NIS2 Readiness Check
Ten operating questions — answer honestly. Your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.
NIS2 applies to essential and important entities across 18 sectors — energy, transport, banking, health, digital infrastructure and more — established in the EU. Your national transposition sets registration, documentation and enforcement specifics.
1.Governance: has your management body formally approved the cybersecurity risk-management measures, and does it oversee them?
Art. 20(1) — management bodies approve and oversee
2.Risk: is a risk analysis kept current, with information-security policies approved on its basis?
Art. 21(2)(a) — risk analysis and information security policies
3.Incidents: is there a documented, tested handling procedure — and could you file the report on the clock: early warning 24 h, notification 72 h, final within one month?
Art. 21(2)(b) + Art. 23 — incident handling and the reporting deadlines
4.Continuity: are backup, disaster-recovery and crisis-management arrangements tested on a schedule, not just written?
Art. 21(2)(c) — business continuity, backup, disaster recovery, crisis management
5.Supply chain: are critical suppliers security-assessed before and during contracts?
Art. 21(2)(d) — supply chain security
6.Systems: do acquisition, development and maintenance carry security requirements, and are vulnerabilities handled and disclosed per policy?
Art. 21(2)(e) — security in acquisition, development and maintenance
7.Effectiveness: is the effectiveness of your security measures assessed on a cadence — and could you show the result today?
Art. 21(2)(f) — policies to assess the effectiveness of measures
8.Training: do management and all staff receive regular cybersecurity training, with completion tracked?
Art. 20(2) + Art. 21(2)(g) — training and cyber hygiene
9.Encryption: is data encrypted in transit and at rest as a matter of policy?
Art. 21(2)(h) — cryptography and encryption policy
10.Access: are assets and privileged accounts inventoried, is MFA enforced where it matters, and is access reviewed?
Art. 21(2)(i)–(j) — access control, asset management, MFA
NIS2 readiness
Answer to scoreWhat the score means
80–100% · Low risk
Controls exist and can mostly be shown. Next step: continuous evidence, so the score stops depending on audit season.
40–79% · Medium / High
The usual state: real work done, proof missing. Onboarding turns it into a running operating model in weeks.
0–39% · Critical
Start with applicability and the clock: your country page shows the authority, the transposition and the deadlines.
Every score
Bring it to a demo — walked through against your actual obligations, not generic advice.
Book a demoTruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.