NIS2 Compliance Readiness Assessment
Assess your organization's readiness for the NIS2 Directive before the June 2026 enforcement deadline. Get your compliance score, gap report, and penalty exposure in minutes.
Loading assessment...
About This Assessment
What is NIS2?
The NIS2 Directive (Directive (EU) 2022/2555) is the EU's updated network and information security directive. It expands the scope of the original NIS Directive, introducing stricter cybersecurity requirements, mandatory incident reporting, and significant penalties for non-compliance. Enforcement begins June 2026.
Who Must Comply?
- • Essential entities: Energy, transport, banking, health, drinking water, digital infrastructure, public administration, space — with 250+ employees or €50M+ revenue
- • Important entities: Postal, waste management, chemical, food, manufacturing, digital providers, research — with 50+ employees or €10M+ revenue
Penalties for Non-Compliance
- Essential entities: Up to €10M or 2% of global annual turnover (whichever is higher)
- Important entities: Up to €7M or 1.4% of global annual turnover (whichever is higher)
- Personal liability: Senior management can be held personally liable for failure to implement security measures
Article 21 Requirements
This assessment covers all 15 mandatory security measures required by NIS2 Article 21, including risk analysis, incident handling, business continuity, supply chain security, and more.
Important Disclaimer
This tool provides a self-assessment for informational purposes only. It does not constitute legal advice or a guarantee of compliance. Organizations should consult with qualified legal and cybersecurity professionals for formal compliance assessments.
100% Private
All calculations happen in your browser. No data is sent to any server until you request a report.
15 Controls
Complete coverage of all NIS2 Article 21 security measures.
PDF Report
Get a detailed compliance report with gap analysis and priority action items.