NIS2 audit: the checklist we actually use in-house
52 items grouped into 10 macro-areas. One day of work for the first pass, half a day for subsequent ones.
Tag
10 articles
52 items grouped into 10 macro-areas. One day of work for the first pass, half a day for subsequent ones.
Essential and important sectors, size thresholds and the borderline cases (supply chain, IT providers) that often think they are out of scope.
Article 21 lists ten mandatory areas. We map them to concrete controls already in ISO 27001 and NIST CSF, avoiding duplicate work.
The dates that matter (registration, notification, controls) and the actual numbers of fines ACN can issue. What has already happened in 2025-2026.
What NIS2 demands on business continuity and DR. Article 21, Italian deadlines, penalties and a concrete checklist to reach compliance.
NIS2 entities must assess their IT suppliers. What to ask, what to require contractually, what to accept as an attestation.
Concrete differences between essential and important entities: controls, maximum fines, audit frequency. Examples for each category.
Overlaps, differences and the seven areas where a GDPR-compliant company is already halfway to NIS2 readiness.
What to file at each of the three notification deadlines. Early-warning template and the three mistakes that make a filing officially "late".
Mapping the ten Article 21 areas to Sefthy features. What we solve directly, what stays your responsibility.