA) or continuous authentication and secured communications | ________ | ________ | ________ | ________ |
Incident reporting obligations (Art. 23)
| Requirement | Status | Owner | Evidence | Target date |
|---|---|---|---|---|
| Process to submit an early warning to the CSIRT / competent authority within 24 hours of becoming aware of a significant incident | ________ | ________ | ________ | ________ |
| Process to submit an incident notification within 72 hours | ________ | ________ | ________ | ________ |
| Process to submit a final report no later than one month after the incident notification | ________ | ________ | ________ | ________ |
| Process to notify recipients of services of significant incidents, where appropriate | ________ | ________ | ________ | ________ |
Governance and management-body accountability (Art. 20)
| Requirement | Status | Owner | Evidence | Target date |
|---|---|---|---|---|
| Management body approves the cybersecurity risk-management measures | ________ | ________ | ________ | ________ |
| Management body oversees implementation of the measures | ________ | ________ | ________ | ________ |
| Management-body members follow cybersecurity training | ________ | ________ | ________ | ________ |
Registration with the competent authority
| Requirement | Status | Owner | Evidence | Target date |
|---|---|---|---|---|
| Register the entity and submit required information to the competent authority | ________ | ________ | ________ | ________ |
| Keep registration details (contacts, IP ranges, Member States of operation) up to date | ________ | ________ | ________ | ________ |
PART 2 — CORPORATE SUSTAINABILITY DUE DILIGENCE DIRECTIVE (EU) 2024/1760
Scope and integration
| Requirement | Status | Owner | Evidence | Target date |
|---|---|---|---|---|
| Determine whether the company meets the employee and net-turnover thresholds bringing it within scope | ________ | ________ | ________ | ________ |
| Integrate due diligence into policies and risk-management systems, including a due diligence policy | ________ | ________ | ________ | ________ |
Risk-based due diligence process (Arts. 5–16)
| Requirement | Status | Owner | Evidence | Target date |
|---|---|---|---|---|
| Identify and assess actual and potential adverse human-rights and environmental impacts in own operations, subsidiaries and the chain of activities | ________ | ________ | ________ | ________ |
| Prevent and mitigate potential adverse impacts | ________ | ________ | ________ | ________ |
| Bring actual adverse impacts to an end and minimise their extent | ________ | ________ | ________ | ________ |
| Establish and maintain a complaints / notification mechanism | ________ | ________ | ________ | ________ |
| Monitor the effectiveness of the due diligence policy and measures (periodic assessment) | ________ | ________ | ________ | ________ |
| Publicly communicate on due diligence (annual statement) | ________ | ________ | ________ | ________ |
| Adopt and put into effect a climate-change transition plan compatible with limiting global warming to 1.5°C | ________ | ________ | ________ | ________ |
SUMMARY & SIGN-OFF
- Overall compliance status: ________
- Reviewer: ________
- Next review date: ________
Fields you complete are inserted into the document live. This template is general guidance only - not legal advice.