NIS2 Readiness Check
Ten operating questions — answer honestly. Your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.
1.Incident response: is there a documented, tested procedure with named owners?
2.Risk management: is a risk assessment reviewed at least yearly at management level?
3.Supply chain: are critical suppliers security-assessed before and during contracts?
4.Training: do all staff receive regular security training with completion records?
5.Business continuity: are continuity and recovery plans tested, not just written?
6.Encryption: is data encrypted in transit and at rest as a matter of policy?
7.Access control: are privileged accounts inventoried, MFA-enforced and reviewed?
8.Monitoring: are security events logged, retained and actually watched?
9.Governance: does the board receive security reporting and accept residual risk explicitly?
10.Documentation: could you show evidence for any of the above today, on demand?
NIS2 readiness
Answer to scoreWhat the score means
80–100% · Low risk
Controls exist and can mostly be shown. Next step: continuous evidence, so the score stops depending on audit season.
40–79% · Medium / High
The usual state: real work done, proof missing. Onboarding turns it into a running operating model in weeks.
0–39% · Critical
Start with applicability and the clock: your country page shows the authority, the transposition and the deadlines.
Every score
Bring it to a demo — walked through against your actual obligations, not generic advice.
Book a demoTruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.