NIS2 Checklist as an Excel Template: the 10 §30 Obligations

A NIS2 checklist translates the 10 minimum measures from §30 BSIG into trackable tasks. An Excel template is the most pragmatic format for this: structured, filterable, and free of specialised software. NIS2Compass provides this framework along with the templates. Where you stand today and which of the ten obligations are still open is shown in minutes by the free Pre-Check.
Free download
NIS2 checklist as an Excel template
The 10 minimum measures under §30 BSIG as trackable tasks — plus registration, reporting and management duties (§§32, 33, 38).
- Status, owner, evidence and due-date columns
- ISO 27001 / BSI IT-Grundschutz mapping per measure
- Includes the duties ISO 27001 does not cover
XLSX · 10 KB · no email required · last updated September 2026
Optional: NIS2 updates by email
To show this form, we need your consent for the Marketing category.
No spam, unsubscribe anytime. Double opt-in, processed via Brevo.
Need the substance behind the skeleton? The Template Library provides 45+ reviewed Word and Excel templates for every §30 measure. View NIS2 templates →
What belongs in a NIS2 checklist under §30 BSIG?
The 10 minimum measures from §30 (2) BSIG are the core of every NIS2 checklist. They have been binding without transition periods since 6 December 2025. The measures range from technical requirements such as encryption and access control to organisational duties such as training and supply chain security. NIS2Compass structures each of these obligations as its own item, complete with tasks and evidence.
- Risk analysis and security concepts: A documented risk assessment and security concepts for your information systems, kept as evidence.
- Handling security incidents: An incident-handling process with reporting paths, roles, and logging of every incident.
- Business continuity: Business continuity, backup management, recovery procedures, and crisis management, each demonstrably tested.
- Supply chain security: Assessment and contractual safeguarding of critical suppliers and service providers.
- Security in procurement, development, and maintenance: Secure procurement and maintenance processes, including vulnerability management.
- Assessing effectiveness: Procedures that regularly check whether the risk measures actually work.
- Cyber hygiene and training: Basic security practices and demonstrable training for employees.
- Cryptography and encryption: Concepts and rules for the use of encryption.
- Personnel security, access control, asset management: Governed access rights, personnel security, and a maintained asset inventory.
- Multi-factor authentication and secured communication: MFA, secured communication, and secured emergency communication.
A good checklist does not just tick off measures; it captures the specific evidence and documentation for each item. §30 demands this with its requirement of demonstrability. §38 BSIG adds that management must approve and oversee the measures, a duty that cannot be delegated.
Why is Excel a suitable format for the NIS2 checklist?
Excel is the most pragmatic format for the NIS2 checklist because it is available without a licensing hurdle, without a rollout project, and is familiar to every SME team. §30 BSIG requires demonstrable documentation of the measures. A structured table meets this requirement immediately, without having to introduce new software.
The advantages at a glance:
- Ready to use immediately: No licence costs, no rollout project. Any team can open the template and start filling it in.
- Versionable: Every revision can be saved as its own file. This keeps progress traceable over time.
- Status columns and filters: Open, in-progress, and completed measures can be flagged and filtered as needed.
- Shareable with management: §38 BSIG requires management to oversee the measures. A compact table delivers the status overview that is needed.
- Mapping-friendly: Each obligation can be linked to references to internal documents, policies, or responsible owners.
Excel has clear limits. It offers no real-time collaboration like dedicated GRC software, maintenance is manual, and automatic reminders are missing. For larger organisations with many stakeholders, that can become a burden. For most SMEs with an IT department of 3 to 10 people, however, a well-maintained Excel file is enough to demonstrate the §30 obligations in a structured way.
NIS2Compass provides ready-made Word and Excel templates, each assigned to a §30 implementation step. You start from a reviewed structure instead of a blank sheet. The Template Library lists all available NIS2 templates.
How do you build the NIS2 checklist step by step?
In six steps, the 10 §30 measures become a maintainable Excel checklist. The path leads from clarifying applicability through the column structure to the review cycle. Most SMEs can set up the basic structure in a single working day; populating it with evidence typically takes several weeks. The result is a document that demonstrably meets §30 and §38 BSIG.
- Clarify applicability and entity type. First determine whether your company qualifies as an essential or important entity. The free Pre-Check from NIS2Compass gives you an initial assessment in minutes.
