NIS-2 self-check

Twelve questions, five minutes, no registration: a first orientation on whether NIS-2 applies to your company and where your measures stand today. The check is not a substitute for legal advice – it shows what you should be talking about.

Part 1: Scope

  1. A01

    Does your company operate in one of the 18 NIS-2 sectors (including energy, transport, health, chemicals, food, manufacturing, digital services)?

  2. A02

    Do you employ 50 or more people – or do both your turnover and your balance-sheet total exceed EUR 10 million?

  3. A03

    Do you supply customers who are themselves regulated (energy utilities, banks, healthcare, large industry)?

  4. A04

    Is your company already registered with the BSI (Germany's Federal Office for Information Security)?

Part 2: Measure maturity

  1. B01

    Are all external access paths (VPN, cloud, remote maintenance) protected with multi-factor authentication?

  2. B02

    Do you have an immutable backup copy – and has recovery been tested within the last 12 months?

  3. B03

    Is there a documented process for security incidents, including the NIS-2 reporting deadlines (24 h / 72 h / 1 month)?

  4. B04

    Is there a documented IT risk analysis that management is aware of and has approved?

  5. B05

    Are staff and management trained on IT security on a regular basis?

  6. B06

    Is your network segmented (office, servers, production, guests kept separate)?

  7. B07

    Is there a governed patch and vulnerability management process with defined deadlines?

  8. B08

    Do you have an IT contingency plan that has been exercised or reviewed within the last 12 months?

The evaluation runs entirely in your browser – no data is transmitted or stored.

Rather talk directly than click?