NIS2 Assessment

Answer 25 guided questions across five key NIS2 areas. You will get a 0-100 score, your readiness tier and the highest-impact recommendations. The calculation runs in your browser: we do not send your answers to any server.

1. Risk identification and management

Is there an up-to-date inventory of critical assets, essential systems and owners?

Does the organization run documented risk assessments at least once a year?

Are cybersecurity risks mapped to operational, legal and financial impact?

Does management formally review and approve the risk management plan?

Are mitigation actions prioritized with owners, deadlines and verifiable evidence?

2. Incident management

Is there a documented and tested incident response plan?

Does the team know escalation and early notification criteria under NIS2?

Are incidents logged with timeline, evidence, root cause and corrective actions?

Are channels defined to coordinate legal, management, IT and suppliers during an incident?

Are incident tabletop exercises or simulations performed at least annually?

3. Business continuity

Are RTO and RPO defined for critical services?

Are backups tested through real restores on a regular basis?

Is there a continuity plan covering unavailability of systems, people and suppliers?

Are recovery procedures documented and accessible outside the primary environment?

Are lessons learned reviewed after tests, incidents or critical changes?

4. Supply chain security

Are suppliers classified by criticality, data access and operational dependency?

Do contracts include security requirements, incident notification and audit rights?

Is the security posture of critical suppliers reviewed periodically?

Is there an onboarding, change and offboarding process for suppliers with access control?

Are concentration or single critical supplier dependency risks assessed?

5. Technical security and cryptography

Is MFA enabled for administrative access, email and critical systems?

Do systems apply security patches with deadlines based on criticality?

Is sensitive data encrypted in transit and at rest where appropriate?

Are security logs monitored with alerts for relevant events?

Do privileged accounts follow least privilege, periodic review and traceability?

NIS2 Assessment

In fifteen minutes, measure your maturity against NIS2 and where to start

NIS2 is the European cybersecurity directive in force since October 2024. It changes the rules of the game for thousands of companies that previously had no formal obligations. This free tool gives you a snapshot of your maturity at a glance: your score against the directive's requirements, which areas are weakest and which actions are most urgent.


What NIS2 is

The NIS2 Directive (Network and Information Security 2) considerably broadens cybersecurity obligations for European companies. Its predecessor, NIS1, covered operators of essential services (energy, transport, banking, health). NIS2 expands to new sectors (postal services, waste management, food, manufacturing), incorporates important entities in addition to essential ones, raises the technical bar of required controls, and tightens penalties for non-compliance.

National transposition in EU member states is ongoing. Inspections are being prepared. Administrative penalties can reach 10 million euros or 2% of global turnover for essential entities (7 million or 1.4% for important ones), in addition to personal liability of management in case of serious non-compliance.

This tool does not replace a formal compliance analysis, but gives you the first operational answer: does it apply to me? what should I look at first? am I far or close to compliance?


Why it matters

The calendar is tight. The directive is in force. National transposition is ongoing or already done in several member states. Supervisory authorities are operational. The comfortable "I will look at it later" deadline no longer exists.

Penalties are material. Up to 10 million euros or 2% of annual global turnover for essential entities; up to 7 million or 1.4% for important entities. Penalties frequently come with public corrective measures that erode customer trust.

Liability reaches management. NIS2 introduces explicit liability of the management body. Approving measures, supervising implementation, receiving training. It is no longer fully delegated to the technical department.

Your customers will ask. If your customer falls under NIS2 and you provide them a relevant ICT service, they will pass the question to you. They can demand new contractual clauses, evidence of controls, capacity to notify incidents within deadlines. Anticipating it is competitive advantage.


What the assessment evaluates

The questionnaire has twenty-five questions organised in five sections of five questions each:

Section 1 · Risk identification and management (5 questions). Identification of the organisation (sector, size, type of service) and risk management maturity: documented risk analysis, approved security policy, assignment of responsibilities, involvement of the management body and periodic review.

Section 2 · Incident management (5 questions). Existence of documented response plan, identified and trained team, criteria and capacity to notify the national authority within NIS2 deadlines (early warning 24h, notification 72h, final report 1 month), communication to affected users and periodic plan testing.

Section 3 · Business continuity (5 questions). Continuity and disaster recovery plans, backups, recovery time and point objectives, restoration testing and crisis management.

Section 4 · Supply chain security (5 questions). Inventory of critical ICT suppliers, contractual security clauses, periodic supplier risk evaluation and capacity for a coordinated response to an incident originating at a supplier.

Section 5 · Technical security and cryptography (5 questions). Identity and access management, control of privileged accounts, encryption of data in transit and at rest, vulnerability and patch management, and network segmentation and monitoring.

Each question has guided options with contextual explanation; you do not need to be a specialist to answer.


Estimated time

Around fifteen minutes for someone with a view of the organisation (manager, CFO, IT or quality lead). The questionnaire is completed in a single session, directly in your browser.


Results you will see

When you close the questionnaire you obtain:

Global score 0-100. A score estimating how your organisation stands against the directive's requirements, calculated instantly from your answers.

Maturity level. Beyond the numerical score, we place your organisation on a qualitative level (from "at critical risk" to "aligned"), to interpret the starting point at a glance.

Breakdown by area. Your score in each of the five areas evaluated (risk identification and management, incident management, business continuity, supply chain and technical security), to see where to concentrate effort.

Priority recommendations. The actions that would have most impact on your compliance level, prioritised by your weakest areas. Not a list of fifty things: the ones that really matter now, ordered from highest to lowest impact.


Who it is for

CISO or security lead who needs a first baseline before a full formal analysis.

CTO or technical director of a mid-sized company without dedicated security function, who wants to understand exposure before budgeting.

DPO or data protection lead who already knows GDPR and needs to position NIS2 relative to what they already manage.

CEO or general manager of SME and mid-market companies who have heard of NIS2 and need to know, in clear language, what it means for their organisation.

Compliance or quality lead who is mapping regulatory obligations and needs to incorporate NIS2 into the panel.


Frequently asked questions

Does it replace a formal compliance analysis?

No. It is a first map, not an exhaustive analysis. If after the result you consider you need a deep diagnosis, we can talk. If the result gives you the comfort you need to manage internally, perfect: the tool has saved you money and time.

What do you do with my answers?

The calculation runs instantly and we do not store your individual answers. Only if you choose to leave your email so we can send you a proposal do we use it for that, and only if you tick the specific box. No automatic newsletter or transfer to third parties.

Is it updated with national transposition?

Yes. We keep the tool up to date with transposition in Spain and monitor transpositions of other relevant member states. If your country's transposition has nuances, we indicate it in the result.

Are my answers sent or stored?

No. We do not store your individual answers. The questionnaire is completed in a single session in your browser; it is best to set aside fifteen uninterrupted minutes to do it in one go.

Is it really free and without catch?

Yes. The full result is free. The commercial option is voluntary: you tick a box if you want us to contact you. If you do not tick it, we do not contact you.

Can several members of the same company do it and compare answers?

Yes. It is a practice we recommend: have the IT lead and the general manager answer separately and compare. Discrepancies usually reveal perception gaps worth discussing before investing.


Want to go further?

If after the assessment you decide you need accompaniment to close gaps, we can talk about a formal diagnosis or the option of monthly vCISO to lead the adaptation programme. No pressure: if the tool has been useful as is, it has saved you money. That is gain already.

Let us talk · [email protected] · Contact us

Try Email Scanner too

Want a tailored assessment? Let us talk