Skip to main content
The pilot is open — free for the first cohort. V1 lists on the Microsoft Marketplace Q4 2026.→ Apply
NIS2 overview
Free · Interactive · 5 minutes

NIS2 readiness check.

Two scopes — pick one inside the tool. Supply chain (default · 20 questions, ~5 min) covers governance, supplier risk, incident response, and evidence under a supply-chain emphasis. Full NIS2 (35 questions, ~8-10 min) covers all ten Article 21(2) clauses with dedicated categories for acquisition / development / vulnerability handling, cryptography, and cyber hygiene / access / secure communications. Three-point scale per question, article-anchored gap report at the end.

Honest framing: this is a directional steer, not a substitute for a formal assessment. We'll tell you the same thing in your results. Sister to the supplier-side Supplier readiness check.

Two scopes available: Supply chain (default — twenty questions, supplier-risk emphasis) or Full NIS2 (thirty questions, adds Article 21(2)(e) acquisition / development / vulnerability handling and 21(2)(h) cryptography). Three answers per question. Your inputs stay in your browser; if you'd like an email summary at the end, you opt in then. Everything is anchored to a specific NIS2 article so you can verify the framing.

Scope
Switch between supply-chain emphasis and full Article 21(2) coverage. Your answers persist across both.
Progress
0%
0/20
Category breakdown
Governance & risk management0/5
Supplier risk management0/5
Incident response & continuity0/5
Evidence & audit-readiness0/5
Score so far
0 / 40
Articles touched
Art. 20Art. 21(2)(a)Art. 21(2)(b)Art. 21(2)(c)Art. 21(2)(d)+6
20 remaining to unlock your readiness band and gap report. Use the sidebar to jump between categories.
01/

Governance & risk management

Whether your organisation treats cybersecurity as an operational risk owned at executive level, or a checkbox owned by IT.

0/5 answered0%
Score · 0/10
01

Do you have a documented information security risk management policy approved by the management body?

Article 21(2)(a)
02

Has the management body received cybersecurity training in the last 12 months?

Article 20
03

Is there a defined risk owner for cybersecurity at executive level (named individual, not a department)?

Article 20
04

Are cybersecurity risks reviewed regularly (e.g., quarterly) with the board, with documented minutes?

Article 21(2)(a)
05

Is your risk register linked to specific operational and supplier risks — not just abstract categories like "cyber attack"?

Article 21(2)(a)