NIS2 Compliance Checklist for 2026: Deadlines, Evidence, and What Regulators Actually Inspect

This is not another explanation of what NIS2 is. It is a working checklist for the organizations already inside the regime in Slovakia and Czechia, built around the dates that bite in 2026 and 2027. Slovak entities regulated under the old rules may follow them only until 31 December 2026; from 1 January 2027 decree 227/2025 applies in full. Czech entities have one year from notifying NÚKIB to have measures in place. Below: the deadline table, a four-part checklist, the evidence a regulator asks for, and a downloadable template you can fill in.

The deadlines that matter in 2026 and 2027

Most NIS2 articles stop at the directive. The obligations that actually get inspected come from national law, and both Slovakia and Czechia now have theirs in force with running clocks. If you only take one thing from this page, take this table.

ObligationSlovakia (Act 69/2018)Czechia (Act 264/2025)
Register / notify the regulatorWithin 60 days of starting the regulated activity (entities active on 1 Jan 2025: by 2 March 2025)Within 60 days of the act taking effect, i.e. by the end of 2025, via the NÚKIB portal
Implement security measuresWithin 12 months of entry in the registerWithin one year of notifying the service
Old rules stop applying31 December 2026. From 1 January 2027 decree 227/2025 applies in fullNot applicable - the new act replaced the old regime outright on 1 November 2025
First audit or self-assessmentWithin 2 years of entry in the register (self-assessment route: full audit within 5 years)Per the applicable decree for your regime (409/2025 higher, 410/2025 lower)
Incident reporting24 hours / 72 hours / 30 days24 hours / 72 hours / final report

Step 0: confirm you are actually in scope

Scope is decided by sector plus size, not by whether anyone told you. In Slovakia the amendment brought in at least 3,403 organizations across 18 high-criticality and other critical sectors. In Czechia the new act covers more than 6,000. The common trigger is the medium-enterprise threshold: 50 or more employees, or turnover and balance sheet total from EUR 10 million.

  • Are you in one of the listed sectors - energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, postal services, waste, chemicals, food, manufacturing, digital providers, research and the rest?
  • Do you meet the size threshold, or are you covered regardless of size as a central government body, municipality, critical entity or a third party with significant influence on cybersecurity?
  • Have you registered or notified? If not, do that first - late registration is still required, and failing to register is itself a sanctionable administrative offence.
  • Do you know your category? Slovakia distinguishes essential from important entities; Czechia splits into a higher-obligations and a lower-obligations regime. Your category decides which decree applies and how deep the duties go.

Free phishing campaign

Test your employees with one free phishing campaign and see the results for yourself.

Run a focused pilot, measure clicks and reports, and review the training outcomes before rollout.

No credit card required.

Part 1: Governance and documentation

This is the layer auditors open first, because it is the layer that proves the rest was deliberate rather than accidental.

  • Risk analysis exists, is approved, dated and signed - and the security measures you chose visibly follow from it. Measures without a risk analysis behind them are the single most common finding.
  • Security documentation matches the applicable decree: Slovak decree 227/2025, or Czech decree 409/2025 for the higher regime and 410/2025 for the lower one.
  • A responsible person is named and their contact details are filed with the regulator. In the Czech higher regime this means an appointed cybersecurity manager.
  • The management body has approved the measures. Under Article 20(1) of NIS2 they approve, oversee, and are personally liable - so the approval needs to be minuted, not assumed.
  • Supply chain security is addressed: a list of suppliers with access, and security clauses in their contracts.

Part 2: People and security awareness

Article 21(2)(g) makes basic cyber hygiene practices and cybersecurity training a mandatory risk-management measure, and Article 20(2) puts a separate, harder duty on the management body. Both national frameworks turn this into a documented plan. Our NIS2 security awareness training guide covers the legal basis in depth; this is the checklist version.

