For asset owners, EPCs, and developers

NIS2 Handover Readiness Checklist

NIS2 compliance is the asset owner's obligation — but the party performing OT integration determines whether the plant meets the requirements at COD. This checklist covers what a NIS2-ready handover looks like: 28 items across 5 categories, from OT network architecture to incident response readiness.

What's inside

  • OT Network Architecture 5 items
  • Access Control & Authentication 6 items
  • Commissioning Handover Documentation 6 items
  • Supply Chain & Contract Requirements 6 items
  • Incident Response Readiness 5 items

Access the full checklist

Enter your email to unlock the full checklist.

No spam. Unsubscribe anytime.

Why a handover checklist matters for NIS2

NIS2 — Directive (EU) 2022/2555 — requires asset owners providing energy storage services to implement cybersecurity measures across their OT systems. But the party performing OT integration — whether an EPC contractor or the developer's engineering team under a split-contract model — is the one that designs and configures the control and communication architecture. The cybersecurity decisions made during design and commissioning determine whether the plant meets NIS2 requirements at COD.

Article 21(2)(d) of the directive requires asset owners to audit the cybersecurity practices of their direct suppliers — including EPCs. This checklist covers the handover deliverables, OT architecture requirements, and contract scope items that asset owners, EPCs, and developers increasingly need to address.

What this checklist covers

The checklist is organized into five categories that span the cybersecurity scope of a BESS integration project:

  1. OT Network Architecture — zones and conduits per IEC 62443, network segmentation, firewall configuration, and legacy protocol mitigation.
  2. Access Control & Authentication — default credentials, role-based access, MFA, privileged access management, and vendor account governance.
  3. Commissioning Handover Documentation — the documentation package the asset owner needs for their NIS2 compliance file: network diagrams, asset inventory, credentials register, firewall rules, and vulnerability records.
  4. Supply Chain & Contract Requirements — supplier mapping, cybersecurity contract clauses, incident notification obligations, right-to-audit provisions, and end-of-contract procedures.
  5. Incident Response Readiness — incident response plan, CSIRT reporting readiness, significant-incident thresholds, OT monitoring, and backup recovery.

Each item includes a brief explanation of what it means and why it matters for NIS2 compliance.

Who this is for

  • Asset owners defining what a NIS2-ready commissioning handover must include and what to require from their EPC or integration contractor.
  • EPC contractors scoping cybersecurity into their integration work and preparing for asset owner supply chain audits.
  • Developers specifying cybersecurity requirements in EPC contracts or managing OT integration directly under a split-contract model.
  • OT cybersecurity consultants advising BESS stakeholders on NIS2 compliance and using the checklist as a structured assessment framework.

Get the full checklist

28 items across 5 categories, from OT network architecture to incident response readiness.

No spam. Unsubscribe anytime.