Blog Risk Management

NIS2 Risk Analysis: How to Conduct It Correctly (with a Downloadable Template)

Risk analysis is a legal requirement and at the same time the most important tool for effective NIS2 compliance. We provide a complete methodology, template and specific risk examples for different sectors.

10 February 2026 · 7 minutes reading · Risk Management

Decree No. 409/2025 Coll. Places risk analysis first: it is item No. 1 of the 13 mandatory security measures under Act No. 264/2025 Coll. Without a performed and documented risk analysis, you cannot claim compliance with NIS2. The regulator (NÚKIB) will require it as one of the first documents during an inspection.

Good news: risk analysis is not rocket science. With the right methodology and a structured template, even an internal team without specialised training in cybersecurity can handle it. This article will guide you through the entire process.

Why risk analysis is the foundation of NIS2 compliance

NIS2 takes a systematic approach to security: first understand your risks, then implement proportionate measures. This approach is reflected in the structure of Decree 409/2025 Coll., other areas of measures (access control, cryptography, incident detection...) all stem from the conclusions of the risk analysis.

In practice, this means that without a risk analysis:

Risk analysis methodology for NIS2

We recommend a five-step process that fully complies with the requirements of Decree 409/2025 Coll. And respects international standards (ISO 27005, NIST SP 800-30).

Step 1: Asset Identification

First, you must know what you are protecting. Compile an inventory of assets relevant to your key services (see our NIS2 audit guide). For each asset, record:

Examples of assets: production SCADA system, customer database, email server, VPN access, data backups, process documentation.

Step 2: Threat Identification

For each asset or group of assets, identify the relevant threats. A threat is a potential cause of an undesirable event. Use threat catalogues, for example, the NÚKIB catalogue or the ENISA Threat Landscape.

Typical threat categories for regulated entities:

Step 3: Identification of vulnerabilities

A vulnerability is a weakness that a threat can exploit. For each threat, identify the vulnerabilities in your environment:

Step 4: Risk Assessment (Probability × Impact)

For every combination of asset, threat and vulnerability, assess the risk. We use a qualitative scale of 1–5:

Prioritisation based on result:

Step 5: Selection of measures and acceptance of residual risk

For each risk, decide on a management strategy:

Examples of specific risks for different sectors

Healthcare

Energy and Industry

Digital infrastructure and IT services

What a risk analysis must contain according to Decree 409/2025

The decree does not require a specific format, but the output documentation must demonstrate:

NIS2 Risk Analysis Template (Excel)

We have prepared a clear Excel template containing:

You will receive the template after registering on secureon.cz SecureOn.cz or directly via the online audit tool on nis2ok.czwhere risk analysis is part of the structured NIS2 compliance process.

How to keep risk analysis up to date

A risk analysis is not a one-off document: the law requires regular review. We recommend:

Version and archive every update: the regulator may require proof of your security status development history.

Start your risk analysis today

A free NIS2 audit at nis2ok.cz will guide you through key areas and help identify the main risks in your environment.

Start a free audit →