NIS2 Compliance Assessment

    Check your organization's compliance level with NIS2 directive requirements. Answer the questions and receive a detailed report.

    16 questions
    about 5 min
    3 NIS2 areas

    How it works

    1. 1

      You answer

      For each requirement you pick: yes, partially or no.

    2. 2

      You see the score

      Scoring happens instantly, with no sign-up and no waiting.

    3. 3

      You locate the gaps

      The area table shows where controls are missing.

    4. 4

      You plan the work

      Discuss the result with our team and agree on priorities.

    What the assessment covers

    20Governance4
    • 20.1The management body has approved cybersecurity risk management measures
    • 20.1The management body oversees the implementation of cybersecurity measures
    • 20.2Management body members undergo regular cybersecurity training
    • 20.2Employees regularly receive cybersecurity awareness training
    21Cybersecurity Risk Management Measures7
    • 21.2.gWorkstations, servers and mobile devices have malware protection
    • 21.2.bEvents from key systems are logged and available for incident handling
    • 21.2.cBackups run to a defined schedule and scope
    • 21.2.cRestoring data from backup is tested periodically
    • 21.2.hCryptographic keys have an owner and a defined lifecycle
    • 21.2.hBackups are cryptographically protected at rest and in transit
    • 21.2.hStorage in portable devices is encrypted
    23Reporting Obligations5
    • 23.4.aA process exists for early warning to CSIRT within 24 hours of detecting an incident
    • 23.4.bA process exists for incident notification within 72 hours including impact assessment
    • 23.4.dA final incident report is submitted within 1 month of the notification
    • 23.1The relevant CSIRT and the incident reporting channel are known
    • 23.3Criteria for classifying an incident as significant are defined internally

    Your answers stay in your browser. We do not send them to a server, we do not store them, and we do not ask for your email address.

    This assessment is indicative and does not replace a full compliance audit.