The list is not a general security checklist. It is built from the requirements the Act states, and every item carries the article it comes from: governance and training under Art. 21, the measures under Art. 22, incident reporting under Art. 23, the data under Art. 6, certified products under Art. 24, and the supply chain under Art. 22(3) and Art. 26.
That is also the practical benefit: a check does not ask whether a policy exists, but which requirement it covers and what evidences it. An item with a recorded article can be traced; an item without one turns into a dispute about scope.