NIS2Compass — NIS2-Compliance-Plattform
Use CasesPricing
Go to platform

Weiterführende Seiten

  • Blog
  • FAQ
  • Glossar
  • Use Cases
  • Branchen
  • Preisgestaltung

Offizielle Quellen

  • BSI – Bundesamt für Sicherheit in der Informationstechnik
  • NIS2-Richtlinie (EUR-Lex)
  • NIS2UmsuCG (Bundesgesetzblatt)
NIS2Compass — NIS2-Compliance-Plattform

Ihr Navigator durch die NIS2-Compliance

Rechtliches

  • Datenschutzerklärung
  • Allgemeine Geschäftsbedingungen
  • Cookie-Richtlinie
  • Impressum

Ressourcen

  • Blog
  • Use Cases
  • Branchen
  • Preise
  • FAQ
  • Glossar

Kontakt

Kontakt

kontakt@nis2compass.de

NIS2Compass bietet Informationen und Orientierungshilfen zur NIS2-Compliance. Die Inhalte stellen keine Rechtsberatung im Sinne des Rechtsdienstleistungsgesetzes (RDG) dar und ersetzen keine individuelle rechtliche oder fachliche Beratung.

© Copyright 2026 NIS2Compass. Alle Rechte vorbehalten.

Entwickelt in DeutschlandAllianz für Cyber-Sicherheit — Teilnehmer
Home/Blog/NIS2 Checklist as an Excel Template: the 10 §30 Obligations
Guide

NIS2 Checklist as an Excel Template: the 10 §30 Obligations

Authored by NIS2Compass Experten, NIS2 Compliance Expert
Last updated:July 1, 20268 min read
Stylised checklist with checkmarks and section-sign symbols in dark blue and teal – symbolising the NIS2 checklist as an Excel template

Turn the 10 minimum measures from §30 BSIG into an Excel checklist: a 6-step build, ISO 27001 mapping, and common mistakes. With the free NIS2Compass Pre-Check.

A NIS2 checklist translates the 10 minimum measures from §30 BSIG into trackable tasks. An Excel template is the most pragmatic format for this: structured, filterable, and free of specialised software. NIS2Compass provides this framework along with the templates. Where you stand today and which of the ten obligations are still open is shown in minutes by the free Pre-Check.

What belongs in a NIS2 checklist under §30 BSIG?

The 10 minimum measures from §30 (2) BSIG form the substantive backbone of every NIS2 checklist. They have been binding without transition periods since 6 December 2025. NIS2Compass structures each of these obligations as its own item, complete with tasks and evidence.

  1. Risk analysis and security concepts: A documented risk assessment and security concepts for your information systems, kept as evidence.
  2. Handling security incidents: An incident-handling process with reporting paths, roles, and logging of every incident.
  3. Business continuity: Business continuity, backup management, recovery procedures, and crisis management, each demonstrably tested.
  4. Supply chain security: Assessment and contractual safeguarding of critical suppliers and service providers.
  5. Security in procurement, development, and maintenance: Secure procurement and maintenance processes, including vulnerability management.
  6. Assessing effectiveness: Procedures that regularly check whether the risk measures actually work.
  7. Cyber hygiene and training: Basic security practices and demonstrable training for employees.
  8. Cryptography and encryption: Concepts and rules for the use of encryption.
  9. Personnel security, access control, asset management: Governed access rights, personnel security, and a maintained asset inventory.
  10. Multi-factor authentication and secured communication: MFA, secured communication, and secured emergency communication.

A good checklist does not just tick off measures; it captures the specific evidence and documentation for each item. That is what §30 demands with its requirement of demonstrability, and §38 BSIG, under which management must approve and oversee the measures, a duty that cannot be delegated.

Why is Excel a suitable format for the NIS2 checklist?

Excel is the most pragmatic format for the NIS2 checklist because it is available without a licensing hurdle, without a rollout project, and is familiar to every SME team. §30 BSIG requires demonstrable documentation of the measures. A structured table meets this requirement immediately, without having to introduce new software.

The key advantages at a glance:

  • Ready to use immediately: No licence costs, no rollout project. Any team can open the template and start filling it in.
  • Versionable: Every revision can be saved as its own file. This keeps progress traceable over time.
  • Status columns and filters: Open, in-progress, and completed measures can be flagged and filtered as needed.
  • Shareable with management: §38 BSIG requires management to oversee the measures. A compact table delivers the status overview that is needed.
  • Mapping-friendly: Each obligation can be linked to references to internal documents, policies, or responsible owners.

