NIS2 Compliance Checker
Free NIS2 Directive 2022/2555 compliance tool — determine whether your organisation qualifies as an essential entity (Annex I) or important entity (Annex II), assess all 10 Article 21 cybersecurity measures across 55 controls, identify gaps, and export a PDF gap analysis report. No signup. No upload. 100% client-side.
NIS2 Compliance Checker — frequently asked questions
What is NIS2?
NIS2 (Directive 2022/2555) is the EU's updated Network and Information Systems Directive, replacing the original 2016 NIS Directive. It significantly expands the scope of organisations required to implement cybersecurity measures, introduces stricter incident reporting obligations (24-hour early warning, 72-hour notification), and holds management personally liable for compliance failures. Member states were required to transpose NIS2 into national law by 17 October 2024.
Who must comply with NIS2?
Medium and large enterprises in Annex I (essential) or Annex II (important) sectors must comply. Micro and small enterprises (fewer than 50 employees, under €10M turnover) are generally excluded, unless they are a sole provider in their country, operate in specific high-risk sub-sectors, or their member state has expanded scope nationally. Always verify with your national competent authority.
What's the difference between NIS1 and NIS2?
NIS2 replaces the original 2016 NIS Directive and closes many of its gaps. It widens sector coverage (11 essential-entity sectors and 7 important-entity sectors, versus a narrower original list), replaces the old national “operator of essential services” designation process with a simpler size-and-sector self-assessment, harmonises incident reporting deadlines (24 hours, 72 hours, 1 month) across all member states, introduces direct fines comparable to GDPR, and adds explicit personal liability for management bodies who fail to oversee compliance.
Does completing this tool mean my organisation is legally compliant with NIS2?
No. This tool is a self-assessment and gap-analysis aid, not a certification or a legal compliance determination. It gives you a first read on likely scope and highlights gaps against the 10 Article 21 measure categories, but real compliance requires implemented controls with supporting evidence, a formal risk assessment, and — for many organisations — sign-off from qualified security and legal advisors. Always confirm scope and requirements with your national competent authority.
Essential vs Important Entities — what's the difference?
NIS2 distinguishes between Essential Entities (Annex I — energy, transport, banking, health, water, digital infrastructure, ICT service management, space, public administration) and Important Entities (Annex II — postal, waste, chemicals, food, manufacturing, digital providers, research). Essential entities face stricter, proactive supervision and fines up to €10M or 2% of global turnover. Important entities face lighter, reactive supervision and fines up to €7M or 1.4% of global turnover.
Full list of NIS2 sectors (Annex I & II)
Annex I — Essential Entities: Energy (electricity, oil & gas, hydrogen, district heating/cooling), Transport (air, rail, water, road), Banking, Financial market infrastructure, Health, Drinking water, Wastewater, Digital infrastructure (IXPs, DNS, TLD registries, cloud computing, data centres, CDN, trust services, electronic communications), ICT service management (B2B), Space, Public administration (central and regional government).
Annex II — Important Entities: Postal and courier services, Waste management, Manufacture/production/distribution of chemicals, Food production/processing/distribution, Manufacturing (medical devices, computers & electronics, electrical equipment, machinery, motor vehicles, aerospace, other transport equipment), Digital providers (online marketplaces, search engines, social networking platforms), Research organisations.
Am I exempt if my company is micro or small?
Generally yes — NIS2 exempts micro and small enterprises (fewer than 50 employees and under €10M annual turnover, or under €10M balance sheet total) from most obligations. However, NIS2 Article 2(2)–(3) lets certain categories stay in scope regardless of size: sole providers of a service in a member state, entities whose disruption could significantly affect public safety or health, providers of public electronic communications networks above a certain scale, DNS service providers and TLD name registries, trust service providers, and public administration bodies. If any of these could describe you, don't rely on the size exemption alone — verify with your national competent authority.
How accurate is this tool's essential/important determination?
It applies the general NIS2 Article 3 size-and-sector rule as a simplified model: large enterprises in Annex I sectors are treated as essential, medium enterprises in Annex I sectors and qualifying Annex II entities are treated as important, and micro/small enterprises are generally treated as out of scope. It does not account for every national transposition nuance, sector-specific size exemptions (see the question above), or a member state's discretionary designation of specific entities as essential or important. Treat the result as a fast first estimate, not a final determination.
My organisation is outside the EU, or serves EU customers remotely — does NIS2 apply?
NIS2 primarily applies to entities established in an EU member state. However, some non-EU organisations offering services into the EU can still face obligations — for example, DNS providers, cloud services, and certain digital infrastructure providers may need to designate a representative in the EU. If you serve EU customers but aren't established there, seek legal advice on whether NIS2's territorial rules reach your organisation.
What are the 10 Article 21 cybersecurity measures?
- Risk analysis & information security policies
- Incident handling and reporting
- Business continuity & disaster recovery
- Supply chain security
- Security in acquisition, development & maintenance
- Policies to assess cybersecurity effectiveness
- Cyber hygiene practices and training
- Cryptography and encryption policies
- HR security, access control & asset management
- MFA and secure communications
How is my overall compliance score calculated?
