Self-survey

NIS2 readiness self-survey

Twelve quick checks across the four NIS2 pillars: governance, risk management, incident handling, and supply-chain due diligence. You'll get an indicative readiness score and we'll point you at the highest-impact gaps.

About 8 minutes

Where should we send the result?
1 Governance Board accountability and policy structure.

Is there a named senior officer (CISO or equivalent) accountable for cybersecurity?

Is your cybersecurity strategy reviewed and approved by the board at least annually?

Are cyber-risk metrics reported to the board at least quarterly?

2 Risk management Identification, treatment and review of cyber risks.

Do you maintain a current cyber-risk register with owners and treatment plans?

Have you completed a Business Impact Analysis (BIA) for your essential services in the last 12 months?

Do you enforce multi-factor authentication on all administrative accounts?

3 Incident handling Detection, response, and notification readiness.

Do you have a written incident-response plan tested in the last 12 months?

Can you meet the NIS2 24-hour early-warning notification deadline?

Do you log and retain security-relevant events for at least 12 months?

4 Supply chain Third-party risk and vendor oversight.

Do your contracts with critical providers include cybersecurity and incident-notification clauses?

Do you maintain a list of critical suppliers with risk classifications?

Do you re-assess critical suppliers at least annually?

We email the result to you. Nothing is shared without consent.