NIS 2 assessment: a self-assessment checklist for SMEs

Your company has just found out it falls under NIS 2. A self-assessment to run before an ACN review or an external audit: confirm scope, find the measures for essential or important entities, answer a checklist by function with the evidence for each question, score the gaps and decide what to fix first.

October 09, 2026 10 min read

Auditor working through binders and printed documents with a highlighter Made with AI
Contents
  1. In brief
  2. First question: are you in NIS 2 scope
  3. Which measures apply: essential and important entities
  4. Self-assessment checklist by function
  5. How to score the gaps and choose priorities
  6. Self-assessment, external assessment, audit: differences and when you need each
  7. The next step

You have just found out that your company falls under NIS 2. Before calling an auditor, it pays to know where you stand on your own: whether the scope is confirmed, which measures apply to you, which evidence you already have and which is missing. This guide is a self-assessment checklist built on D.Lgs. 138/2024 and on the baseline measures of Italy's National Cybersecurity Agency (ACN, Agenzia per la Cybersicurezza Nazionale), meant for whoever fills it in from inside the company.

In brief

  • Start from scope: the sector in the annexes of the decree, the size of the company and the cases that apply regardless of size.
  • The measures to check depend on the category: 37 for important entities and 43 for essential entities, in ACN determination 379907/2025.
  • The checklist follows the six functions of the ACN measures (GV, ID, PR, DE, RS, RC): each question has a yes or no answer and a piece of evidence that proves it.
  • A "yes" without dated evidence, approved by the management bodies where required, counts for half.
  • Priorities come from obligations with a running deadline and from the measures the others depend on, even before the score.

First question: are you in NIS 2 scope

The decree applies to public and private entities of the types listed in Annexes I to IV (D.Lgs. 138/2024, art. 3). For a private company there are three questions.

  1. Sector. Annex I lists the sectors of high criticality (for example energy, transport, health, water, digital infrastructure, business-to-business ICT service management). Annex II lists the other critical sectors (for example postal services, waste, chemicals, food, manufacturing of certain products, digital providers, research).
  2. Size. For the sectors of Annexes I and II the decree applies to companies above the small enterprise ceilings of Recommendation 2003/361/EC: in practice medium and large companies (art. 3, paragraph 2). Partner and linked enterprises count too, under the rules of the same Recommendation (art. 3, paragraph 4).
  3. Exceptions. Some types are in scope regardless of size (art. 3, paragraph 5). They are providers of public electronic communications networks and publicly available services, trust service providers, top-level domain registries and DNS service providers, and domain name registration services. The same applies to entities identified as critical under Directive (EU) 2022/2557. ACN can also designate entities of any size, for example the sole national provider of an essential service (art. 3, paragraph 9). A company linked to a NIS entity is also in scope when, for example, it manages that entity's information systems or provides it with ICT or security services (art. 3, paragraph 10).

For a first indication you can use the NIS 2 scope check: enter sector and size and get an indicative outcome with the article of the decree behind it. The outcome does not account for linked enterprises or ACN designations. Confirmation comes from the ACN platform: from 1 January to 28 February each year entities register, and ACN notifies their inclusion in the list (art. 7).

Which measures apply: essential and important entities

Essential entities include Annex I companies above the medium enterprise ceilings and medium-sized electronic communications providers. Qualified trust service providers, top-level domain registries and DNS service providers are essential regardless of size. All other entities in scope are important, unless ACN designates them otherwise (art. 6).

The category decides two things for the self-assessment:

  • Which measures. ACN determination no. 379907 of 19 December 2025 sets 37 measures for important entities (Annex 1) and 43 for essential entities (Annex 2); the significant incidents to notify are in Annexes 3 and 4 (ACN determination 379907/2025, ACN, baseline specifications).
  • How you are checked. ACN can review documents, carry out on-site and remote inspections and request data. For important entities these powers apply only when ACN receives evidence of possible breaches (art. 36).

