Skip to content

NIS2 without consultants: the technical checklist

Article 24 of Italy's NIS2 decree, rewritten as an implementable control checklist: what the law says, the config that satisfies it, the evidence to keep.

Search for "NIS2 checklist" and you get two kinds of results: law firms explaining the directive in the abstract, and vendors explaining why their product is the answer. What you rarely get is the thing a sysadmin or an IT manager actually needs: the legal obligations translated into configurations you can implement this quarter, plus the evidence you will be asked to produce when someone checks.

I work as an independent consultant, which means I am usually the person who has to make the paperwork true. This article is the checklist I use, built directly on the Italian transposition of NIS2, Legislative Decree 138/2024, in force since 16 October 2024, and on the implementing determinations of the Italian National Cybersecurity Agency (ACN). Italy is the reference market here, but the structure applies anywhere in the EU: the national decrees all descend from the same Article 21 of Directive (EU) 2022/2555.