NIS2 checklist - get started step by step

Ten steps to go from "we don't know if we're in scope" to documented compliance with the Cybersecurity Act.

1

Find out if you're in scope

Check your sector against the 18 sectors covered by the Cybersecurity Act, and your size (medium/large). Not sure? Take our 1-minute self-test for a quick indication.

2

Register your organisation

Essential and important entities must register with the National Cybersecurity Center (NCSC), no later than 14 days after the obligation arises. Registration is sent encrypted to nis2anmalan@ncsc.se, and NCSC confirms receipt within two business days.

3

Get management on board

The board must approve the risk-management measures and undergo cybersecurity training - and can be held personally liable for gross negligence. Start there, not in the IT department.

4

Run a gap analysis

Map your current state against Article 21's ten requirements (next step) to see where the biggest gaps are before spending time on the wrong things.

5

Implement the ten baseline security measures

Risk analysis and policies, incident handling, business continuity planning, supply chain security, security in system acquisition and maintenance, effectiveness evaluation, cyber hygiene and training, cryptography, personnel security and access control, and multi-factor authentication.

6

Set up incident reporting routines

Three deadlines to be able to meet: early warning within 24 hours, formal notification within 72 hours, a final report within one month. Build the routine before you need it, not during an active incident.

7

Review your supply chain

Your suppliers and subcontractors need to maintain a reasonable security level - you're responsible for keeping track of that, not just your own environment.

8

Train staff on an ongoing basis

Cybersecurity training is a recurring requirement, not a one-off - for both management and staff generally.

9

Document everything

You need to be able to show your risk analysis, policies, training records, and incident logs during supervision - not just have done the work, but be able to prove it.

10

Keep it alive

The Cybersecurity Act is new, and the regulatory structure has already changed once since it came into force. Book a recurring check-in, not a one-off review.

Want to do it digitally instead?

This checklist can be run in Excel and email - or in a platform that keeps track of deadlines, documentation, and status for you automatically.

Get started as a customer

This checklist is a practical starting point, not an exhaustive legal requirements list. Contact us or a lawyer for a full assessment of your situation.

Take the self-testSee all 18 sectors