Skip to content
Knowledge base Updated: February 28, 2026

NIS2 checklist for the board — 10 questions every CEO must ask their CISO

NIS2 checklist for the board — 10 key questions for the CISO, obligation→responsible→deadline table, non-compliance warning signs. Practical guide for CEO/CFO.

The NIS2 Directive is not just another regulation that can be delegated to the IT department and forgotten. It is a legal act that, for the first time in the history of European law, introduces personal liability of board members for organizational cybersecurity. If you are a CEO, CFO, or supervisory board member, this article is your practical checklist — 10 questions you must ask your CISO before it is too late.

Why is NIS2 a board-level issue, not an IT matter?

The traditional approach to cybersecurity in companies is based on a simple assumption: IT security is the IT department’s responsibility. The board approves the budget, and the rest is the domain of technicians. NIS2 fundamentally changes this paradigm. The directive explicitly requires management bodies to approve cybersecurity risk management measures, oversee their implementation, and bear liability for violations of these requirements.

In practice, this means that a board member who has not demonstrated due diligence in overseeing cybersecurity may be held personally liable. Penalties include not only financial fines but also temporary bans from holding managerial positions. This is an unprecedented change — for the first time, European law treats neglect of cybersecurity at the board level similarly to neglect of fiduciary duties.

Why now? Because the scale of cyberattacks in Europe is growing exponentially. According to ENISA (the European Union Agency for Cybersecurity), the number of significant incidents has doubled over the past two years. Ransomware attacks are paralyzing hospitals, energy operators, and logistics companies. The European legislator concluded that the previous model — where cybersecurity was “an IT problem” — does not provide an adequate level of protection for critical infrastructure.

For the board, the key is a change in perspective. Cybersecurity is now an element of corporate governance, just like financial compliance or workplace safety. You do not need to understand the technical details — you need to know what questions to ask and how to interpret the answers.

📚 Read the complete guide: NIS2: Kompletny przewodnik po dyrektywie NIS2 - obowiązki, kary, terminy

10 questions every CEO must ask their CISO

The following checklist is not a set of exam questions — it is a management tool. Each question is formulated in business language, and the expected answer should be specific, measurable, and tied to a deadline. If the CISO cannot answer any of these questions clearly and without technical jargon — that in itself is a warning sign.

Question 1: Does our organization fall under NIS2, and in which category?

Expected answer: a clear classification as an “essential entity” or “important entity,” specifying the sector and legal basis. If the answer is “we’re still checking” — that is a red flag. Classification should be the first step, completed at the very beginning of the process.

Question 2: What are our current gaps in NIS2 compliance, and what is the plan to close them?

Expected answer: the result of a formal gap analysis with a list of non-compliance areas, assigned responsibilities, and a remediation timeline. Without a gap analysis document, there is no way to plan sensibly — it is like building a strategy without a financial audit.

Question 3: Do we have a documented and tested incident reporting procedure under the 24h/72h regime?

Expected answer: yes, the procedure is documented, roles are assigned, it has been practiced in a simulation, and we know the contact point at the CSIRT. NIS2 requires an early warning within 24 hours — this is not a deadline that allows for improvisation.

Question 4: How do we manage risk in our ICT supply chain?

Expected answer: we have a register of key suppliers, an assessment of their security levels, cybersecurity clauses in contracts, and a monitoring procedure. Supply chain security is one of the most commonly neglected areas.

Question 5: What is our current cybersecurity maturity level, and how do we measure it?

Expected answer: we use a maturity assessment framework (e.g., NIST CSF, ISO 27001), we know our current level, we have a defined target level, and a plan to reach it. Without metrics, management is impossible — this is a fundamental management principle.

Question 6: When did we last test our defenses (penetration testing, red teaming)?

Expected answer: the specific date of the last test, its scope, key findings, and the status of implementing recommendations. If the last test was more than 12 months ago — that is a sign the organization is not keeping pace with the evolving threat landscape.

Question 7: Does our business continuity plan account for cyberattack scenarios?

Expected answer: yes, the BCP/DRP covers ransomware, data breach, and critical infrastructure attack scenarios. The plan was tested within the last 12 months. NIS2 explicitly requires business continuity and crisis management plans.

