Skip to main content

NIS2 readiness assessment in 15 minutes

NIS2Certify is an online NIS2 readiness assessment. In about 15 minutes you answer 55 questions mapped to the 10 risk-management measures of Article 21 of Directive (EU) 2022/2555, and you get a PDF report with a score per domain and a prioritised action plan. It is a gap analysis, not a certification.

Why NIS2Certify?

NIS2Certify turns the 10 measures of Article 21 into 55 plain questions, so you see in one session which measures are in place and which are missing.

Fast & Simple

Complete your first assessment in less than 15 minutes. No technical knowledge required.

Built on Article 21

Every question maps to one of the 10 measures of Article 21(2) of Directive (EU) 2022/2555, so the report follows the structure your regulator uses.

Instant Reports

Receive a comprehensive PDF report immediately with your score, risk analysis and actionable recommendations.

NIS2 in Numbers

What NIS2 requires
and what our scan covers

24/72

Hours for the early warning and the incident notification (Article 23)

Source: NIS2 Directive (EU) 2022/2555, Article 23

Our scan asks 55 questions, mapped to Article 21, and covers all 10 risk-management domains of Article 21(2). Available in 7 languages.

Does NIS2 apply to your organisation?

That depends on your sector, your size and where you operate. NIS2 applies to medium and large organisations in 18 sectors, from energy, health and drinking water to digital infrastructure, food and manufacturing. Some providers, such as public administration bodies and DNS service providers, are in scope regardless of size. Your national law decides the details.

Size
50 or more employees, or fewer than 50 employees with both annual turnover and balance sheet total above €10 million.
Essential entity
Large organisation in an Annex I sector, such as energy, transport, health, drinking water and digital infrastructure. Supervised proactively; maximum fine of at least €10 million or 2% of worldwide annual turnover.
Important entity
Medium-sized organisation in an Annex I sector, or medium-sized and large organisation in an Annex II sector, such as postal services, waste management, chemicals, food and manufacturing. Supervised after the fact; maximum fine of at least €7 million or 1.4%.
UK companies
NIS2 does not apply in the UK. A UK group is in scope through its EU subsidiaries, and some digital providers, such as cloud, DNS and managed service providers, are in scope when they offer services in the EU (Article 26).
Which law applies
The national law of the member state where you are established, or for some digital providers where your main establishment is. Registration and reporting go to that country’s authority.

Transparent Pricing

Buy a single assessment for your own organisation, or subscribe if you assess several clients as an adviser.

Founding Member

25% discount for the first 100 customers — stays valid for as long as your subscription runs

Limited spots remaining

Single Scan

One-time NIS2 readiness scan

€299 one-time
  • 1 complete NIS2 assessment
  • PDF report with score and recommendations
  • Concrete action plan per category
Order now

Starter

Ideal for small teams

From €149/month
  • Up to 5 clients
  • Up to 3 users
  • 10 reports per month
View Starter
MOST POPULAR

Professional

For growing advisory firms

From €449/month
  • Up to 15 clients
  • 30 reports per month
View Professional

Enterprise

For large organisations and partners

From €899/month
  • Unlimited clients and users
  • White-label branding
View Enterprise

How it works

Four steps to a score per NIS2 measure

  1. Create Account

    Create an account and choose a plan

  2. Fill in Questionnaire

    Answer 55 questions across 10 NIS2 categories

  3. Receive Score

    Immediate insight into your compliance level with weighted scores

  4. Download Report

    Comprehensive PDF report with recommendations and action plan

Example result

Incident Handling

Does your organisation have a formal incident response plan?

YesPartialNoNot applicable

Score per category

  • Governance & Risk Management72%
  • Incident Handling58%
  • Supply Chain Security34%
  • Access Control83%

Comprehensive PDF report with recommendations and action plan

Frequently Asked Questions

Answers to the most common questions about NIS2Certify

What is NIS2 compliance?

NIS2 compliance means meeting the obligations of Directive (EU) 2022/2555 as implemented in your member state: risk-management measures in the 10 areas of Article 21, incident reporting (early warning within 24 hours, notification within 72 hours, final report within one month of the incident notification), registration with the competent authority, and oversight by the management body. National authorities enforce it, not the EU directly.

What is NIS2? The full guide
Who needs to be NIS2 compliant?

Medium and large organisations in the 18 sectors of Annexes I and II: 50 or more employees, or fewer with both turnover and balance sheet above €10 million. Some providers are in scope regardless of size, such as public administration bodies and DNS service providers. Smaller suppliers are often pulled in through the supply-chain requirements of in-scope customers.

Does NIS2 apply to my organisation?
Is NIS2 applicable in the UK?

No. NIS2 is an EU directive and does not apply in the UK, which is reforming its own NIS Regulations 2018. A UK company is still affected through subsidiaries in the EU, and cloud, DNS, managed service and some other digital providers that offer services in the EU must designate a representative in a member state (Article 26).

NIS2 Article 26: which regulator supervises you
Is NIS2 already law in Ireland and the rest of the EU?

Not everywhere. Member states had to transpose NIS2 by 17 October 2024, but on 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to do so in full. Ireland’s National Cyber Security Bill has not yet been enacted. The Netherlands has since applied its Cyberbeveiligingswet from 15 August 2026.

Ireland’s National Cyber Security Bill explained
Does ISO 27001 make you NIS2 compliant?

Not on its own. ISO 27001 is a voluntary, certifiable standard; NIS2 is a legal obligation. An ISO 27001 management system covers much of Article 21, but not registration with your authority, the 24- and 72-hour incident reports or the training duty of the management body. Treat it as strong evidence and close the remaining gaps with a NIS2-specific assessment.

NIS2 vs ISO 27001: what overlaps
Is my data secure?

Yes, we take security very seriously. All data is stored encrypted, we use multi-tenant isolation, and comply with GDPR. Your data is never shared with third parties and you can delete your account and data at any time.

Can I cancel my subscription?

Yes, you can cancel your subscription at any time. There is no notice period. After cancellation you keep access to your account until the end of the paid period: until the end of the current month on a monthly subscription, and until the end of the current annual term on an annual subscription. Amounts already paid are not refunded.

Ask a question about NIS2

Our assistant answers from our NIS2 knowledge base and links the articles it used.

Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.

Free NIS2 Compliance Guide

Download our comprehensive guide to understanding NIS2 requirements and preparing your organisation for compliance.

  • Complete overview of all 10 NIS2 compliance categories
  • Practical checklist for immediate implementation
  • Practical tips for each Article 21 measure

PDF — 10 pages — Free

We respect your privacy. Your email will only be used for relevant NIS2 updates.

Ready to get started?

Start your NIS2 compliance readiness scan today and discover where your organisation stands.

View Pricing