Scope My NIS2 Assessment

Free Self-Assessment

NIS2 & CRA Readiness Check

12 questions mapped to NIS2 Article 21 risk-management measures and CRA vulnerability-handling requirements. Answer honestly — you'll see your result immediately, no form required.

01 / Risk management

Do you have a documented risk-analysis and information-security policy that's reviewed at least annually?

02 / Incident handling

Do you have a formal incident-response plan with a defined escalation path and a process for meeting regulator notification timelines?

03 / Incident handling

Has that plan been tested with a tabletop exercise or simulated incident in the last 12 months?

04 / Business continuity

Do you have a documented business-continuity and disaster-recovery plan for your critical systems?

05 / Supply-chain security

Do you assess the security posture of key suppliers and third-party vendors before onboarding them?

06 / Access control

Is multi-factor authentication enforced for all privileged and remote-access accounts?

07 / Vulnerability handling

Do you have a defined process for handling and disclosing vulnerabilities found in your own products or systems?

08 / Secure-by-design

Do you maintain a software bill of materials (SBOM), or an equivalent inventory of third-party components in your products?

09 / Security testing

Has an external party — not your own team — performed a penetration test or security assessment on your critical systems in the last 12 months?

10 / Audit readiness

Could you hand an auditor documented evidence today — not just policy — that these controls are actually in place?

11 / Scope awareness

Do you know whether your organization qualifies as an "essential" or "important" entity under NIS2, and which specific obligations apply to you?

12 / Response capability

If a critical vulnerability were found in a customer-facing system tomorrow, could your team ship a fix and notify affected parties within 72 hours?