The series tracks regulation back to specific files, commands, and
operational practices, and is explicit about which obligations live
on the host versus which are governance work outside it. Aimed at
sysadmins and ops leads working in regulated EU and UK
environments; useful adjacent to the
host-hardening and
data-tier-hardening tracks, which
provide most of the technical controls compliance frameworks
require.
After this series: NIS2 Article 21(2)’s ten measure areas map
cleanly onto specific files, commands, and configurations on your
box — and you can demonstrate each one on demand, with the technical
readiness checklist as the evidence pack.
Scope A technical self-assessment for entities in scope of the NIS2 Directive (Directive (EU) 2022/2555). Each item is a thing a sysadmin can verify on a host now — a command output, a config flag, a file’s contents, an external scan result — not a policy approval or a named role.
This is the box-level companion to nis2-infrastructure. That guide explains why each Article 21(2) measure matters and how to implement it; this checklist is the “is it actually configured?” layer.
...
Applies to: EU-established entities that fall in scope of NIS2 as essential or important entities, and the infrastructure teams that serve them. This is not legal advice — it is an infrastructure-focused reading of Article 21’s risk-management measures, intended to be operationally useful. Use it alongside formal legal review, not instead of it.
Why this matters NIS2 — the Network and Information Security Directive, Directive (EU) 2022/2555 — is the regulation a lot of sysadmins are told to “comply with” without ever being told what that means at the level of files, configurations, and procedures. The directive is short by EU standards and intentionally outcome-focused: it lists ten risk-management measure areas in Article 21(2) and asks each entity to implement “appropriate and proportionate” measures in each.
...