NIS2 self-check: is your organisation in scope?
Answer 13 questions — one per NIS2 measure area — and see where you stand in a few minutes. The check runs entirely in your browser: no tracking, no data transmitted.
An honest picture, immediately usable
All measure areas
Yes / partly / no
National reference
Get the NIS2 checklist as a PDF
The checklist covering all mandatory Article 21 measures — a practical starting point for your own documentation.
Used only to send the checklist. No newsletter without separate consent.
What the checklist leads to
Screenshots from the English edition with the EU country pack, filled with sample data.
One screen, whole state
Processing status, fulfilment rate and certification readiness sit on one screen, so a status update takes a glance, not a meeting.
Search, don't scroll
Filters for status, obligation level and scope narrow the catalogue down instead of asking you to scroll a list from A to Z.
Tasks, on a board
The same tasks from the project plan sorted into open, in progress and done — for teams who read a board faster than a list.
What does the NIS2 checklist cover?
The checklist follows the ten measures that Article 21 of the NIS2 Directive requires. For each measure it says what you need to be able to demonstrate and which document carries that evidence — so you do not start from a blank page.
- Risk analysis and information security policies — the starting point the other nine measures rest on
- Incident handling: how you detect, record, escalate and close an incident
- Business continuity: backup management, disaster recovery and crisis management, including evidence that you tested the recovery
- Supply chain security: what you agreed with the suppliers and service providers who can reach your systems
- Secure acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure
- Assessing effectiveness: how you measure whether the measures work, and when you last did so
- Cyber hygiene and training, for staff and for the board
- Cryptography and encryption: a written policy on where you encrypt and why
- Human resources security, access control and asset management: who may reach what, and what happens when someone leaves
- Multi-factor authentication and secured communications, including for emergencies
The order is not arbitrary. Without a documented risk assessment the other nine measures cannot be justified: the law prescribes no product list, it requires your measures to be demonstrably appropriate and proportionate to the risks you identified yourself. What that means in your sector is filled in by national law — the outline is on the page about the NIS2 Directive.
What the self-check does and does not do
The self-check gives you an indication within minutes: is your organisation likely in scope, and how far along are you across the thirteen measure areas? It is not a legal opinion and not a risk assessment — it is the starting point for one.
Whether the law applies to you depends on two things at once: your sector and your size. NIS2 works with sector annexes and with thresholds for medium and large organisations — as a rule from 50 employees or 10 million euros in turnover. But size is only the rule. Article 2(2) pulls some organisations in regardless of size, among them trust service providers, DNS service providers and any entity that is the sole provider in a member state of a service essential to society or the economy. That combination makes the question harder than “do we have more than fifty people?”. Which sectors and thresholds apply is set out under who is affected.
The check runs entirely in your browser. No answers are transmitted and no account is needed; what you enter stays on your own device. That is deliberate: the questions touch on what is not yet in order in your organisation, and that information does not belong on someone else’s server.
One more thing the check cannot do for you: NIS2 is a directive, so the binding text is your national law. If you operate in several member states, the duty of care is much the same everywhere, but registration, supervision and deadlines are not.
About the check and the checklist
Is the NIS2 checklist free?
Yes. You request the PDF with your business email address and confirm that request once by email (double opt-in). The checklist is then sent to you. No newsletter without separate consent.
How long does the self-check take?
Five to ten minutes. Thirteen questions, one per measure area, each answered with yes, partly or no.
Are my answers stored?
No. The check runs entirely in your browser. No answers go to a server and no registration is required.
Does the check replace a risk assessment?
No. The check shows where the largest gaps are. The risk assessment Article 21 requires is a documented exercise in its own right, with its own outcome.
What if it turns out I am in scope?
Then the duty of care, the reporting deadlines of 24 hours, 72 hours and one month and the registration obligation apply, on the date your national law sets. The NIS2 software brings those three together in one local record.
What happens if I do nothing?
For essential entities fines reach at least 10 million euros or 2 per cent of worldwide annual turnover, for important entities at least 7 million euros or 1.4 per cent, whichever is higher in each case. Management can also be held personally responsible — more on the fines.
In scope? Here is the next step
The local NIS2 software covers the Article 21 duty of care, incident reporting (24h/72h) and registration — without the cloud.