- Set up the 10 §30 measures as rows. Adopt the ten minimum measures from §30 (2) BSIG as fixed rows. Break down extensive measures such as risk management or supply chain security into sensible subtasks.
- Define the column structure. Create six columns for each measure: requirement (the concrete obligation per §30 item), status (met, partially met, or open), owner (a named person or role), evidence/document (the assigned policy or template), due date, and gap/action (what is still outstanding).
- Assess the current state of each measure. Carry out a gap analysis and rate each measure as met, partially met, or open. This makes your maturity transparent and helps you prioritise the next steps.
- Link evidence and documents. §30 BSIG requires demonstrability. Therefore link each measure to the supporting document, such as a policy, a log, or a contract.
- Define the review cycle and reporting. §38 BSIG obliges management to approve and oversee the measures. Define fixed review dates and regular reporting to the management level.
How do you link the checklist with ISO 27001 and BSI IT-Grundschutz?
A mapping column connects each §30 measure with the matching ISO 27001 controls and BSI IT-Grundschutz building blocks. Anyone already using these frameworks avoids duplicate work, for example on controls covering access control, cryptography, or supplier management under ISO 27001 Annex A. ISO 27001 does not, however, replace full NIS2 evidence.
The Excel checklist contains an additional column "ISO 27001 / BSI building block" next to each of the ten §30 obligations. There you enter the control or building block that already covers the respective measure.
This approach saves considerable effort. Existing documents can be reused directly: anyone who has documented risk treatment under ISO 27001 references it in the mapping column instead of starting over.
This way, you see at a glance which §30 measures are already evidenced and where genuine gaps remain. This is especially efficient for companies with an existing ISMS. The official BSI IT-Grundschutz building blocks provide the reference needed for the mapping.
Which NIS2 obligations does ISO 27001 not cover?
An ISO 27001 certificate is not automatic NIS2 evidence. Several legal obligations lie outside the classic ISMS scope:
- Registration (§33 BSIG): Registering with the BSI is a legal obligation, not an ISMS topic.
- Reporting obligations (§32 BSIG): The deadlines and procedures for security incidents are not governed by ISO 27001.
- Management liability (§38 BSIG): The personal responsibility of the management bodies is not recognised by ISO 27001 in this form.
Scope and risk acceptance may also differ. An ISMS often covers only parts of the organisation, while §30 BSIG covers the entire affected company. More on this in the article Is ISO 27001 enough for NIS2?. The NIS2Compass Pre-Check additionally maps your answers to ISO 27001 and BSI IT-Grundschutz and shows which §30 obligations are already covered.
Which mistakes should you avoid with the NIS2 checklist?
The most common mistakes are a checklist without an evidence column, without named owners, and without a review cycle. It is ticked off once and then becomes outdated. The result is a document that formally fails to meet §30 BSIG because demonstrability is missing.
- Ticking off once instead of ongoing maintenance: §30 requires demonstrability over time. Treat the checklist as a living document with a status history.
- Missing evidence column: Without a reference to a policy, configuration, or log, implementation remains unevidenced. Link the specific artefact for each measure.
- No named owners: A measure without an owner is rarely maintained. Enter a person or role for each of the 10 §30 obligations.
- Management not involved: §38 BSIG requires approval and oversight by management. This duty cannot be delegated and belongs in the documentation.
- No review cycle: Without fixed dates, the status becomes outdated. Define quarterly or semi-annual reviews with a date.
- Only technical measures: Organisational obligations and supply chain security are often forgotten. Cover all three areas in the checklist.
In practice, many checklists look technically complete but fail an audit because the documentation is missing.
How does a machine builder with 140 employees use the checklist?
A mid-sized machine builder with 140 employees falls under NIS2 as an important entity, classified under the manufacturing sector. The IT function consists of an IT lead and a small team without a dedicated information security officer. Before introducing the checklist, there was no structured overview of the implementation status across the ten §30 obligations.
The team uses an Excel checklist along the 10 §30 measures. In a first pass, a gap analysis is carried out: for each measure, the status is recorded and an open gap is flagged.
A responsible role is assigned to each obligation. In the evidence column, the team links the associated policy, configuration, or log. This produces a verifiable status rather than a mere tick.
Each quarter, the IT lead reports the status to management. Management approves and oversees the measures as §38 BSIG requires. Anyone looking to get started without external support will find guidance in the article Implementing NIS2 without a consultant.
