Fill in the details

0/136

0 of 136 completed

Type below - the document on the right updates as you go.

Save my document

NIS2 & CSDDD Compliance Self-Assessment Checklist

NIS2 & CSDDD COMPLIANCE SELF-ASSESSMENT CHECKLIST

ORGANISATION IDENTITY

  • Entity name: ________
  • Sector / principal activity: ________
  • Organisation size (headcount / turnover / balance sheet): ________
  • Assessment date: ________
  • Responsible officer: ________

PART 1 — NIS2 DIRECTIVE (EU) 2022/2555

Scope determination

RequirementStatusOwnerEvidenceTarget date
Determine whether the entity is an "essential entity" or an "important entity"________________________________
Confirm which sector(s) in Annex I (sectors of high criticality) apply________________________________
Confirm which sector(s) in Annex II (other critical sectors) apply________________________________
Verify size-cap thresholds and any size-cap exemptions________________________________

Cybersecurity risk-management measures (Art. 21)

RequirementStatusOwnerEvidenceTarget date
Policies on risk analysis and information system security________________________________
Incident handling________________________________
Business continuity, backup management and disaster recovery, and crisis management________________________________
Supply-chain security, including security aspects with direct suppliers and service providers________________________________
Security in acquisition, development and maintenance of systems, including vulnerability handling and disclosure________________________________
Policies and procedures to assess the effectiveness of risk-management measures________________________________
Basic cyber hygiene practices and cybersecurity training________________________________
Policies and procedures on the use of cryptography and, where appropriate, encryption________________________________
Human resources security, access control policies and asset management________________________________
Use of multi-factor authentication (MFA) or continuous authentication and secured communications________________________________

Incident reporting obligations (Art. 23)

RequirementStatusOwnerEvidenceTarget date
Process to submit an early warning to the CSIRT / competent authority within 24 hours of becoming aware of a significant incident________________________________
Process to submit an incident notification within 72 hours________________________________
Process to submit a final report no later than one month after the incident notification________________________________
Process to notify recipients of services of significant incidents, where appropriate________________________________

Governance and management-body accountability (Art. 20)

RequirementStatusOwnerEvidenceTarget date
Management body approves the cybersecurity risk-management measures________________________________
Management body oversees implementation of the measures________________________________
Management-body members follow cybersecurity training________________________________

Registration with the competent authority

RequirementStatusOwnerEvidenceTarget date
Register the entity and submit required information to the competent authority________________________________
Keep registration details (contacts, IP ranges, Member States of operation) up to date________________________________

PART 2 — CORPORATE SUSTAINABILITY DUE DILIGENCE DIRECTIVE (EU) 2024/1760

Scope and integration

RequirementStatusOwnerEvidenceTarget date
Determine whether the company meets the employee and net-turnover thresholds bringing it within scope________________________________
Integrate due diligence into policies and risk-management systems, including a due diligence policy________________________________

Risk-based due diligence process (Arts. 5–16)

RequirementStatusOwnerEvidenceTarget date
Identify and assess actual and potential adverse human-rights and environmental impacts in own operations, subsidiaries and the chain of activities________________________________
Prevent and mitigate potential adverse impacts________________________________
Bring actual adverse impacts to an end and minimise their extent________________________________
Establish and maintain a complaints / notification mechanism________________________________
Monitor the effectiveness of the due diligence policy and measures (periodic assessment)________________________________
Publicly communicate on due diligence (annual statement)________________________________
Adopt and put into effect a climate-change transition plan compatible with limiting global warming to 1.5°C________________________________

SUMMARY & SIGN-OFF

  • Overall compliance status: ________
  • Reviewer: ________
  • Next review date: ________

Fields you complete are inserted into the document live. This template is general guidance only - not legal advice.