NIS2 Self-Check: How Ready Is Your Organization?
20 core questions from our assessment catalog with over 125 checkpoints. Evaluate your current cybersecurity maturity in 10 minutes – structured by the key NIS2 requirement domains.
Note: This self-check does not replace a professional assessment. It provides an initial orientation of where you stand and where the greatest need for action lies.
1 Governance & Risk Management
Does a cybersecurity strategy approved by senior management exist?
Is senior management demonstrably involved in monitoring cybersecurity measures (NIS2 Art. 20)?
Does senior management regularly participate in cybersecurity training?
Are cybersecurity risks considered in company-wide risk management?
2 Incident Management
Does a documented incident response plan for cybersecurity incidents exist?
Is the reporting process to BSI implemented according to NIS2 deadlines (early warning 24h, initial report 72h, final report 1 month)?
Are incident response exercises or tabletop exercises conducted regularly?
3 Business Continuity & Crisis Management
Has a Business Impact Analysis (BIA) for critical business processes been conducted?
Does an IT Disaster Recovery Plan with defined RTO/RPO values exist?
4 Supply Chain Security
Are cybersecurity requirements contractually agreed with critical suppliers?
Does a process for monitoring the security posture of critical suppliers exist?
5 Network & Information Security
Does a network security architecture with segmentation and zone concepts exist?
Are security events centrally collected and correlated (SIEM)?
Are penetration tests or vulnerability scans conducted regularly?
6 Cryptography & Encryption
Is data in transit and at rest protected by current encryption methods?
Does a key management process with defined responsibilities exist?
7 Access Controls & MFA
Is Multi-Factor Authentication (MFA) implemented for all remote access and privileged accounts?
Is the principle of least privilege consistently applied?
Are access rights regularly reviewed and recertified?
Please answer all 19 questions.
Full NIS2 Readiness Assessment?
In 3–4 days we audit your organization against all 125 NIS2 checkpoints and deliver a prioritized action plan – at a fixed price.
30 Min · Video-Call · unverbindlich