Excel has clear limits. It offers no real-time collaboration like dedicated GRC software, maintenance is manual, and automatic reminders are missing. For larger organisations with many stakeholders, that can become a burden. For most SMEs with an IT department of 3 to 10 people, however, a well-maintained Excel file is enough to demonstrate the §30 obligations in a structured way.

NIS2Compass provides ready-made Word and Excel templates, each assigned to a §30 implementation step. This means you do not have to build the checklist from scratch but can draw on a reviewed structure instead. An overview of all available NIS2 templates can be found in the Template Library.

How do you build the NIS2 checklist step by step?

In six steps, the 10 §30 measures become a maintainable Excel checklist. The path leads from clarifying applicability through the column structure to the review cycle. The result is a document that demonstrably meets §30 and §38 BSIG.

  1. Clarify applicability and entity type. First determine whether your company qualifies as an essential or important entity. The free Pre-Check from NIS2Compass gives you an initial assessment in minutes.
  2. Set up the 10 §30 measures as rows. Adopt the ten minimum measures from §30 (2) BSIG as fixed rows. Break down extensive measures such as risk management or supply chain security into sensible subtasks.
  3. Define the column structure. Create the following columns for each measure:

- Requirement: a concrete description of the obligation per §30 item

- Status: met, partially met, or open

- Owner: a named person or role

- Evidence/document: the assigned policy or template

- Due date: implementation or review date

- Gap/action: outstanding action required

  1. Assess the current state of each measure. Carry out a gap analysis and rate each measure as met, partially met, or open. This makes your maturity transparent and helps you prioritise the next steps.
  2. Link evidence and documents. §30 BSIG requires demonstrability. Therefore link each measure to the supporting document, such as a policy, a log, or a contract.
  3. Define the review cycle and reporting. §38 BSIG obliges management to approve and oversee the measures. Define fixed review dates and regular reporting to the management level.

How do you link the checklist with ISO 27001 and BSI IT-Grundschutz?

A mapping column connects each §30 measure with the matching ISO 27001 controls and BSI IT-Grundschutz building blocks. Anyone already using these frameworks avoids duplicate work. ISO 27001 does not, however, replace full NIS2 evidence.

The Excel checklist contains an additional column "ISO 27001 / BSI building block" next to each of the ten §30 obligations. There you enter the control or building block that already covers the respective measure.

This approach saves considerable effort. Existing documents can be reused directly: anyone who has documented risk treatment under ISO 27001 references it in the mapping column instead of starting over.

This way, you see at a glance which §30 measures are already evidenced and where genuine gaps remain. This is especially efficient for companies with an existing ISMS. The official BSI IT-Grundschutz building blocks provide the reference needed for the mapping.

Which NIS2 obligations does ISO 27001 not cover?

An ISO 27001 certificate is not automatic NIS2 evidence. Several legal obligations lie outside the classic ISMS scope:

  • Registration (§33 BSIG): Registering with the BSI is a legal obligation, not an ISMS topic.
  • Reporting obligations (§32 BSIG): The deadlines and procedures for security incidents are not governed by ISO 27001.
  • Management liability (§38 BSIG): The personal responsibility of the management bodies is not recognised by ISO 27001 in this form.

On top of this: scope and risk acceptance may differ. An ISMS often covers only parts of the organisation, while §30 BSIG covers the entire affected company. More on this in the article Is ISO 27001 enough for NIS2?. The NIS2Compass Pre-Check additionally maps your answers to ISO 27001 and BSI IT-Grundschutz and shows which §30 obligations are already covered.

Which mistakes should you avoid with the NIS2 checklist?

The most common mistakes are a checklist without an evidence column, without named owners, and without a review cycle. It is ticked off once and then becomes outdated. The result is a document that formally fails to meet §30 BSIG because demonstrability is missing.

  • Ticking off once instead of ongoing maintenance: §30 requires demonstrability over time. Treat the checklist as a living document with a status history.
  • Missing evidence column: Without a reference to a policy, configuration, or log, implementation remains unevidenced. Link the specific artefact for each measure.
  • No named owners: A measure without an owner is rarely maintained. Enter a person or role for each of the 10 §30 obligations.
  • Management not involved: §38 BSIG requires approval and oversight by management. This duty cannot be delegated and belongs in the documentation.
  • No review cycle: Without fixed dates, the status becomes outdated. Define quarterly or semi-annual reviews with a date.
  • Only technical measures: Organisational obligations and supply chain security are often forgotten. Cover all three areas in the checklist.

The NIS2Compass experts observe in practice that many checklists appear technically complete but fail an audit due to missing documentation.