  • A security awareness development plan exists in writing and defines the format, content, scope, frequency and target roles. Slovak decree 227/2025 sets a floor of security education at least once every three years - treat it as a floor, not a target.
  • The statutory body and senior management have completed training, with a record. A generic staff e-learning module does not satisfy Article 20(2).
  • New employees are trained before, or immediately as, they receive accounts.
  • Recurring refresher training runs on a justified cadence, and the justification traces back to the risk analysis.
  • Administrators and privileged roles receive deeper, practical training beyond general awareness.
  • Third parties with system access are covered, either by your training or by contract.
  • Effectiveness is verified, not assumed. This is the requirement most programs fail: completion percentages are not evidence of awareness.

That last point is where a phishing test for employees does real work. A simulated campaign produces a measured click rate, credential submission rate and report rate - numbers that show whether behaviour changed, in a form an auditor can read. PhishGun pairs localized Slovak, Czech and English campaigns with immediate micro-training at the moment someone clicks, so the same exercise generates both the learning and the evidence. If you have never run one, the step-by-step playbook covers Microsoft 365 and Google Workspace allowlisting.

Part 3: Technical measures

Slovak decree 227/2025 tightened this layer noticeably when it replaced decree 362/2018. Two changes catch the most organizations out.

  • Multi-factor authentication is mandatory for privileged accounts. Have the configuration export and the list of covered accounts ready.
  • Network segmentation: infrastructure divided into security zones with controlled access between them, documented in a current network diagram.
  • Identity and access management with a record of periodic access reviews - not just a list of who has what, but proof you re-checked it.
  • Logging and monitoring, with a stated retention period.
  • Backup and recovery, including a record of an actual restore test. An untested backup plan is a finding.
  • Contracts under the Slovak § 19(2) concluded up to 31 August 2025 remain valid only for their originally agreed term and cannot be extended past that if they do not meet the new measures.

Part 4: Incident detection and reporting

Slovak decree 226/2025 sets the reporting phases at 24 hours for an early warning, 72 hours for a detailed notification and 30 days for the final report. Czechia follows the same directive structure. Those clocks start when you detect the incident - which means detection capability is implicitly part of the obligation.

  • A written incident reporting procedure with the deadlines and the named person who files the report.
  • An internal channel employees can use to report something suspicious, and evidence that it was actually communicated to them.
  • An incident register, including what was reported to the regulator and when.
  • A rehearsal: minutes from a tabletop exercise or a real incident showing the procedure works under time pressure.

There is a direct line from awareness training to this section. A trained employee who recognizes a phishing message and reports it in minutes is the first link in the 24-hour chain; an untrained one is the reason the clock started late. The organizational controls that support this are covered in how to prevent phishing.

The evidence table: what to have in the folder

Supervision is documentary. The auditor will rarely watch you train anyone - they read what you can produce. The most efficient way to prepare is to build one table, fill in where each artefact lives and who owns it, and keep it current. The same records satisfy ISO 27001 clause 7.3 and control A.6.3, as covered in the ISO 27001 awareness training guide, so build the evidence once and reuse it.

RequirementEvidence a regulator expects to see
Security awareness development planThe approved plan itself: format, content, scope, frequency, and which roles get what
Management body trainingAttendance or completion record, the training content, and the date
Onboarding trainingPer-person record showing training happened before access was granted
Recurring trainingParticipant records for the last cycle plus the plan for the next one
Privileged role trainingEvidence of deeper, role-appropriate content for administrators
Third-party coverageTraining record, or the contractual clause placing the duty on the supplier
Effectiveness verificationTest or phishing simulation results, with a comparison over time
Review and remediationMinutes of the review and the follow-up actions for high-risk groups

What inspectors actually open first

Based on how the Slovak and Czech regimes are written, and on what auditors ask for in comparable ISO 27001 engagements, the opening moves are predictable.

  1. The register entry or notification, to confirm your category and start date - which fixes every other deadline.
  2. The risk analysis, because everything downstream is supposed to follow from it.
  3. The security awareness development plan, because it is a named, specific document that either exists or does not.
  4. Training records for the statutory body, since that is the one duty pointed directly at the people being interviewed.
  5. Evidence of effectiveness verification, which separates a real program from a slide deck.
  6. The incident reporting procedure and register, checked against the 24/72-hour clocks.

