For asset owners, EPCs, and developers
NIS2 Handover Readiness Checklist
NIS2 compliance is the asset owner's obligation — but the party performing OT integration determines whether the plant meets the requirements at COD. This checklist covers what a NIS2-ready handover looks like: 28 items across 5 categories, from OT network architecture to incident response readiness.
What's inside
- OT Network Architecture 5 items
- Access Control & Authentication 6 items
- Commissioning Handover Documentation 6 items
- Supply Chain & Contract Requirements 6 items
- Incident Response Readiness 5 items
Access the full checklist
Enter your email to unlock the full checklist.
No spam. Unsubscribe anytime.
OT Network Architecture
Access Control & Authentication
Commissioning Handover Documentation
Supply Chain & Contract Requirements
Incident Response Readiness
Specialist Guide
NIS2 for BESS — Cybersecurity Compliance
This checklist covers what to check. The specialist guide covers how to implement it — Article 21 obligations, the 24/72/30 incident reporting timeline, IEC 62443 zones and conduits applied to a BESS plant, supply chain security, penalties, and a ten-step compliance roadmap.
Read the specialist guide →Why a handover checklist matters for NIS2
NIS2 — Directive (EU) 2022/2555 — requires asset owners providing energy storage services to implement cybersecurity measures across their OT systems. But the party performing OT integration — whether an EPC contractor or the developer's engineering team under a split-contract model — is the one that designs and configures the control and communication architecture. The cybersecurity decisions made during design and commissioning determine whether the plant meets NIS2 requirements at COD.
Article 21(2)(d) of the directive requires asset owners to audit the cybersecurity practices of their direct suppliers — including EPCs. This checklist covers the handover deliverables, OT architecture requirements, and contract scope items that asset owners, EPCs, and developers increasingly need to address.
What this checklist covers
The checklist is organized into five categories that span the cybersecurity scope of a BESS integration project:
- OT Network Architecture — zones and conduits per IEC 62443, network segmentation, firewall configuration, and legacy protocol mitigation.
- Access Control & Authentication — default credentials, role-based access, MFA, privileged access management, and vendor account governance.
- Commissioning Handover Documentation — the documentation package the asset owner needs for their NIS2 compliance file: network diagrams, asset inventory, credentials register, firewall rules, and vulnerability records.
- Supply Chain & Contract Requirements — supplier mapping, cybersecurity contract clauses, incident notification obligations, right-to-audit provisions, and end-of-contract procedures.
- Incident Response Readiness — incident response plan, CSIRT reporting readiness, significant-incident thresholds, OT monitoring, and backup recovery.
Each item includes a brief explanation of what it means and why it matters for NIS2 compliance.
Who this is for
- Asset owners defining what a NIS2-ready commissioning handover must include and what to require from their EPC or integration contractor.
- EPC contractors scoping cybersecurity into their integration work and preparing for asset owner supply chain audits.
- Developers specifying cybersecurity requirements in EPC contracts or managing OT integration directly under a split-contract model.
- OT cybersecurity consultants advising BESS stakeholders on NIS2 compliance and using the checklist as a structured assessment framework.
Get the full checklist
28 items across 5 categories, from OT network architecture to incident response readiness.
No spam. Unsubscribe anytime.