Question 8: What percentage of employees completed cybersecurity training in the last 12 months?

Expected answer: a specific percentage, training scope, and phishing test results. NIS2 requires regular training — including training dedicated to the board. If the board has not been trained — that is another gap.

Question 9: What is our cybersecurity budget relative to the IT budget, and how does it compare to industry benchmarks?

Expected answer: a specific amount and percentage of the IT budget, compared to the sector benchmark. The industry standard is 10-15% of the IT budget allocated to security. If it is below 5%, the organization likely cannot meet NIS2 requirements.

Question 10: If a serious incident happened today — are we ready?

Expected answer: a description of operational readiness — incident response team, procedures, tools, contracts with external security service providers. This question synthesizes all the previous ones. If the CISO struggles to give a clear answer — the answer is probably “no.”

NIS2 obligations table: obligation, responsible party, deadline

The table below is an operational tool for the board. Each obligation arising from the NIS2 Directive is assigned to a specific responsible party with a defined deadline. The board should require regular status reporting for each item.

NIS2 obligationResponsible partyDeadlineStatus
Organization classification (essential/important entity)CISO / Legal DepartmentCompleted
Gap analysis against NIS2 requirementsCISO30 days from classification
Cybersecurity risk management policyCISO + Board60 days from gap analysis
Incident reporting procedure (24h/72h/1 month)CISO + SOC90 days
Supply chain security assessmentCISO + Procurement120 days
Business continuity plan (BCP/DRP) with cyber scenariosCISO + COO120 days
Cybersecurity training program (including board)CISO + HR90 days, then cyclically
Penetration testing and security auditCISO + external auditorEvery 12 months
Registration in supervisory system (if required)Legal Department + CISOPer national deadlines
Board cybersecurity reviewBoardQuarterly

Each item should have a specific named owner (not just a function), a measurable end result, and a budget. The board should receive a monthly status report in a “green/yellow/red” format — not a technical report, but a management report.

It is also worth defining escalation. If any obligation moves to “red” status (delay exceeding 30 days or no owner), it should automatically be placed on the agenda of the next board meeting. This is not excessive bureaucracy — it is a corporate governance standard that NIS2 enforces.

Warning signs of non-compliance — red flags for the board

The board does not need to understand firewall configurations, but it must recognize warning signs indicating cybersecurity problems. The following red flags should trigger immediate action.

No dedicated cybersecurity budget. If security is “somewhere in the IT budget” without being separated — the organization does not take it seriously. NIS2 requires adequate resources, and without a dedicated budget, these cannot be demonstrated.

CISO reports to the IT director, not the board. Reporting structure matters. If the CISO is subordinate to the CIO, there is an inherent conflict of interest — the security budget competes with the IT development budget. NIS2 assumes that cybersecurity is a board-level priority, which implies direct CISO access to the board.

No documented incident response procedures. If the organization does not have a written and tested procedure — chaos will ensue during an incident. Twenty-four hours for the first report is a very short time if nobody knows who to call, whom to contact, and what to say.

Outdated asset inventory. You cannot protect what you do not know. If the organization does not have an up-to-date list of critical systems, applications, and data — risk management is fiction. Every NIS2 auditor will start by asking about the inventory.

No testing within the last 12 months. Penetration tests, tabletop exercises, phishing simulations — these are not optional extras but elements required by NIS2. An organization that does not test its defenses does not know whether they work.

No cybersecurity clauses in supplier contracts. The supply chain is one of the primary attack vectors. If contracts with key IT suppliers do not contain security requirements, the organization has an open flank that NIS2 explicitly requires closing.

The board has never participated in cybersecurity training. NIS2 requires training for management bodies. The absence of such training is not only a compliance gap but also a signal that the board does not understand the risks for which it is responsible.

Incident reporting — the NIS2 three-tier system

One of the most operationally demanding NIS2 obligations is the security incident reporting system. The directive introduces a three-tier mechanism that imposes strict timeframes and requires efficient coordination between teams.

Tier 1 — Early warning (24 hours). From the moment the organization becomes aware of a significant incident, it has 24 hours to submit an early warning to the relevant CSIRT (Computer Security Incident Response Team) or supervisory authority. The warning does not need to be complete — its purpose is to inform authorities about a potential threat, especially if the incident may be cross-border or affect multiple sectors.

