NIS2 Scoring
EUEuropean Union · English
a service bySightadel

Free · no sign-up · about 8 minutes

Do you know where your company stands on NIS2?

Answer 34 short questions and see your score straight away. Free, no sign-up, about eight minutes.

  • Fines up to €10 million
  • Incident reports within 24 hours
  • Management bodies accountable
Guide
Start here1 / 13

Which sector does your company work in?

Employees

Your answers stay anonymous until you request the report.

Independent service by neonotu GmbH. Not affiliated with the institutions of the European Union.

NIS2 in brief

What the directive requires

NIS2 replaced the first NIS Directive and widened its reach from a few operators of essential services to medium-sized and large organisations in 18 sectors. Each Member State turns it into national law, with its own authority, registration portal and fines. This version covers the common EU rules.

18.10.2024Date from which Member States had to apply NIS2
10Minimum measures under Article 21(2)
24 hto send an early warning of a significant incident
€10m / 2%Minimum fine ceiling for essential entities, whichever is higher

What the scoring checks

12 areas, weighted by legal consequences

The questions follow the directive. Duties whose breach can lead directly to a fine or to liability of the management body count more than topics that mainly show maturity. Each area is explained in detail in the guide.

The same questions are also available as a printable checklist.

  1. Management bodyArt. 20 NIS2 · 4 questions · explained
  2. Registration and incident reportingArt. 3(4), 23, 27 NIS2 · 4 questions · explained
  3. Risk analysis and security policiesArt. 21(2)(a) NIS2 · 3 questions · explained
  4. Incident handlingArt. 21(2)(b) NIS2 · 3 questions · explained
  5. Business continuity and crisis managementArt. 21(2)(c) NIS2 · 3 questions · explained
  6. Supply chain securityArt. 21(2)(d) NIS2 · 3 questions · explained
  7. Security in acquisition, development and maintenanceArt. 21(2)(e) NIS2 · 3 questions · explained
  8. Effectiveness of measuresArt. 21(2)(f) NIS2 · 2 questions · explained
  9. Cyber hygiene and trainingArt. 21(2)(g) NIS2 · 2 questions · explained
  10. Cryptography and encryptionArt. 21(2)(h) NIS2 · 2 questions · explained
  11. HR security, access control and assetsArt. 21(2)(i) NIS2 · 3 questions · explained
  12. Authentication and secure communicationArt. 21(2)(j) NIS2 · 2 questions · explained

Guide

NIS2 explained at EU level

Frequently asked questions about the scoring

Is the NIS2 scoring really free?

Yes. You see your score immediately and without signing up. For the full PDF report, you enter your name, company and the email address we send the report to.

How long does the scoring take?

About eight minutes. You answer 34 questions in 12 areas. “Don’t know” is a valid answer and counts as not implemented.

Which legal basis does the assessment use?

This version uses Directive (EU) 2022/2555: classification under Articles 2 and 3 and Annexes I and II, measures under Article 21, reporting under Article 23, registration under Article 3(4) and Article 27, and management duties under Article 20. National laws can go further. If your country has its own version on this site, use that one.

How is the score calculated?

Each answer earns 0 to 3 points. Questions with a direct legal consequence, such as registration or the reporting chain, count up to three times. The total is the weighted share of points achieved, from 0 to 100.

What happens to my data?

Your answers are processed only for the assessment. We use your name, company and email address to send the report and handle your request. We only contact you if you tick the box. Details in the privacy policy.

Does the scoring replace legal advice or an audit?

No. It is an initial assessment based on your own answers. It shows where you stand and where to start.