SaaSFort
Free Excel Template — 10 Controls

NIS2 Article 21 Self-Audit Template

All 10 mandatory NIS2 cybersecurity risk-management measures, in one Excel. Status, priority, owner, deadline — and an auto-counted readiness percentage. Built for SaaS compliance teams without a €50K consultant budget.

No spam. Unsubscribe anytime. Free forever.

NIS2 Art. 21 Self-Audit
10 controls · v1.0
.xlsx
Control
Status
Priority
Owner
21(2)(a) Risk analysis
Yes
P0
21(2)(b) Incident handling
Partial
P0
21(2)(c) Continuity
Yes
P1
21(2)(d) Supply chain
No
P0
21(2)(e) Vulnerability
Partial
P0
21(2)(h) Cryptography
Yes
P0
21(2)(j) MFA
No
P0
Readiness 42.9%
Free .xlsx
10

NIS2 Article 21(2) measures covered, one row each

EU 2022/2555

17,500

German entities missed the BSI registration deadline

BSI / heise

€10M

maximum fine for essential entities — 2% of global turnover

NIS2 Art. 34

All 10 Controls

Every NIS2 Article 21(2) measure, one row at a time

21(2)(a)

Risk analysis & policies

Documented ISMS, board-approved policy review.

21(2)(b)

Incident handling

24h early warning + 72h CSIRT report procedure.

21(2)(c)

Business continuity

BCP/DRP with RTO/RPO objectives, tested annually.

21(2)(d)

Supply chain security

Critical supplier inventory + contractual clauses.

21(2)(e)

Vulnerability handling

Patching SLA, SBOM, disclosure policy.

21(2)(f)

Effectiveness assessment

External scans, KPI dashboard, MTTR/MTTD.

21(2)(g)

Cyber hygiene & training

Annual training records, §38 BSIG board training.

21(2)(h)

Cryptography

TLS 1.2+, encryption-at-rest, key management.

21(2)(i)

Access control

RBAC, quarterly access reviews, PAM for admins.

21(2)(j)

Multi-factor authentication

MFA on all access, FIDO2 for privileged.

Who It's For

Built for compliance teams on a deadline

Compliance & Risk Officers

Walk into the next NIS2 board meeting with a populated audit, not a blank slate.

SaaS CTOs & Founders

See exactly what auditors will check — and where you stand against the October 2026 deadline.

Mid-Market Teams (50–250)

No €50K consultant. No enterprise GRC tooling. Just a working Excel and a clear remediation path.

October 2026 enforcement is six months away

Get the template, fill it in this week, and validate your external posture with a free SaaSFort scan.