NIS2 Implementing Regulation 2024/2690: interactive checklist

If you are a cloud, data centre, CDN, DNS, managed (security) service, marketplace, search, social network or trust service provider, the NIS2 security measures are not left to national law: they are spelled out in the Annex of Commission Implementing Regulation (EU) 2024/2690. Work through all 49 requirement groups below, see which ISO 27001:2022 controls ENISA maps them to, and export your gap list.

Updated 1 October 20266 min readBy the Dazr Compliance team

At a glance

  • Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 sets the technical and methodological requirements behind NIS2 Article 21(2)(a) to (j) for eleven types of digital provider. It also defines when their incidents are significant.
  • Its Annex has 13 domains and 49 requirement groups, from the security policy (1.1) to physical access control (13.3).
  • It is a regulation, so it applies directly in every Member State. National transposition laws cannot water it down for these entity types.
  • Requirements marked "where appropriate", "where applicable" or "to the extent feasible" can be skipped only with a documented reason (Article 2(2)).
  • ENISA's June 2025 technical implementation guidance maps each group to ISO/IEC 27001:2022. If you are certified, much of the work is already done.

On this page

  1. Who the Regulation applies to
  2. Proportionality and "where appropriate"
  3. The 13 domains at a glance
  4. Interactive checklist
  5. Using the ISO 27001 mapping
  6. Significant incidents
  7. FAQ
  8. Related
  9. Sources (as of 1 October 2026)

Who the Regulation applies to

Article 21(5) of NIS2 required the Commission to spell out the security measures for providers whose services are highly cross-border. Implementing Regulation 2024/2690 does that for these "relevant entities":

  • DNS service providers and TLD name registries
  • cloud computing service providers and data centre service providers
  • content delivery network providers
  • managed service providers (MSPs) and managed security service providers (MSSPs)
  • providers of online marketplaces, online search engines and social networking services platforms
  • trust service providers

Whether you are an NIS2 entity at all still depends on NIS2 and your national law. Most of these types are in scope only from medium size upwards, while DNS service providers, TLD name registries and trust service providers are in scope regardless of size. If you are in scope and in this list, the Annex is your rulebook. The Regulation was published on 18 October 2024, entered into force twenty days later, and repealed the old NIS1 implementing regulation 2018/151.

Not in the list? The Annex is still the most detailed official reading of what Article 21 means, and many national authorities and customers use it as a benchmark. Suppliers answering NIS2 questionnaires will recognise most of its items (see our questionnaire guide).

Proportionality and "where appropriate"

Article 2(2) asks for a level of security appropriate to the risks. Entities must take account of their exposure to risk, their size, and the likelihood and severity of incidents. Many requirements carry qualifiers such as "where appropriate". If you decide one does not apply to you, you must "in a comprehensible manner document [your] reasoning". The checklist below has an N/A (reasoned) status for exactly this. Use the note field for the reason, and export it.

Several requirements also scale with size explicitly. For example, small entities may combine the security role with other duties (1.2.4) and may use alternative measures for impartial independent reviews (2.3.2).

The 13 domains at a glance

AnnexDomainNIS2Main ISO 27001:2022 links (ENISA)
1Security policy, roles and responsibilities21(2)(a)5.2, 5.3, A.5.1–A.5.4
2Risk management, compliance monitoring, independent review21(2)(a)6.1–6.2, 8.2–8.3, 9.2, A.5.35, A.5.36
3Incident handling, logging, event reporting, response, post-incident review21(2)(b)A.5.24–A.5.28, A.6.8, A.8.15–A.8.17
4Business continuity, backups, redundancy, crisis management21(2)(c)A.5.29, A.5.30, A.8.13, A.8.14
5Supply chain security and supplier directory21(2)(d)A.5.19–A.5.22, A.8.30
6Acquisition, secure development, configuration, change, testing, patching, network security and segmentation, malware, vulnerabilities21(2)(e)A.5.23, A.8.7–A.8.9, A.8.20, A.8.22, A.8.25–A.8.34
7Assessing the effectiveness of measures21(2)(f)6.2, 9.1, 9.3
8Awareness, cyber hygiene and security training21(2)(g)7.2, 7.3, A.6.3
9Cryptography and key management21(2)(h)A.8.24
10Human resources security, background checks, leavers, discipline21(2)(i)A.6.1–A.6.5
11Access control, privileged accounts, identities, authentication, MFA21(2)(i), (j)A.5.15–A.5.18, A.8.2, A.8.3, A.8.5, A.8.18
12Asset classification, handling, removable media, inventory, return21(2)(i)A.5.9–A.5.14, A.7.7, A.7.10
13Utilities, physical and environmental threats, perimeter and access21(2)(c), (e), (i)A.7.1–A.7.5, A.7.11

