Who the Regulation applies to
Article 21(5) of NIS2 required the Commission to spell out the security measures for providers whose services are highly cross-border. Implementing Regulation 2024/2690 does that for these "relevant entities":
- DNS service providers and TLD name registries
- cloud computing service providers and data centre service providers
- content delivery network providers
- managed service providers (MSPs) and managed security service providers (MSSPs)
- providers of online marketplaces, online search engines and social networking services platforms
- trust service providers
Whether you are an NIS2 entity at all still depends on NIS2 and your national law. Most of these types are in scope only from medium size upwards, while DNS service providers, TLD name registries and trust service providers are in scope regardless of size. If you are in scope and in this list, the Annex is your rulebook. The Regulation was published on 18 October 2024, entered into force twenty days later, and repealed the old NIS1 implementing regulation 2018/151.
Not in the list? The Annex is still the most detailed official reading of what Article 21 means, and many national authorities and customers use it as a benchmark. Suppliers answering NIS2 questionnaires will recognise most of its items (see our questionnaire guide).
Proportionality and "where appropriate"
Article 2(2) asks for a level of security appropriate to the risks. Entities must take account of their exposure to risk, their size, and the likelihood and severity of incidents. Many requirements carry qualifiers such as "where appropriate". If you decide one does not apply to you, you must "in a comprehensible manner document [your] reasoning". The checklist below has an N/A (reasoned) status for exactly this. Use the note field for the reason, and export it.
Several requirements also scale with size explicitly. For example, small entities may combine the security role with other duties (1.2.4) and may use alternative measures for impartial independent reviews (2.3.2).
The 13 domains at a glance
| Annex | Domain | NIS2 | Main ISO 27001:2022 links (ENISA) |
|---|---|---|---|
| 1 | Security policy, roles and responsibilities | 21(2)(a) | 5.2, 5.3, A.5.1–A.5.4 |
| 2 | Risk management, compliance monitoring, independent review | 21(2)(a) | 6.1–6.2, 8.2–8.3, 9.2, A.5.35, A.5.36 |
| 3 | Incident handling, logging, event reporting, response, post-incident review | 21(2)(b) | A.5.24–A.5.28, A.6.8, A.8.15–A.8.17 |
| 4 | Business continuity, backups, redundancy, crisis management | 21(2)(c) | A.5.29, A.5.30, A.8.13, A.8.14 |
| 5 | Supply chain security and supplier directory | 21(2)(d) | A.5.19–A.5.22, A.8.30 |
| 6 | Acquisition, secure development, configuration, change, testing, patching, network security and segmentation, malware, vulnerabilities | 21(2)(e) | A.5.23, A.8.7–A.8.9, A.8.20, A.8.22, A.8.25–A.8.34 |
| 7 | Assessing the effectiveness of measures | 21(2)(f) | 6.2, 9.1, 9.3 |
| 8 | Awareness, cyber hygiene and security training | 21(2)(g) | 7.2, 7.3, A.6.3 |
| 9 | Cryptography and key management | 21(2)(h) | A.8.24 |
| 10 | Human resources security, background checks, leavers, discipline | 21(2)(i) | A.6.1–A.6.5 |
| 11 | Access control, privileged accounts, identities, authentication, MFA | 21(2)(i), (j) | A.5.15–A.5.18, A.8.2, A.8.3, A.8.5, A.8.18 |
| 12 | Asset classification, handling, removable media, inventory, return | 21(2)(i) | A.5.9–A.5.14, A.7.7, A.7.10 |
| 13 | Utilities, physical and environmental threats, perimeter and access | 21(2)(c), (e), (i) | A.7.1–A.7.5, A.7.11 |
Interactive checklist
Each item below summarises one Annex point in our own words. Read the legal text for the exact obligations, especially the lists of required log types (3.2.3), backup plan contents (4.2.2), contract clauses (5.1.4) and key management steps (9.2(c)). Set a status for each item. Your progress is saved in this browser and encoded in the page link, so you can share it with a colleague. Notes stay on your device. Export a CSV to use it as a gap list.
Loading the 49 requirement groups…
Using the ISO 27001 mapping
The ISO references come from ENISA's mapping table to its Technical Implementation Guidance (version 1.2, 21 August 2025). Entries starting with "A." are Annex A controls. Entries without it, such as 6.1 or 9.3, are clauses of the ISO 27001 management system. Keep three caveats in mind:
- ENISA warns the table is not an equivalence. An ISO 27001 certificate does not prove compliance with the Regulation, which is in places more specific. Examples: management review of the policy at least yearly (1.1.2), quarterly checks for recurring incidents (3.4.2(b)), backups stored off-network at a distance (4.2.2(c)), and plans for modern e-mail security standards and current network protocols (6.7.2(j)–(k)).
- Check your Statement of Applicability. If you excluded a mapped Annex A control, the corresponding NIS2 requirement likely needs separate work or a documented reason.
- Scope matters. Your ISMS scope must cover the services that make you an NIS2 entity.
For the 10.4 disciplinary process, ENISA's table lists "5.28", which does not exist as an ISO 27001 clause. We show it as A.5.28 (collection of evidence) next to A.6.4 (disciplinary process).
The ENISA guidance also suggests concrete evidence for each requirement: approved policy versions, risk treatment plans, test reports, training records. Those make good attachments for each checklist item.
Significant incidents
Articles 3 to 14 of the Regulation define when an incident at these entities is "significant" and must be reported under NIS2 Article 23 (24-hour early warning, 72-hour notification, final report within one month). There are general criteria, such as financial loss above EUR 500 000 or 5% of annual turnover (whichever is lower), and entity-specific ones, such as unavailability thresholds for cloud and DNS. Recurring incidents with the same apparent root cause can be significant together. Use our NIS2 significant-incident checker to walk through the criteria for your entity type.
Turn the gap list into owned, recurring controls
Dazr Compliance's NIS2 framework includes these Annex requirements as recurring controls with owners, due dates and evidence. Together with the ISO 27001 Statement of Applicability, the same evidence serves both. It also covers the incident register with NIS2 clocks and the significant-incident checker.
FAQ
Does Implementing Regulation 2024/2690 apply to my company?
Its security requirements apply to NIS2 entities that are DNS service providers, TLD name registries, cloud computing, data centre and CDN providers, managed service and managed security service providers, online marketplaces, search engines, social networks and trust service providers. Other NIS2 entities follow their national implementation of Article 21, but the Annex is a useful benchmark.
Is ISO 27001 certification enough for 2024/2690?
No, but it covers a large share. ENISA's mapping links every Annex requirement to ISO 27001:2022 clauses or Annex A controls, but ENISA states this is not an equivalence. The Regulation adds specific requirements, such as annual policy review by management and quarterly checks for recurring incidents.
Can I mark requirements as not applicable?
Only those qualified with "where appropriate", "where applicable" or "to the extent feasible", and you must document your reasoning in a comprehensible manner (Article 2(2)). Use the N/A status and the note field in the checklist.
Where is my checklist data stored?
Only in your browser (localStorage) and, for statuses, in the page URL so you can share it. Nothing is sent to Dazr. Clearing site data removes it, so export a CSV regularly.
Related
Sources (as of 1 October 2026)
- Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024, OJ L 18 October 2024, Articles 2 to 16 and Annex.
- Directive (EU) 2022/2555 (NIS2), Articles 21 and 23.
- ENISA, NIS2 Technical Implementation Guidance, 26 June 2025, and its mapping table v1.2 (21 August 2025).
The summaries are our own plain-language reading of the Annex as of 1 October 2026, not the legal text, and not legal advice.