NIS2 Quick Assessment

Answer 18 quick questions to see where you stand.

Current risk score 0 of 18 answered
0.0 /100 Low risk
Governance & risk management

Governance & risk management

Policies, accountability, and how risk decisions get made.

Not answered

Has management formally approved an information security policy?

NIS2 makes management bodies personally accountable for approving risk-management measures.

Is there a named person accountable for cybersecurity?

A specific individual, not "IT in general".

Do you maintain a documented risk register?

Identified risks, their owners, and treatment decisions.

Incident handling

Incident handling

Detection, response, and the 24-hour reporting obligation.

Not answered

Do you have a documented incident response plan?

Roles, escalation paths, and communication steps written down in advance.

How would you detect a compromise today?

Consider whether anyone is actually watching the alerts outside office hours.

Could you file an early warning to the authorities within 24 hours of a significant incident?

NIS2 requires an early warning within 24 hours and a full notification within 72 hours.

Business continuity & backup

Business continuity & backup

Backups, recovery targets, and crisis management.

Not answered

How are your backups protected against ransomware?

Backups reachable with normal admin credentials get encrypted along with everything else.

When did you last successfully restore from backup as a test?

An untested backup is a hypothesis, not a control.

Are recovery time and recovery point objectives defined for critical systems?

How much downtime and how much data loss the business has agreed it can absorb.

Supply chain security

Supply chain security

Supplier risk, contracts, and third-party access.

Not answered

Do you maintain an inventory of suppliers with access to your systems or data?

Including SaaS vendors and managed service providers.

Do supplier contracts include security requirements and breach notification duties?

NIS2 pushes obligations down the supply chain to your vendors.

How is third-party remote access to your network controlled?

Vendor remote access is a recurring initial access vector.

Access control & cryptography

Access control & cryptography

Authentication, privilege management, and encryption.

Not answered

Is multi-factor authentication enforced on remote access and email?

NIS2 Article 21(2)(j) explicitly names multi-factor authentication.

How are administrator accounts managed?

Shared admin passwords make attribution impossible after an incident.

Is sensitive data encrypted at rest on laptops and servers?

Full-disk encryption on endpoints, plus encryption for sensitive databases.

Cyber hygiene & training

Cyber hygiene & training

Patching, vulnerability handling, and staff awareness.

Not answered

How quickly are critical security patches applied?

Measured from vendor release to deployment on production systems.

Do you run vulnerability scanning or penetration testing?

Article 21(2)(e) covers vulnerability handling and disclosure.

Do staff receive security awareness training?

NIS2 requires training for management bodies specifically, not just staff.

How can we reach you?

How can we reach you?

Our team reviews every assessment and follows up personally.

Your answers and contact details go to our team, who will review them and get in touch. Your score is shown on screen as soon as you submit.

By submitting this assessment you agree to our Privacy Policy.