Skip to main content
TOOLS

NIS2 Readiness Check

Ten operating questions — answer honestly. Your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.

NIS2 applies to essential and important entities across 18 sectors — energy, transport, banking, health, digital infrastructure and more — established in the EU. Your national transposition sets registration, documentation and enforcement specifics.

0/10
  1. 1.Governance: has your management body formally approved the cybersecurity risk-management measures, and does it oversee them?

    Art. 20(1) — management bodies approve and oversee

  2. 2.Risk: is a risk analysis kept current, with information-security policies approved on its basis?

    Art. 21(2)(a) — risk analysis and information security policies

  3. 3.Incidents: is there a documented, tested handling procedure — and could you file the report on the clock: early warning 24 h, notification 72 h, final within one month?

    Art. 21(2)(b) + Art. 23 — incident handling and the reporting deadlines

  4. 4.Continuity: are backup, disaster-recovery and crisis-management arrangements tested on a schedule, not just written?

    Art. 21(2)(c) — business continuity, backup, disaster recovery, crisis management

  5. 5.Supply chain: are critical suppliers security-assessed before and during contracts?

    Art. 21(2)(d) — supply chain security

  6. 6.Systems: do acquisition, development and maintenance carry security requirements, and are vulnerabilities handled and disclosed per policy?

    Art. 21(2)(e) — security in acquisition, development and maintenance

  7. 7.Effectiveness: is the effectiveness of your security measures assessed on a cadence — and could you show the result today?

    Art. 21(2)(f) — policies to assess the effectiveness of measures

  8. 8.Training: do management and all staff receive regular cybersecurity training, with completion tracked?

    Art. 20(2) + Art. 21(2)(g) — training and cyber hygiene

  9. 9.Encryption: is data encrypted in transit and at rest as a matter of policy?

    Art. 21(2)(h) — cryptography and encryption policy

  10. 10.Access: are assets and privileged accounts inventoried, is MFA enforced where it matters, and is access reviewed?

    Art. 21(2)(i)–(j) — access control, asset management, MFA

0%

NIS2 readiness

Answer to score

What the score means

80–100% · Low risk

Controls exist and can mostly be shown. Next step: continuous evidence, so the score stops depending on audit season.

40–79% · Medium / High

The usual state: real work done, proof missing. Onboarding turns it into a running operating model in weeks.

0–39% · Critical

Start with applicability and the clock: your country page shows the authority, the transposition and the deadlines.

Every score

Bring it to a demo — walked through against your actual obligations, not generic advice.

Book a demo

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

Frequently Asked Questions

What does the NIS2 readiness check measure?
Ten operating conditions drawn from the directive itself — Article 20 governance and training, the Article 21(2) risk-management measures, and the Article 23 reporting clock. Each question maps to a clause, shown under the question.
Is the score an official NIS2 assessment?
No. It is an indicative maturity score from ten questions, not an assessment of record. Supervisors judge compliance against the full directive and your national transposition — the check tells you where the gaps are.
Does NIS2 apply to me?
The sector test and the size test decide most cases, and the binding answer is always national. See the dedicated applicability page for both tests and the exceptions — then start with your country page for the authority and the deadlines.