Tier 2 — Full incident notification (72 hours). Within 72 hours, the organization must deliver a more detailed notification, including an initial assessment of the incident, its severity and impact, and indicators of compromise. This notification should contain sufficient information for the supervisory authority to assess the scale of the threat.

Tier 3 — Final report (1 month). Within one month of the incident notification, the organization must deliver a comprehensive final report. This should include a detailed description of the incident, its root cause analysis, applied remedial and corrective measures, and conclusions and preventive recommendations.

For the board, the key understanding is that this system requires operational readiness. You cannot write an early warning in 24 hours if the organization does not have: a team monitoring security events (SOC — internal or external), a clearly defined escalation procedure, a person authorized to communicate with the supervisory authority, and prepared notification templates. Each of these elements requires advance preparation. The board should demand a simulation exercise (tabletop exercise) at least once a year to ensure the procedure works in practice.

Supply chain security — obligations and risks

The NIS2 Directive introduces unprecedented requirements for ICT supply chain security. For the board, this is a particularly demanding area because it requires collaboration between the IT department, procurement, legal, and the CISO.

Obligations cover four key areas. First, identification and assessment of critical suppliers — the organization must know which suppliers have access to its systems, data, or infrastructure. Second, supplier risk assessment — each critical supplier should be evaluated for their security level, including certifications (ISO 27001, SOC 2), procedures, and incident history. Third, contractual clauses — supplier contracts must contain cybersecurity requirements, the right to audit, and the obligation to notify of incidents. Fourth, continuous monitoring — supplier assessment is not a one-time activity. The organization must monitor changes in supplier security levels on an ongoing basis.

Supply chain attacks are one of the fastest-growing threat vectors. It is enough to recall the SolarWinds (2020), Kaseya (2021), and 3CX (2023) attacks to understand the scale of the problem. An attack on a single supplier can cascade to affect thousands of organizations. NIS2 requires organizations to actively manage this risk, rather than merely accept it.

The board should require regular reports from the CISO on the state of supply chain security, covering the number of critical suppliers, results of the latest assessments, and identified risks along with mitigation plans.

How to prepare the board — a practical implementation path

Preparing the board for NIS2 requirements does not require transforming board members into cybersecurity experts. It does, however, require a systematic approach that ensures an adequate level of oversight and awareness.

Step 1: Board training (month 1). A dedicated 3-4 hour training session for all board members, covering key NIS2 requirements and their implications for the organization, personal liability of board members, fundamentals of cyber risk management, and an overview of key threat scenarios for the industry.

Step 2: Establishing a Cybersecurity Committee (months 1-2). Creating a standing committee of the board or supervisory board responsible for cybersecurity oversight. The committee should meet at least quarterly and receive regular reports from the CISO.

Step 3: Gap analysis and remediation plan (months 2-3). Commissioning a formal gap analysis between the current state of cybersecurity and NIS2 requirements. The result should be presented to the board in the form of a management report with a clear remediation plan, budget, and timeline.

Step 4: Budgeting and resource allocation (months 3-4). Based on the gap analysis, the board must approve an appropriate budget. This is a crucial moment — underfunding cybersecurity is not a saving, it is increasing the risk for which the board is personally liable.

Step 5: Implementation and monitoring (months 4-12). Systematic execution of the remediation plan with monthly status reporting to the board. Key milestones: implementing the incident reporting procedure, supply chain review, penetration testing, and business continuity plan.

Step 6: Annual review and continuous improvement (cyclical). NIS2 is not a project with an end date — it is a continuous process. The board should conduct a formal cybersecurity review annually, update the risk assessment, and adjust the strategy.

Cost of compliance vs. cost of non-compliance

One of the most common arguments against cybersecurity investments is their cost. However, it is worth comparing it with the costs of non-compliance to gain a complete perspective.

Compliance costs include implementation and maintenance of security systems (SIEM, EDR, monitoring), hiring or outsourcing a CISO and security team, employee and board training, regular audits and penetration tests, updating procedures and documentation, and supply chain security management. The estimated annual cost for a mid-sized company is EUR 50,000-120,000, and for a large organization — from EUR 250,000 upward. These figures depend on the organization’s size, sector, and current maturity level.