In practice: how a machine builder with 140 employees uses the checklist

A mid-sized machine builder with 140 employees falls under NIS2 as an important entity. The IT function consists of an IT lead and a small team without a dedicated information security officer.

The team uses an Excel checklist along the 10 §30 measures. In a first pass, a gap analysis is carried out: for each measure, the status is recorded and an open gap is flagged.

A responsible role is assigned to each obligation. In the evidence column, the team links the associated policy, configuration, or log. This produces a verifiable status rather than a mere tick.

Each quarter, the IT lead reports the status to management. Management approves and oversees the measures as §38 BSIG requires. Anyone looking to get started without external support will find guidance in the article Implementing NIS2 without a consultant.

The result is a documentable compliance status that can be demonstrated to the BSI. The scenario is anonymized and for illustration only.

Which NIS2 Excel Templates Does NIS2Compass Offer?

NIS2Compass delivers 45+ Word and Excel templates covering the entire implementation path – from risk analysis to management-level documentation under §38 BSIG. The NIS2 checklist is just the starting point.

Each template is mapped to a specific §30 BSIG implementation step, but can also be downloaded independently. That means: you grab the risk matrix or the report form directly, without working through the entire guide.

The library includes among others:

  • Asset inventory (Excel) and gap assessment (Excel) for §30 No. 1 – the foundation of any NIS2 implementation
  • Risk matrix and risk assessment register (Excel) for §30 No. 3 – with scoring logic and traffic-light status
  • Network security concept and vulnerability register (Word/Excel) for §30 No. 4
  • Incident response policy, report forms under §32 BSIG and IT emergency manual for §30 No. 2
  • Supplier security questionnaire and contract clause set (Excel/Word) for §30 No. 5
  • IS policy, access control policy, patch management policy (Word) for §30 No. 7
  • Management-level documentation under §38 BSIG

All templates contain QMS metadata (status date, version, responsible party) and a liability notice. The Template Library gives a full overview of all available templates.

Frequently Asked Questions

Is there an official NIS2 checklist from the BSI?

No, a binding official checklist does not exist. The substantive framework follows directly from the 10 minimum measures under §30 (2) BSIG. An Excel checklist is therefore not an official BSI form but an internal working and evidence document with which you document your implementation status in a structured way.

Is an Excel checklist sufficient for NIS2 compliance?

For structure, overview, and evidence, an Excel checklist is very useful. It does not, however, replace the actual implementation of the measures. You must additionally fulfil registration under §33 BSIG and the reporting processes under §32 BSIG. The checklist documents progress; it does not establish compliance itself.

How many measures must the NIS2 checklist cover?

At least the 10 minimum measures from §30 (2) BSIG. These include, among others, risk management, incident handling, business continuity, and supply chain security. Depending on the measure, it is advisable to break it down into concrete subtasks so that the implementation status per area remains traceable.

What does a NIS2 checklist cost?

A self-built Excel checklist costs only your working time. NIS2Compass additionally provides reviewed Word and Excel templates as well as an 8-chapter Guide. As a free starting point, you can use the Pre-Check, which captures your current status as a gap analysis and derives the appropriate steps.

Am I even affected by NIS2?

In Germany, around 29,500 companies are affected by NIS2. The classification is based on the sector and the company size. Whether your company falls under the obligations is best clarified through a structured check. The article Am I affected by NIS2? provides guidance.

Is there a free NIS2 checklist as an Excel download?

The BSI provides a free official NIS2 orientation checklist. If you need a fully structured template with status tracking, §30 BSIG mapping, evidence fields and a review cycle, the NIS2Compass template is part of the Pro subscription for €29/month, cancellable monthly. To get started at no cost, the Pre-Check analyses your NIS2 status and shows which §30 measures are still open.

Implement NIS2 step by step

NIS2Compass guides you step by step through implementation – with guide, templates and knowledge hub.

Get started

Ähnliche Artikel

guide

The KRITIS Umbrella Act and NIS2: What Applies to Whom?

Since July 2026, around 2,000 KRITIS operators must register in addition to NIS2. Who needs to comply with NIS2, the KRITIS Umbrella Act, or both — sectors, deadlines, and fines explained.

7 Min. Lesezeit

guide

NIS2 ISO 27001 Mapping: Excel Checklist Download

ISO 27001 covers approximately 70% of NIS2 requirements. The mapping Excel shows at a glance what is already covered — and where the regulatory gap remains.

6 Min. Lesezeit

guide

NIS2 BSI Registration: Missed the Deadline — What Now?

The statutory NIS2 registration deadline has expired, but the BSI is granting an extended deadline until 31 July 2026. How to complete your registration in the BSI portal step by step.

9 Min. Lesezeit

Back to Blog