The deadlines run from the notice of inclusion in the list: nine months for incident notification and eighteen for the measures. For entities added for the first time in 2026, notification applies from 1 January 2027 and the measures must be in place by 31 July 2027 (ACN determination 127434/2026). The differences between the two annexes are in our guide to essential and important entities in the baseline specifications; a summary of the obligations is in our article on the baseline measures set by ACN.

Self-assessment checklist by function

The questions follow the six functions of the ACN measures and, unless stated, apply to both categories; the codes refer to Annex 1 (ACN determination 379907/2025, Annex 1). They do not cover every measure: they are there to show you quickly where you stand. For each question ask yourself two things: is the answer yes? And could you show the evidence to an inspector who asks for it?

ACN leaves room on evidence: each entity decides how to organize its documentation, in one document or several, on paper or digital, as long as it is easy to consult for those who need it. Some documents require approval by the management bodies (ACN, reading guide to the baseline specifications).

GV, govern

QuestionEvidenceMeasure
Do you keep an up-to-date list of the network and information systems relevant to the NIS services?List of relevant systems with its update dateGV.OC-04
Is there a cybersecurity organization approved by the management bodies, with a named point of contact and CSIRT contact person?Approval record, up-to-date list of staff with roles and deputiesGV.RR-02
Do the security policies cover the required areas, are they approved by the management bodies and reviewed at least yearly?Signed, dated policies, outcome of the last reviewGV.PO-01, GV.PO-02
Do you know which suppliers can affect security, and do the contracts state the requirements?Supplier inventory with contact and type of supply, security clauses, risk assessment per supplyGV.SC-04, GV.SC-05, GV.SC-07

ID, identify

QuestionEvidenceMeasure
Are the hardware, software and service inventories, including supplier services, up to date?Inventories with their update dateID.AM-01, ID.AM-02, ID.AM-04
Is the risk assessment less than two years old and approved by the management bodies?Assessment document, approval recordID.RA-05
Is there a treatment plan with priorities, owners and timing, and have the management bodies accepted the residual risks?Approved treatment planID.RA-06
Do you have business continuity, disaster recovery and crisis management plans for the relevant systems?Plans approved by the management bodies, reviewed at least every two yearsID.IM-04

PR, protect

QuestionEvidenceMeasure
Does multi-factor authentication protect at least the relevant systems, according to the risk assessment?Active configuration, documented procedurePR.AA-03
Do staff, including the management bodies, follow a training plan approved by those bodies?Training plan, register of participants and contentPR.AT-01
Do you back up data and configurations periodically, with offline copies for the relevant systems?Backup procedure, log of runs, evidence of offline copiesPR.DS-11
Do you install security updates without undue delay and run only software the vendor still updates?Update management procedure, justified and documented exceptionsPR.PS-02

DE, detect

QuestionEvidenceMeasure
Are there tools on the relevant systems that detect significant incidents in time?List of tools and their configuration, procedureDE.CM-01
Have you defined expected service levels, to tell when a disruption becomes a significant incident?Service level document for the NIS servicesDE.CM-01
Are remote access and access with administrative privileges logged, and are the logs kept for a set period?Securely stored logs, documented retention periodsPR.PS-04
Do devices have an up-to-date system for detecting malicious code?Endpoint coverage, procedureDE.CM-09

RS, respond

QuestionEvidenceMeasure
Is there a plan for incident management and notification to CSIRT Italia, approved by the management bodies?Approved plan, reviewed at least every two yearsRS.MA-01
Would the person on duty know how to send the early warning within 24 hours and the notification within 72 hours?Procedure with roles, contacts and templates for early warning, notification and reportsRS.MA-01; D.Lgs. 138/2024, art. 25
Do you have a procedure to inform customers of a significant incident that affects them?Documented communication procedureRS.CO-02

RC, recover

QuestionEvidenceMeasure
Does the incident management plan include procedures to bring affected systems back into operation?Recovery procedures in the planRC.RP-01
Does the disaster recovery plan set the order of recovery and the recovery objectives?Plan with priorities and objectives per operationID.IM-04
Essential entities only: do you have procedures to communicate recovery activities internally after an incident?Documented communication procedureRC.CO-03 (Annex 2)

Notification runs on tight deadlines: early warning within 24 hours of becoming aware of the significant incident, notification within 72 hours, final report within one month of the notification (art. 25). That is why the RS questions should be tested with an exercise, not just read.