Notice that three of the six are people-related. Awareness is the cheapest part of the regime to implement and the most visible part to fail, which is why it tends to be where inspections start.

Penalties and personal liability

  • Slovakia, essential entities: up to EUR 10,000,000 or 2% of total global annual turnover, whichever is higher.
  • Slovakia, important entities: up to EUR 7,000,000 or 1.4% of turnover.
  • Administrative offences such as failing to register or keeping outdated documentation: EUR 300 to EUR 500,000.
  • Article 20(1) of NIS2 makes management bodies responsible for approving and overseeing the measures, and liable for infringements - the exposure is not purely corporate.

The realistic risk for most mid-sized organizations is not a headline fine. It is a finding that forces an unplanned remediation program on the regulator's timeline rather than your own.

A 90-day plan if you are behind

If the transition deadline is close and the folder is thin, sequence matters more than ambition. This order front-loads the artefacts that are checked first and cheapest to produce.

  1. Days 1-15: confirm scope and category, verify the registration or notification is filed, and fix it if not. Download the evidence table and mark what already exists.
  2. Days 16-40: write or refresh the risk analysis and the security awareness development plan. These two documents unlock most of the rest.
  3. Days 41-60: run management body training and record it. Schedule onboarding and refresher training, and put the calendar in the plan.
  4. Days 61-75: run a baseline phishing simulation to establish the effectiveness measurement, and publish the employee reporting channel alongside it.
  5. Days 76-90: close the incident procedure, rehearse it once, and complete the evidence table with owners and storage locations.

The baseline simulation in the fourth block is worth running early rather than last, because the first result is almost always worse than expected and you want the improvement curve inside your evidence, not just the starting point. PhishGun's first campaign is free and needs no card, so the baseline can be booked before any budget conversation - see pricing for what a full program costs.

Frequently asked questions

What is the NIS2 deadline for 2026?

In Slovakia, 31 December 2026 is the last day entities regulated under the previous regime can follow the old security measures; from 1 January 2027 decree 227/2025 applies in full. Separately, every registered entity has 12 months from its entry in the register to implement measures, and 2 years to complete the first audit. In Czechia, providers have one year from notifying NÚKIB to have measures in place.

Is security awareness training mandatory under NIS2?

Yes. Article 21(2)(g) lists basic cyber hygiene practices and cybersecurity training among the minimum risk-management measures, and Article 20(2) additionally requires members of management bodies to follow cybersecurity training. Slovak decree 227/2025 and Czech decrees 409/2025 and 410/2025 turn this into a documented security awareness development plan with records.

How often does NIS2 training have to happen?

Neither the directive nor the decrees fix a single interval. Slovak decree 227/2025 sets a minimum of security education at least once every three years, but the periodicity you choose has to be justified by your risk analysis. In practice a defensible program combines onboarding training before access, short recurring touchpoints during the year, and a measured effectiveness check.

What evidence does a NIS2 audit require for training?

The approved awareness plan, training records for the management body, onboarding and refresher records per person, deeper records for administrators and privileged roles, coverage of third parties with access, results of an effectiveness check such as a phishing simulation, and minutes of the review with follow-up actions. The downloadable template on this page lists all of them.

What are the fines for NIS2 non-compliance in Slovakia?

Up to EUR 10,000,000 or 2% of total global annual turnover for essential entities, and up to EUR 7,000,000 or 1.4% of turnover for important entities. Administrative offences such as failing to register or maintaining outdated documentation carry fines from EUR 300 to EUR 500,000. Management bodies are also personally liable for approving and overseeing the measures.

Does a phishing simulation count as NIS2 evidence?

It is not a substitute for the training plan, but it is the most practical way to satisfy the requirement to verify that awareness education actually works. Campaign results give you click rate, credential submission rate and report rate per team and over time, which is exactly the kind of measured outcome an auditor can assess - and the same records serve ISO 27001 control A.6.3.

Next step

Ready to measure your phishing and training program?

Book a demo and see how PhishGun can support your simulation and training program, reporting needs, and compliance evidence.