Assess your situation
Essential or important entity? Our tool determines your classification in 3 questions.
In force since 17 Oct 2024·Day 564·Penalties active·
In force · 17 Oct 2024Penalties activeDay 564Updated 04 May 2026
An independent editorial resource for NIS2. Two minutes to know if you’re affected, and a concrete plan to get there.
160,000
entities affected across Europe
18
sectors covered
€10M
maximum fine
72h
to report an incident
§01 · Where to start
Answer 3 questions to find out if NIS2 applies to your sector and size.
Run the test02 / 03Governance, risk management, 72h notification: the 21 measures to deploy, explained simply.
Read the guide03 / 03Fines up to €10M, personal liability for directors, bans from exercising management roles.
See the sanctions§02 · The path
Essential or important entity? Our tool determines your classification in 3 questions.
21 checkpoints covering governance, technical measures and incidents. Tick what is in place.
Get a compliance score and a prioritised action list, ready to share with your board.
§03 · Coverage
Health · Essential entity§04 · The bulletin
GovernanceArticle 20 of Directive 2022/2555 moves cybersecurity formally into the boardroom. Here are the five responsibilities that now fall personally on directors.
Incident managementA cyber incident strikes. The NIS2 clock starts. Here is exactly what you must do, hour by hour.
Supply chainArticle 21(2)(d) of Directive 2022/2555 explicitly mandates supply chain security. Here are 5 concrete contractual clauses to add to every critical supplier contract.
Action · Run the checklist§ Action
Take the 21-point assessment. Score in two minutes. Walk away with a prioritised action plan ready to share with your board.