The result is a documentable compliance status that can be demonstrated to the BSI. During the annual internal audit, the checklist also serves as the evidence base: instead of gathering individual documents, the team refers directly to the linked evidence for each measure, which significantly reduces the effort of the annual review. The scenario is anonymized and for illustration only.
Which NIS2 Excel Templates Does NIS2Compass Offer?
NIS2Compass delivers 45+ Word and Excel templates covering the entire implementation path, from risk analysis to management-level documentation under §38 BSIG. The NIS2 checklist is just the starting point. New templates are added promptly when legal requirements change.
Each template is mapped to a specific §30 BSIG implementation step, but can also be downloaded independently. You grab the risk matrix or the report form directly, without working through the entire guide.
The library includes among others:
- Asset inventory (Excel) and gap assessment (Excel) for §30 No. 1, the foundation of any NIS2 implementation
- Risk matrix and risk assessment register (Excel) for §30 No. 1, with scoring logic and traffic-light status
- Network security concept and vulnerability register (Word/Excel) for §30 No. 5
- Incident response policy, report forms under §32 BSIG and IT emergency manual for §30 No. 2
- Supplier security questionnaire and contract clause set (Excel/Word) for §30 No. 4
- IS policy, access control policy, patch management policy (Word) for §30 No. 7
- Management-level documentation under §38 BSIG
All templates contain QMS metadata (status date, version, responsible party) and a liability notice. The Template Library gives a full overview of all available templates.
Frequently Asked Questions
Is there an official NIS2 checklist from the BSI?
Yes. The BSI provides an official NIS-2 checklist as a free PDF download on bsi.bund.de, letting you check the implementation of the NIS2 Directive step by step. It is a self-assessment orientation aid, not a legally binding official form. It does not offer a structured Excel format with status tracking or §30 BSIG mapping.
Is an Excel checklist sufficient for NIS2 compliance?
For structure, overview, and evidence, an Excel checklist is very useful. It does not, however, replace the actual implementation of the measures. You must additionally fulfil registration under §33 BSIG and the reporting processes under §32 BSIG. The checklist documents progress; it does not establish compliance itself.
How many measures must the NIS2 checklist cover?
At least the 10 minimum measures from §30 (2) BSIG. These include, among others, risk management, incident handling, business continuity, and supply chain security. Depending on the measure, it is advisable to break it down into concrete subtasks so that the implementation status per area remains traceable.
What does a NIS2 checklist cost?
A self-built Excel checklist costs only your working time. NIS2Compass additionally provides reviewed Word and Excel templates as well as an 8-chapter Implementation Guide. As a free starting point, you can use the Pre-Check, which captures your current status as a gap analysis and derives the appropriate steps.
Am I even affected by NIS2?
In Germany, around 29,500 companies are affected by NIS2. The classification is based on the sector and the company size. Whether your company falls under the obligations is best clarified through a structured check. The article Am I affected by NIS2? provides guidance.
Is there a free NIS2 checklist as an Excel download?
The BSI provides a free NIS2 checklist as a PDF download, useful for initial orientation. It does not offer an Excel format or status tracking. The NIS2Compass Excel checklist adds status tracking, §30 BSIG mapping, evidence fields, and a review cycle. It is part of the Pro subscription for €29/month, cancellable monthly. The Pre-Check offers a free starting point.
Implement NIS2 step by step
NIS2Compass guides you step by step through implementation – with an Implementation Guide, templates and Knowledge Hub.
Get startedRelated Articles
Ransomware Attack on a Hospital: Which NIS2 Duties Apply?
A ransomware attack on Nipigon Hospital (Canada) knocked out lab and diagnostics. Which NIS2 duties (§§30, 32, 65 BSIG) apply to German hospitals.
5 min read
NIS2 Crisis Communication: What Role Does Telfo Play?
NIS2 requires crisis management and secure emergency communication under §30 BSIG: escalation matrix, redundant channels, crisis communication plan — plus where Telfo fits in.
10 min read
Rhysida Berlin Leak: Is Redistributing the Data a Crime?
Rhysida published Berlin government data after the city refused a ransom. Redistributing it is a crime under §202d StGB and §42 BDSG — the legal analysis, plus NIS2 lessons.
4 min read