NIS2 Quick Assessment

Answer 18 quick questions to see where you stand.

Current risk score
0/100

Governance & risk management

Policies, accountability, and how risk decisions get made.

Not answered
Has management formally approved an information security policy?

NIS2 makes management bodies personally accountable for approving risk-management measures.

Is there a named person accountable for cybersecurity?

A specific individual, not "IT in general".

Do you maintain a documented risk register?

Identified risks, their owners, and treatment decisions.

Incident handling

Detection, response, and the 24-hour reporting obligation.

Not answered
Do you have a documented incident response plan?

Roles, escalation paths, and communication steps written down in advance.

How would you detect a compromise today?

Consider whether anyone is actually watching the alerts outside office hours.

Could you file an early warning to the authorities within 24 hours of a significant incident?

NIS2 requires an early warning within 24 hours and a full notification within 72 hours.

Business continuity & backup

Backups, recovery targets, and crisis management.

Not answered
How are your backups protected against ransomware?

Backups reachable with normal admin credentials get encrypted along with everything else.

When did you last successfully restore from backup as a test?

An untested backup is a hypothesis, not a control.

Are recovery time and recovery point objectives defined for critical systems?

How much downtime and how much data loss the business has agreed it can absorb.

Supply chain security

Supplier risk, contracts, and third-party access.

Not answered
Do you maintain an inventory of suppliers with access to your systems or data?

Including SaaS vendors and managed service providers.

Do supplier contracts include security requirements and breach notification duties?

NIS2 pushes obligations down the supply chain to your vendors.

How is third-party remote access to your network controlled?

Vendor remote access is a recurring initial access vector.

Access control & cryptography

Authentication, privilege management, and encryption.

Not answered
Is multi-factor authentication enforced on remote access and email?

NIS2 Article 21(2)(j) explicitly names multi-factor authentication.

How are administrator accounts managed?

Shared admin passwords make attribution impossible after an incident.

Is sensitive data encrypted at rest on laptops and servers?

Full-disk encryption on endpoints, plus encryption for sensitive databases.

Cyber hygiene & training

Patching, vulnerability handling, and staff awareness.

Not answered
How quickly are critical security patches applied?

Measured from vendor release to deployment on production systems.

Do you run vulnerability scanning or penetration testing?

Article 21(2)(e) covers vulnerability handling and disclosure.

Do staff receive security awareness training?

NIS2 requires training for management bodies specifically, not just staff.

Where should we send the results?

Our team reviews every assessment and follows up with the detail.

By submitting this assessment you agree to our Privacy Policy.