The hardest part of NIS2 is not the ten security measures. It is proving the board approved them. Article 20 puts the management body on the hook personally, and Article 23 gives you 24 hours to file an early warning — both of which are answered long before anyone looks at your firewall rules.

This assessment scores 60 questions across scope, the ten Article 21 measures, the reporting clocks and supervision, so you can see what a competent authority would find. It is free, it saves as you go, and you can stop and come back to it.

What this is

NIS2 is a directive, not a regulation, so the rules that bind you are the ones your member state wrote when it transposed it. The ten risk-management measures in Article 21 and the reporting clocks in Article 23 are the common core every transposition carries, and that is what this scores. We have the background elsewhere — the directive explained, essential versus important entities, the documentation checklist, using an existing ISMS and penalties and deadlines. Come here when you want a score.

What it covers

AreaQuestions
Scope and registration — sector, entity class, size threshold, jurisdiction6
Governance and management liability — Article 205
Risk analysis and security policies — 21(2)(a)4
Incident handling — 21(2)(b)4
Business continuity and crisis management — 21(2)(c)4
Supply chain security — 21(2)(d)4
Secure acquisition, development and maintenance — 21(2)(e)4
Effectiveness of measures — 21(2)(f)3
Cyber hygiene and training — 21(2)(g)3
Cryptography — 21(2)(h)3
HR security, access control and asset management — 21(2)(i)5
Authentication and secured communications — 21(2)(j)4
Incident reporting — Article 237
Supervision and enforcement4

The two things that catch people out

The management body is personally on the hook. Article 20 makes management approve the risk-management measures, oversee their implementation and take training — and it lets member states hold individuals liable for failures. Most organisations score well on the technical measures and badly here, because nobody has minuted the approval or run the board training.

The clocks start at awareness, not at containment. An early warning goes to your CSIRT or competent authority within 24 hours of becoming aware of a significant incident, a full notification within 72 hours, and a final report within a month. If you have not decided in advance who makes the awareness call and who files, the 24 hours is gone before anyone drafts anything.

How the scoring works

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the scope, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records someone could sample
Not applicable—A justified exclusion, removed from the score

NIS2 does not tell you how to implement a measure, only that it must be there and proportionate to your risk. The scale measures whether the measure is in place and whether you could show a supervisor.

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by Article 21 measure, a prioritised gap list, and the documents from the NIS2 Toolkit that close each gap — as a PDF and a working Excel file.

How long does it take?

About 30 minutes. Scope and governance take the longest, because they need someone who knows how your entity was classified and what the board has actually signed.

What to do with your score

Below 40% — settle scope and registration first. Whether you are essential or important changes how you are supervised, and half the remediation argument disappears once that is decided.

40–70% — the usual shape. Technical measures are in place; supply chain, effectiveness review and the reporting mechanics are not.

Above 70% — pressure-test the reporting path. Run a tabletop that produces a real 24-hour early warning, and see whether the draft would survive contact with your CSIRT.

Frequently asked questions

Is this assessment really free?

Yes. All 60 questions, the breakdown by measure and your overall score cost nothing. The $39 report is optional.

Is NIS2 a certification?

No. It is supervised law. Essential entities face proactive supervision; important entities are supervised after the fact. Neither is a certificate, though member states may require audits.

My country transposed it late — does that help?

Not much. The directive applied from 18 October 2024 regardless of transposition status, and late transposition does not reset a national deadline once it arrives. Score against the measures now and adjust for national detail when your law is final.

We already hold ISO 27001. How much carries over?

A lot of the technical and organisational measures, but not the registration, the management-body duties or the incident reporting clocks. Those have no ISO equivalent.

Can I use this for a client?

Yes. Run one assessment per client organisation.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.