Each control you rate is scored: Implemented = 1, Partial = 0.5, Not implemented = 0, and N/A controls are excluded entirely. A measure's score is the average of its applicable (non-N/A) controls. Your overall score is then the average of all 10 measure scores — not a simple count across all 55 controls — so a measure with only a few controls answered still counts equally toward your total alongside a measure with many.
What does marking a control "N/A" (Not Applicable) do to my score?
N/A controls are removed from that measure's score calculation entirely — they neither help nor hurt your percentage. Use N/A sparingly and honestly, only when a control genuinely doesn't apply to your organisation (for example, “BYOD / Mobile Device Policy” if you issue no personal-device access at all). Marking things N/A to avoid a “No” will inflate your score and undermine the point of a gap analysis.
What are the NIS2 incident reporting deadlines?
24 hours — early warning to CSIRT/competent authority. 72 hours — incident notification with severity assessment and indicators of compromise. 1 month — final report with root cause analysis, mitigation and cross-border impact. Failure to report is itself a sanctionable offence.
What's the difference between "High" and "Medium" priority gaps in my results?
High severity gaps are controls you marked “Not implemented” — a complete absence of that control. Medium severity gaps are controls marked “Partial” — something exists but isn't complete or consistently applied. Both need attention, but High gaps represent the larger immediate exposure and are listed first in the Priority Gaps panel.
Does this tool save or upload my answers anywhere?
No. Your assessment autosaves to your own browser's local storage as you work through it — nothing is ever sent to a server. That means you can close the tab and come back later on the same browser and device to resume exactly where you left off. Clear it anytime with the “clear saved progress” link, or use Start Over.
Can I save my progress and come back later?
Yes — this happens automatically. Every time you make a selection or rate a control, your progress is saved locally in your browser. The next time you open this tool on the same device and browser, you'll see a banner offering to resume your saved assessment or start fresh.
Can I export or share my assessment with someone else?
Yes, in several formats from the Results step: Export PDF for a formatted, printable gap-analysis report; Export CSV for the raw control-by-control data in a spreadsheet; Export JSON for a complete assessment file you can re-import later on this or another device, or hand to a colleague to continue or review; and Copy summary for a quick plain-text overview to paste into an email or chat.
How do I filter the 55 controls to see only what's left or only gaps?
On the Controls step, use the filter buttons above the control list: “All 55” shows everything, “Unanswered” shows only controls you haven't rated yet, and “Gaps (Partial/No)” shows only the controls that need attention. The “Jump to next unanswered” button also scrolls straight to the next control you haven't rated.
Why won't my PDF report open?
Some browsers block the pop-up window this tool uses to generate the printable report. If nothing happens when you click Export PDF, allow pop-ups for this site in your browser settings and try again — the tool will show a message if the pop-up was blocked.
What languages does this tool support?
The navigation labels and the top summary line are available in 10 languages via the 🌐 button (English, Dutch, Spanish, Arabic, Indonesian, French, Portuguese, Russian, Japanese, German). The 55 control descriptions, results, and this FAQ remain in English, since accurately translating detailed legal and technical control language needs careful review per language rather than automated translation.
NIS2 & related frameworks (DORA, GDPR, ISO 27001)
NIS2 overlaps with DORA (financial entities' ICT risk management), GDPR (personal data protection), the CER Directive (physical resilience of critical infrastructure), and ISO/IEC 27001. Organisations already certified to ISO 27001 will find significant control overlap with Article 21, but NIS2 adds specific incident-notification timelines, supply chain security requirements, and personal liability for management that ISO 27001 alone doesn't cover.
What happens if my organisation doesn't comply with NIS2?
Consequences vary by member state's transposition law, but generally include administrative fines (up to €10M or 2% of global turnover for essential entities; up to €7M or 1.4% for important entities), binding instructions or compliance orders from your competent authority, and — for essential entities in serious cases — temporary suspension of authorisations or certifications, or temporary suspension of a manager's responsibilities. Management bodies can also face personal liability for failing to approve or oversee compliance measures.
What is a CSIRT?
A Computer Security Incident Response Team. Each EU member state designates one or more national CSIRTs as part of its NIS2 framework. They receive your 24-hour early warning and 72-hour incident notifications, can provide technical guidance during an incident, and coordinate with CSIRTs in other member states on cross-border incidents. Contact your national CSIRT directly for authoritative guidance.
Is this tool affiliated with ENISA, the EU, or any national authority?
No. This is an independent, free tool built by Jasper Bernaers to help organisations run a quick self-assessment. It has no affiliation with ENISA, the European Commission, or any national competent authority, and using it does not fulfil any official registration, designation, or notification obligation under NIS2.
Disclaimer: This tool provides a preliminary indication only and does not constitute legal advice. NIS2 applicability depends on national transposition law which varies by EU member state. Always verify with your national competent authority or qualified legal counsel. Nothing is uploaded — all data stays in your browser.
Related Security Tools
Other free tools by Jasper Bernaers useful for NIS2 Article 21 compliance work: