NIS2 readiness assessment for SMEs and suppliers
Fifteen questions on the measures NIS2 requires, each based on an article of the Directive. Useful whether NIS2 applies to you or your customers pass it on to you as a supplier.
How many people work for your company?
Count employees on employment contracts. Some obligations depend on company size.
About the assessment
NIS2 (Directive (EU) 2022/2555) requires companies in the covered sectors to have management approve and oversee cybersecurity, to take at least ten minimum measures — from risk analysis and incident handling to backups, supplier security, access control and multi-factor authentication — and to report significant incidents within 24 hours. This free assessment checks your company against those measures in fifteen questions.
What does NIS2 require from companies?
Four areas and fifteen questions, built on Articles 20, 21 and 23 of the Directive. This is the full content of the assessment.
Governance and risk
Whether management owns cybersecurity and decisions rest on an analysis of your risks.
- Our management has approved our cybersecurity measures and oversees how they are put in place.
- Members of our management have completed cybersecurity training.
- We have a written information security policy based on an analysis of our risks.
- We regularly check whether our security measures actually work, for example with a review or a test.
Incidents and continuity
What happens when something goes wrong, and how quickly you can recover.
- We have a written procedure for handling security incidents, and people know whom to contact.
- We know how we would send an early warning to the CSIRT or authority within 24 hours of becoming aware of a significant incident.
- We back up critical data and have tested restoring it.
- We have a plan for keeping the business running and managing a crisis if key systems fail.
People, access and assets
Who can access what, what devices you have, and whether people know the basics.
- Employees regularly get basic cybersecurity training: passwords, phishing, updates.
- Access rights match each person's job and are removed on the day someone leaves.
- We keep an up-to-date list of our IT assets: devices, systems, software and who has them.
- Multi-factor authentication is switched on for email, remote access and our key systems.
Suppliers and technology
How you handle suppliers with access, updates and encryption.
- We know which suppliers can access our systems or data, and we have agreed security requirements with them.
- We install security updates on a set schedule and follow known vulnerabilities in the systems we use.
- We have rules for when data must be encrypted, for example on laptops and when sent outside the company.
How is the score calculated?
The average of all scored questions; each carries the same weight. Every answer carries a compliance percentage and the score is their average. The band drops to the lowest one if too many answers are “We don't have it”.
- We don't have it
- 0 %
- Informally
- 40 %
- On paper
- 70 %
- Works, with evidence
- 100 %
The assessment has 15 scored questions and 2 questions about your company that do not count towards the score. The full method, including how the company type is derived and what is stored, is described in the assessment methodology.
Frequently asked questions
NIS2 applies to companies in the sectors listed in its Annexes I and II — such as energy, transport, banking, health, digital infrastructure, postal services, waste, food, chemicals and some manufacturing — that are medium-sized or larger (Article 2). That generally means 50 or more employees, or annual turnover and balance sheet both above €10 million under the EU SME definition. Some entities are covered regardless of size. Your national law and authority decide the details.
Often, yes, even if the law does not apply to you directly. Article 21(2)(d) requires covered companies to manage supply chain security, including their relationships with direct suppliers and service providers, and Article 21(3) asks them to consider each supplier's security practices. In practice your customers will ask you the same questions this assessment asks.
Risk analysis and security policies; incident handling; business continuity, backups and crisis management; supply chain security; security in acquisition, development and maintenance, including vulnerability handling; assessing whether the measures work; basic cyber hygiene and training; cryptography and encryption; human resources security, access control and asset management; and multi-factor authentication and secured communications.
For a significant incident, Article 23 requires an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours and a final report no later than one month after the notification. Reports go to your national CSIRT or competent authority.
Under Article 34, national law must allow fines of at least up to €10 million or 2 % of worldwide annual turnover for essential entities, and at least up to €7 million or 1.4 % for important entities, whichever is higher. Management bodies can also be held liable (Article 20).
It is free, with no sign-up, and you see the full result straight away. It is a self-assessment against the text of the Directive, not legal advice, and it does not check your national law. National laws had to be in place by 17 October 2024; several countries were late.
Sources
Aptiness editorial team · built from the official texts cited belowContent reviewed September 2026Assessment methodology