NIS2 Compliance Assessment
Check your organization's compliance level with NIS2 directive requirements. Answer the questions and receive a detailed report.
16 questions
about 5 min
3 NIS2 areas
How it works
- 1
You answer
For each requirement you pick: yes, partially or no.
- 2
You see the score
Scoring happens instantly, with no sign-up and no waiting.
- 3
You locate the gaps
The area table shows where controls are missing.
- 4
You plan the work
Discuss the result with our team and agree on priorities.
What the assessment covers
20Governance4
- 20.1The management body has approved cybersecurity risk management measures
- 20.1The management body oversees the implementation of cybersecurity measures
- 20.2Management body members undergo regular cybersecurity training
- 20.2Employees regularly receive cybersecurity awareness training
21Cybersecurity Risk Management Measures7
- 21.2.gWorkstations, servers and mobile devices have malware protection
- 21.2.bEvents from key systems are logged and available for incident handling
- 21.2.cBackups run to a defined schedule and scope
- 21.2.cRestoring data from backup is tested periodically
- 21.2.hCryptographic keys have an owner and a defined lifecycle
- 21.2.hBackups are cryptographically protected at rest and in transit
- 21.2.hStorage in portable devices is encrypted
23Reporting Obligations5
- 23.4.aA process exists for early warning to CSIRT within 24 hours of detecting an incident
- 23.4.bA process exists for incident notification within 72 hours including impact assessment
- 23.4.dA final incident report is submitted within 1 month of the notification
- 23.1The relevant CSIRT and the incident reporting channel are known
- 23.3Criteria for classifying an incident as significant are defined internally
Your answers stay in your browser. We do not send them to a server, we do not store them, and we do not ask for your email address.
This assessment is indicative and does not replace a full compliance audit.
