NIS2 readiness assessment in 15 minutes
NIS2Certify is an online NIS2 readiness assessment. In about 15 minutes you answer 55 questions mapped to the 10 risk-management measures of Article 21 of Directive (EU) 2022/2555, and you get a PDF report with a score per domain and a prioritised action plan. It is a gap analysis, not a certification.
Why NIS2Certify?
NIS2Certify turns the 10 measures of Article 21 into 55 plain questions, so you see in one session which measures are in place and which are missing.
Fast & Simple
Complete your first assessment in less than 15 minutes. No technical knowledge required.
Built on Article 21
Every question maps to one of the 10 measures of Article 21(2) of Directive (EU) 2022/2555, so the report follows the structure your regulator uses.
Instant Reports
Receive a comprehensive PDF report immediately with your score, risk analysis and actionable recommendations.
What NIS2 requires
and what our scan covers
24/72
Hours for the early warning and the incident notification (Article 23)
Source: NIS2 Directive (EU) 2022/2555, Article 23Our scan asks 55 questions, mapped to Article 21, and covers all 10 risk-management domains of Article 21(2). Available in 7 languages.
Does NIS2 apply to your organisation?
That depends on your sector, your size and where you operate. NIS2 applies to medium and large organisations in 18 sectors, from energy, health and drinking water to digital infrastructure, food and manufacturing. Some providers, such as public administration bodies and DNS service providers, are in scope regardless of size. Your national law decides the details.
- Size
- 50 or more employees, or fewer than 50 employees with both annual turnover and balance sheet total above €10 million.
- Essential entity
- Large organisation in an Annex I sector, such as energy, transport, health, drinking water and digital infrastructure. Supervised proactively; maximum fine of at least €10 million or 2% of worldwide annual turnover.
- Important entity
- Medium-sized organisation in an Annex I sector, or medium-sized and large organisation in an Annex II sector, such as postal services, waste management, chemicals, food and manufacturing. Supervised after the fact; maximum fine of at least €7 million or 1.4%.
- UK companies
- NIS2 does not apply in the UK. A UK group is in scope through its EU subsidiaries, and some digital providers, such as cloud, DNS and managed service providers, are in scope when they offer services in the EU (Article 26).
- Which law applies
- The national law of the member state where you are established, or for some digital providers where your main establishment is. Registration and reporting go to that country’s authority.
Transparent Pricing
Buy a single assessment for your own organisation, or subscribe if you assess several clients as an adviser.
25% discount for the first 100 customers — stays valid for as long as your subscription runs
Limited spots remaining
Single Scan
One-time NIS2 readiness scan
- 1 complete NIS2 assessment
- PDF report with score and recommendations
- Concrete action plan per category
Starter
Ideal for small teams
- Up to 5 clients
- Up to 3 users
- 10 reports per month
Professional
For growing advisory firms
- Up to 15 clients
- 30 reports per month
Enterprise
For large organisations and partners
- Unlimited clients and users
- White-label branding
How it works
Four steps to a score per NIS2 measure
Create Account
Create an account and choose a plan
Fill in Questionnaire
Answer 55 questions across 10 NIS2 categories
Receive Score
Immediate insight into your compliance level with weighted scores
Download Report
Comprehensive PDF report with recommendations and action plan
Incident Handling
Does your organisation have a formal incident response plan?
Score per category
- Governance & Risk Management72%
- Incident Handling58%
- Supply Chain Security34%
- Access Control83%
Comprehensive PDF report with recommendations and action plan
Frequently Asked Questions
Answers to the most common questions about NIS2Certify
What is NIS2 compliance?
NIS2 compliance means meeting the obligations of Directive (EU) 2022/2555 as implemented in your member state: risk-management measures in the 10 areas of Article 21, incident reporting (early warning within 24 hours, notification within 72 hours, final report within one month of the incident notification), registration with the competent authority, and oversight by the management body. National authorities enforce it, not the EU directly.
What is NIS2? The full guideWho needs to be NIS2 compliant?
Medium and large organisations in the 18 sectors of Annexes I and II: 50 or more employees, or fewer with both turnover and balance sheet above €10 million. Some providers are in scope regardless of size, such as public administration bodies and DNS service providers. Smaller suppliers are often pulled in through the supply-chain requirements of in-scope customers.
Does NIS2 apply to my organisation?Is NIS2 applicable in the UK?
No. NIS2 is an EU directive and does not apply in the UK, which is reforming its own NIS Regulations 2018. A UK company is still affected through subsidiaries in the EU, and cloud, DNS, managed service and some other digital providers that offer services in the EU must designate a representative in a member state (Article 26).
NIS2 Article 26: which regulator supervises youIs NIS2 already law in Ireland and the rest of the EU?
Not everywhere. Member states had to transpose NIS2 by 17 October 2024, but on 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to do so in full. Ireland’s National Cyber Security Bill has not yet been enacted. The Netherlands has since applied its Cyberbeveiligingswet from 15 August 2026.
Ireland’s National Cyber Security Bill explainedDoes ISO 27001 make you NIS2 compliant?
Not on its own. ISO 27001 is a voluntary, certifiable standard; NIS2 is a legal obligation. An ISO 27001 management system covers much of Article 21, but not registration with your authority, the 24- and 72-hour incident reports or the training duty of the management body. Treat it as strong evidence and close the remaining gaps with a NIS2-specific assessment.
NIS2 vs ISO 27001: what overlapsIs my data secure?
Yes, we take security very seriously. All data is stored encrypted, we use multi-tenant isolation, and comply with GDPR. Your data is never shared with third parties and you can delete your account and data at any time.
Can I cancel my subscription?
Yes, you can cancel your subscription at any time. There is no notice period. After cancellation you keep access to your account until the end of the paid period: until the end of the current month on a monthly subscription, and until the end of the current annual term on an annual subscription. Amounts already paid are not refunded.
Ask a question about NIS2
Our assistant answers from our NIS2 knowledge base and links the articles it used.
Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.
Free NIS2 Compliance Guide
Download our comprehensive guide to understanding NIS2 requirements and preparing your organisation for compliance.
- Complete overview of all 10 NIS2 compliance categories
- Practical checklist for immediate implementation
- Practical tips for each Article 21 measure
PDF — 10 pages — Free
Ready to get started?
Start your NIS2 compliance readiness scan today and discover where your organisation stands.
View Pricing