THREAT-WATCH logo

THREAT‑WATCH

FREE GUIDE + CALCULATOR

NIS2 Readiness Checklist & Fine Calculator

A working checklist based directly on the text of the NIS2 Directive (EU 2022/2555), plus a calculator for your essential/important classification and Article 34 fine exposure, localized to Greece's Law 5160/2024 and the NCSA.

NIS2 FINE & SCOPE CALCULATOR

Estimate Your NIS2 Exposure

Select your sector and size band, add your annual worldwide turnover, and get an estimate of your essential/important classification and maximum fine exposure under Article 34. This is a general estimate, not a legal determination.

This calculator gives a general, educational estimate based on the text of Directive (EU) 2022/2555 (Articles 3, 20, and 34) and Greece's transposition, Law 5160/2024. It doesn't account for every classification exception and isn't legal advice. Confirm your actual status with the NCSA or qualified counsel before making compliance decisions.

1. Confirm whether NIS2 applies to you

  • Does your organization operate in a named essential or important entity sector (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing of certain products, digital providers)?
  • Does your organization meet or exceed the medium-enterprise size thresholds (50+ employees or over €10M annual turnover/balance sheet), or are you specifically named regardless of size?
  • Have you checked your national transposition law? In Greece, that's Law 5160/2024, with the National Cybersecurity Authority (NCSA) as the competent authority. Exact scope and thresholds can vary slightly by EU member state.

2. Governance and accountability

  • Has your management body formally approved the organization's cybersecurity risk-management measures?
  • Does management oversee implementation, not just sign off once?
  • Are management body members receiving cybersecurity training so they can meaningfully assess risk, not just approve documents?
  • Do management members understand that NIS2 creates personal accountability for non-compliance with risk-management obligations?

3. The ten Article 21(2) risk-management measures

NIS2 requires 'appropriate and proportionate' technical, operational, and organizational measures covering all ten of the following areas.

  • 1. Risk analysis & information security policyDocumented policies for assessing and managing security risk across your systems.
  • 2. Incident handlingA defined process for detecting, responding to, and recovering from security incidents.
  • 3. Business continuity & crisis managementBackup management, disaster recovery, and crisis management procedures.
  • 4. Supply chain securitySecurity requirements covering your relationships with direct suppliers and service providers.
  • 5. Secure development & vulnerability handlingSecurity built into system acquisition, development, and maintenance, including vulnerability disclosure.
  • 6. Effectiveness assessmentPolicies and procedures to actually assess whether your risk-management measures work.
  • 7. Cyber hygiene & trainingBasic security practices and cybersecurity training for staff.
  • 8. Cryptography & encryptionPolicies on when and how cryptography and encryption are used.
  • 9. HR security, access control & asset managementPersonnel security policies, access control, and a real asset inventory.
  • 10. Authentication & secure communicationsMulti-factor or continuous authentication, and secured voice, video, text, and emergency communications.

4. Incident-reporting readiness (Article 23)

If a significant incident occurs, the clock starts the moment you become aware of it, not when you've finished investigating.

  • Early warning to your national CSIRT/authority within 24 hours of awareness.
  • Incident notification with initial severity and impact assessment within 72 hours.
  • Final report, including root cause and remedial measures, within one month.
  • Do you know who in your organization is responsible for filing each of these three reports, and do they know the deadlines apply from awareness, not confirmation?

5. Next steps

This checklist tells you what NIS2 requires. It doesn't tell you where you actually stand today. That's what a proper gap assessment is for, comparing your real controls against every item above and prioritizing what to fix first.

Sourced directly from the text of Directive (EU) 2022/2555 (NIS2), Articles 21 and 23. This checklist is general guidance, not legal advice; confirm exact obligations against your national transposition law.

Want help running the actual gap assessment?

We'll walk your environment against every item on this checklist and tell you exactly where you stand.