Non-compliance costs are on an entirely different scale. Administrative penalties: up to EUR 10 million or 2% of annual turnover for essential entities, up to EUR 7 million or 1.4% of turnover for important entities. Personal penalties for board members: fines and temporary bans from holding managerial positions. Incident costs (in the absence of safeguards): the average cost of a data breach in Europe exceeds EUR 4 million (IBM Cost of Data Breach Report). Reputation loss: difficult to quantify but tangibly affecting revenue and client relationships. Mandatory public disclosure order: NIS2 gives supervisory authorities the right to order public disclosure of non-compliance — a potential reputational crisis.

Simple mathematics shows that the investment in compliance is many times lower than the potential consequences of neglect. Moreover, cybersecurity is not just a regulatory cost — it is protection of business value, operational continuity, and client trust.

It is also worth remembering that supervisory authorities take “due diligence” into account when imposing penalties — an organization that demonstrates steps toward compliance (even if not yet 100% compliant) can expect more lenient treatment than an organization that has taken no action.

How does nFlo support NIS2 compliance?

Implementing NIS2 requirements is a complex process that demands both expert knowledge and experience in delivering compliance projects across various sectors. nFlo supports organizations at every stage of this journey — from entity classification, through gap analysis, to full implementation and monitoring.

Our NIS2 compliance service encompasses a comprehensive organizational readiness assessment, development of an implementation plan tailored to industry specifics, support in building incident reporting procedures, supply chain security audits, and training for the board and key employees. We work with organizations from all sectors covered by NIS2 — from energy, through healthcare, to digital infrastructure.

What the board receives from such an engagement is three things an inspection can be shown: a determination of the organisation’s status with the reasoning behind it, a risk treatment plan ready to be approved by resolution, and duties assigned to named people with deadlines. Response times for incident handling are agreed per priority and written into the contract — that is the number that can be enforced, and it is what the 24-hour reporting window depends on.

The key is to start the process as soon as possible. The earlier the organization identifies gaps and begins implementation, the lower the risk of penalties and the smoother any supervisory inspection will proceed.

Summary

  • Personal board liability — NIS2, for the first time in European law, imposes personal liability on board members for cybersecurity oversight, including bans from holding managerial positions.
  • 10 questions for the CISO — a practical checklist allows the board to quickly assess organizational readiness without delving into technical details.
  • Three-tier reporting system — 24 hours for an early warning, 72 hours for a full notification, 1 month for a final report. Requires advance operational preparation.
  • Supply chain under scrutiny — NIS2 requires supplier security assessments, contractual clauses, and continuous monitoring. This is one of the most commonly neglected areas.
  • Financial penalties up to EUR 10 million — plus personal penalties for the board, mandatory public disclosure orders, and bans from holding positions. The cost of non-compliance far exceeds the cost of implementation.
  • Compliance is a process, not a project — NIS2 requires continuous improvement, regular reviews, and updates. The board must treat cybersecurity as a permanent element of corporate governance.

Frequently Asked Questions

Does the board bear personal liability under NIS2?

Yes. NIS2 introduces personal liability for board members regarding cybersecurity oversight. Penalties may include a ban from holding managerial positions. This is a fundamental change — cybersecurity is no longer solely an IT department problem.

What penalties apply for NIS2 non-compliance?

For essential entities: up to EUR 10 million or 2% of annual turnover (whichever is higher). For important entities: up to EUR 7 million or 1.4% of turnover. Additionally: personal penalties for board members, orders for public disclosure of violations, and periodic bans from holding managerial positions.

How quickly must a security incident be reported under NIS2?

NIS2 introduces a three-tier system: early warning within 24 hours, full notification within 72 hours, and a final report within 1 month. This applies to incidents having a significant impact on service provision.

How much time does a company have to comply with NIS2?

The NIS2 Directive has been in effect since 18 October 2024. National implementation (amendment of the National Cybersecurity System Act) may introduce transitional periods, but organizations should already be implementing requirements, as supervision and penalties may be applied.


Need expert support? nFlo team can help secure your organization:


See also:


Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist