Self-assessment · NIS2 directive

NIS2 Self-Assessment

In 16 simple questions, find out where your organisation stands against the requirements of the NIS2 directive (network and information systems security). Instant score; detailed per-criterion analysis on request.

No expertise required: answer honestly, based on your organisation’s real situation. It takes about 5 minutes.

  1. 1

    Do you know whether your organisation falls within NIS2 scope (essential or important entity), and have you registered with the competent authority if required?

  2. 2

    Has your management formally approved the security measures, and does it regularly follow up on their implementation?

  3. 3

    Do your executives and teams regularly receive cybersecurity training or awareness sessions?

  4. 4

    Do you run a regular risk analysis covering your critical systems, networks and services?

  5. 5

    Do you have written security policies (access, passwords, backups, remote work…) that are actually applied?

  6. 6

    Do you apply security patches quickly and keep your systems up to date?

  7. 7

    Does access to your sensitive systems require strong authentication (MFA), and do you encrypt data where relevant?

  8. 8

    Can you detect a security incident on your systems (logs, alerts, monitoring)?

  9. 9

    Do you have an incident-management procedure stating who does what, tested at least once?

  10. 10

    Could you notify a significant incident to the competent authority within the NIS2 deadlines (early warning within 24h, notification within 72h)?

  11. 11

    Are your critical data and systems backed up, with tested restorations?

  12. 12

    Do you have a business continuity and recovery plan covering a major outage or cyberattack?

  13. 13

    Have you organised crisis management (roles, backup communication channels, exercises)?

  14. 14

    Do you know your critical suppliers and service providers, and do you assess their security level?

  15. 15

    Do your contracts with these suppliers include security requirements (incident notification, audits, exit clauses)?

  16. 16

    Do you take security into account when buying or developing new systems and services?

0 / 16