Interactive checklist

Each item below summarises one Annex point in our own words. Read the legal text for the exact obligations, especially the lists of required log types (3.2.3), backup plan contents (4.2.2), contract clauses (5.1.4) and key management steps (9.2(c)). Set a status for each item. Your progress is saved in this browser and encoded in the page link, so you can share it with a colleague. Notes stay on your device. Export a CSV to use it as a gap list.

Loading the 49 requirement groups…

Using the ISO 27001 mapping

The ISO references come from ENISA's mapping table to its Technical Implementation Guidance (version 1.2, 21 August 2025). Entries starting with "A." are Annex A controls. Entries without it, such as 6.1 or 9.3, are clauses of the ISO 27001 management system. Keep three caveats in mind:

  • ENISA warns the table is not an equivalence. An ISO 27001 certificate does not prove compliance with the Regulation, which is in places more specific. Examples: management review of the policy at least yearly (1.1.2), quarterly checks for recurring incidents (3.4.2(b)), backups stored off-network at a distance (4.2.2(c)), and plans for modern e-mail security standards and current network protocols (6.7.2(j)–(k)).
  • Check your Statement of Applicability. If you excluded a mapped Annex A control, the corresponding NIS2 requirement likely needs separate work or a documented reason.
  • Scope matters. Your ISMS scope must cover the services that make you an NIS2 entity.

For the 10.4 disciplinary process, ENISA's table lists "5.28", which does not exist as an ISO 27001 clause. We show it as A.5.28 (collection of evidence) next to A.6.4 (disciplinary process).

The ENISA guidance also suggests concrete evidence for each requirement: approved policy versions, risk treatment plans, test reports, training records. Those make good attachments for each checklist item.

Significant incidents

Articles 3 to 14 of the Regulation define when an incident at these entities is "significant" and must be reported under NIS2 Article 23 (24-hour early warning, 72-hour notification, final report within one month). There are general criteria, such as financial loss above EUR 500 000 or 5% of annual turnover (whichever is lower), and entity-specific ones, such as unavailability thresholds for cloud and DNS. Recurring incidents with the same apparent root cause can be significant together. Use our NIS2 significant-incident checker to walk through the criteria for your entity type.

Turn the gap list into owned, recurring controls

Dazr Compliance's NIS2 framework includes these Annex requirements as recurring controls with owners, due dates and evidence. Together with the ISO 27001 Statement of Applicability, the same evidence serves both. It also covers the incident register with NIS2 clocks and the significant-incident checker.

FAQ

Does Implementing Regulation 2024/2690 apply to my company?

Its security requirements apply to NIS2 entities that are DNS service providers, TLD name registries, cloud computing, data centre and CDN providers, managed service and managed security service providers, online marketplaces, search engines, social networks and trust service providers. Other NIS2 entities follow their national implementation of Article 21, but the Annex is a useful benchmark.

Is ISO 27001 certification enough for 2024/2690?

No, but it covers a large share. ENISA's mapping links every Annex requirement to ISO 27001:2022 clauses or Annex A controls, but ENISA states this is not an equivalence. The Regulation adds specific requirements, such as annual policy review by management and quarterly checks for recurring incidents.

Can I mark requirements as not applicable?

Only those qualified with "where appropriate", "where applicable" or "to the extent feasible", and you must document your reasoning in a comprehensible manner (Article 2(2)). Use the N/A status and the note field in the checklist.

Where is my checklist data stored?

Only in your browser (localStorage) and, for statuses, in the page URL so you can share it. Nothing is sent to Dazr. Clearing site data removes it, so export a CSV regularly.

Sources (as of 1 October 2026)

The summaries are our own plain-language reading of the Annex as of 1 October 2026, not the legal text, and not legal advice.