How to score the gaps and choose priorities

For a self-assessment a three-value scale per question is enough:

  • 2: yes, with dated evidence and, where required, approval by the management bodies;
  • 1: yes in practice, but the evidence is missing, out of date or not approved;
  • 0: no.

Add up the points per function and compare them with the maximum. The result tells you which function is most exposed, but not where to start. For that you need three criteria, in this order.

  1. Obligations with a deadline or an external recipient. Registration and updates on the platform, the CSIRT contact person, the notification plan and procedures. Notification has a shorter deadline than the measures and involves CSIRT Italia: a 0 here comes before anything else.
  2. Measures the others depend on. Many ACN measures refer back to the policies of GV.PO-01 and to the risk assessment of ID.RA-05: procedures are adopted in line with the policies, while authentication, log retention and permitted software follow the outcome of the assessment. Backups, too, follow the continuity plans of ID.IM-04. Until these exist, the other answers rest on nothing.
  3. Exposure of the relevant systems. Among the remaining gaps, first those that leave the relevant systems exposed: multi-factor authentication, offline backup copies, security updates, detection.

The 1s deserve separate attention: often the control exists and only the document or the signature is missing. They are the quickest gaps to close and the first ones an inspector notices. The result goes into a remediation plan with actions, owners and timing, which the management bodies approve (ID.IM-01): our guide to the NIS 2 remediation plan explains how to set it up.

Self-assessment, external assessment, audit: differences and when you need each

Self-assessmentExternal assessmentAudit
Who does itInternal staffAn outside party with a structured methodA reviewer independent of the work under review
QuestionWhere are we?Where are we against a reference, and where do we start?Does the evidence prove the requirements?
ResultA list of gaps and a first order of priorityA profile with reasoned prioritiesDocumented findings and a remediation plan
WhenRight after scope is confirmed, then at every reviewWhen you want an outside view before investingBefore an ACN or customer review, and at regular intervals

A self-assessment is not only an internal exercise. The decree allows ACN to ask entities to report on the state of implementation of their obligations, including self-assessments and implementation plans, and to require security audits, periodic or targeted (art. 35). A checklist filled in with its evidence is therefore already a useful document.

The auditor's side is covered in our operational checklist for the NIS 2 documentation audit, and the handling of findings in our article on prioritizing NIS 2 findings.

The next step

If you want a first picture before filling in the checklist, the Cyber Check-up follows the same logic: a first block of questions for management, then a technical block the IT contact answers, and a report organized on the NIST CSF 2.0 functions, the same ones as the ACN measures.

Once the checklist is filled in and the evidence collected, we can check your documents against the requirements with you through the NIS 2 documentation audit, which returns findings and a remediation plan.

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

October 08, 2026

NIS 2 vs ISO 27001: what certification covers and the gaps

Your company holds or plans ISO/IEC 27001 and falls under NIS 2. What the certification already covers, the obligations D.Lgs. 138/2024 adds (registr…

September 27, 2026

NIS Reinforced Security Measures: ACN Opens the Consultation

On 18 September 2026 ACN opened a sector consultation on reinforced NIS security measures, meant to supplement and replace the baseline measures. The…

September 27, 2026

ACN NIS Vademecum 2026: Compliance Calendar and Operational Checklist

ACN's NIS Vademecum 1.0 (September 2026) puts the NIS obligations on one calendar: six obligation families, three recurring annual windows and differ…