NetOpsKit

NIS2 Readiness Self-Assessment

30 questions across the ten Article 21 security measures with a score, a gap list and an action plan you can print.

A. Risk analysis & information security policies (Art. 21(2)(a))

Do you have a documented, management-approved information security policy that is reviewed at least annually?

Do you carry out and document a cybersecurity risk assessment at least annually and after major changes?

Does senior management approve cyber risk decisions and review cyber risk at least yearly?

B. Incident handling (Art. 21(2)(b))

Do you have a documented incident response plan with roles, escalation paths and contact lists?

Can you detect incidents (central logging, monitoring, alerting) and keep logs long enough to investigate?

Do you have a process to decide whether an incident is significant and to report it within 24 hours / 72 hours / one month?

C. Business continuity, backup & crisis management (Art. 21(2)(c))

Are critical systems backed up with at least one offline or immutable copy?

Have you defined recovery time/point objectives (RTO/RPO) and a continuity / disaster recovery plan for critical services?

Have you tested restores and the crisis plan in the last 12 months?

D. Supply chain security (Art. 21(2)(d))

Do you keep a list of critical suppliers and service providers (MSPs, cloud, software, connectivity)?

Do contracts with critical suppliers include security requirements and incident notification duties?

Do you assess suppliers' security before onboarding and periodically afterwards?

E. Secure acquisition, development, maintenance & vulnerability handling (Art. 21(2)(e))

Is there a patch management process with defined timelines (for example critical fixes within days)?

Do you scan for vulnerabilities regularly and track remediation to closure?

Are security requirements part of procurement and change management (and secure development if you build software)?

F. Assessing effectiveness of measures (Art. 21(2)(f))

Do you run internal audits or independent assessments (for example penetration tests) at least annually?

Do you track security metrics (patch latency, MFA coverage, restore success rate) and report them to management?

Are audit and test findings tracked to closure with owners and due dates?

G. Cyber hygiene & training (Art. 21(2)(g))

Do all staff receive security awareness training at least annually, including phishing?

Do management body members receive cybersecurity training?

Are baseline hygiene controls in place (endpoint protection, secure configuration, email filtering, no default passwords)?

H. Cryptography & encryption (Art. 21(2)(h))

Do you have a cryptography policy covering approved algorithms and key management?

Is data encrypted in transit (TLS) and are laptops, mobiles and servers holding sensitive data encrypted at rest?

Are keys and certificates inventoried, protected and renewed before they expire?

I. HR security, access control & asset management (Art. 21(2)(i))

Do you have joiner / mover / leaver processes that grant and revoke access promptly?

Is access least-privilege, with periodic access reviews and separate administrator accounts?

Do you maintain an asset inventory (hardware, software, data) with owners?

J. MFA & secured communications (Art. 21(2)(j))

Is multi-factor authentication enforced for remote access, administrator accounts and email/cloud services?

Do you use secured voice/video/text communications and have an out-of-band emergency channel for incidents?

Is the network segmented and are admin interfaces kept off the public internet?

How to use this tool

Answer each question with Yes, Partially or No. You get an overall readiness score, a score for each of the ten Article 21(2) measures, and a prioritised list of gaps with concrete actions. Your answers are saved only in your browser. Print the result to PDF for your records, or send the gap list to the AI remediation planner to turn it into a 90-day plan. This is a self-assessment to structure your work, not an audit or a certification.

Worked example

A company with MFA on VPN but no tested restores and no incident reporting procedure would score well on authentication (j) but low on business continuity (c) and incident handling (b), and the gap list would put "test restores" and "define 24h/72h reporting" at the top.

Frequently asked questions

What are the ten NIS2 Article 21 measures?

Risk analysis and information system security policies; incident handling; business continuity, backup and crisis management; supply chain security; security in acquisition, development and maintenance including vulnerability handling; policies to assess the effectiveness of measures; basic cyber hygiene and training; cryptography and encryption; human resources security, access control and asset management; multi-factor or continuous authentication and secured communications.

Do I need ISO 27001 certification for NIS2?

NIS2 does not itself require ISO 27001. A recognised framework such as ISO 27001 is a common way to structure and evidence the Article 21 measures, but your national law and authority decide what they expect.

Who is responsible for NIS2 compliance in a company?

Article 20 requires the management body to approve the cybersecurity risk-management measures, oversee their implementation and undergo training, and it can be held accountable for infringements. Delegating the work to IT does not remove that responsibility.

Is my data sent anywhere?

No. Answers are processed and stored locally in your browser unless you choose to send the gap list to the AI planner.

Stuck on something this page doesn't cover?

Tell us the problem in your own words. We use these reports (anonymously) to decide which guides to write. No account, name or email needed. Do not include passwords or customer data.