NIS2 is already enforceable — national deadlines run through October 2026

Is your company inside the scope of NIS2? Find out in 15 minutes.

Find out in minutes whether the EU's NIS2 cybersecurity law applies to you — and exactly what's missing to comply.

NIS2Ready is a self-service gap-analysis for the EU's cybersecurity directive. Answer a short, structured questionnaire about your sector, size and current measures, see your likely classification instantly, and get a full prioritised report — plus a NIS2Ready readiness certificate — by email. No audit-firm retainer, no sales call.

Covers all 27 EU member states · Built on Articles 20/21 & Annex I/II · Results in minutes, report by email

Two cybersecurity professionals reviewing security dashboards on screens in a monitoring room
classificationImportant entity
Art.21 · incident responseMissing
Art.21 · MFA admin accessPartial
Preparedness score: 42% · full report + readiness certificate by email

02 · What's actually at stake

This isn't a distant EU regulation. It reaches your board personally.

NIS2 (Directive (EU) 2022/2555) replaced the original NIS Directive with a much wider scope, tougher penalties, and — for the first time — direct personal accountability for management.

Up to €10,000,000 or 2%

Essential entities

Member states must set fines for essential entities at a maximum of at least €10 million or 2% of total worldwide annual turnover — whichever figure is higher.

Source: NIS2directive.eu, NIS2 fines & consequences

Up to €7,000,000 or 1.4%

Important entities

Important entities face a lower but still substantial ceiling: up to €7 million or 1.4% of total worldwide annual turnover, whichever is higher.

Source: NIS2directive.eu, NIS2 fines & consequences

Personal liability

Article 20 — it's on your board now

Management bodies must approve and oversee cybersecurity risk-management measures and can be held liable for infringements. National laws can add personal sanctions for directors, including temporary bans from management functions.

Source: DLA Piper, Directors' personal liability under NIS2

Around 160,000 entities across the EU fall inside NIS2's scope — yet only 16% of leaders at in-scope companies feel fully prepared, and 11% still aren't sure NIS2 applies to them at all.

See exactly where you stand

Source: CyberSmart survey of 670 in-scope business leaders across eight countries, April 2026, as reported by Passwork, NIS2 latest news.

03 · Who has to comply

18 sectors, two tiers, two size thresholds — in plain language

NIS2 splits in-scope sectors into two annexes and two entity tiers. Most companies assume "critical infrastructure" means someone else. It usually doesn't.

A management team reviewing documents together in a meeting room
Annex I · high criticality

11 sectors — typically Essential if large

  • Energy (electricity, oil, gas, hydrogen)
  • Transport (air, rail, water, road)
  • Banking & financial market infrastructure
  • Health (providers, EU reference labs, pharma R&D)
  • Drinking water & waste water
  • Digital infrastructure (cloud, data centres, DNS, CDN, trust services, telecoms)
  • ICT service management (managed service & security providers)
  • Public administration & space
Annex II · other critical

7 sectors — typically Important

  • Postal & courier services
  • Waste management
  • Manufacture, production & distribution of chemicals
  • Production, processing & distribution of food
  • Manufacturing (medical devices, electronics, machinery, motor vehicles)
  • Digital providers (online marketplaces, search engines, social networks)
  • Research organisations

Do you meet the size threshold?

Medium50+ staff, or over €10M annual turnover — usually in scope in a listed sector
Large250+ staff, or over €50M annual turnover — usually classed Essential in Annex I sectors
Any sizeDNS providers, TLD registries, trust service providers & public electronic-communications providers are in scope regardless of size

Even below the threshold, if you supply critical digital services, software or hardware to a company that is in scope, you may face NIS2-derived security requirements through your customer contract. Sources: Glocert, NIS2 applicability guide and European Commission, NIS2 transposition tracker.

04 · How it works

Three steps. No sales call required.

From "no idea if this even applies to us" to a prioritised action plan, in about the time it takes to read this page.

Answer 17 quick questions

Sector, country, size, turnover, supply-chain exposure, and where your current security measures stand — from policy and MFA to encryption, backups and incident reporting. About 6 minutes, entirely in your browser.

Get your classification instantly

Our rule engine applies NIS2's own Annex I/II and Article 21 logic and shows you: essential, important, in scope through your supply chain, or out of scope — plus a preparedness score.

Request the full report by email

A structured PDF with your classification, every gap mapped to the specific Article 21 measure it relates to, and a priority order to close them — delivered automatically, no consultant call needed.

Included with every paid report

Your NIS2Ready readiness certificate

Proof you took NIS2 seriously — dated, branded, and shareable

When you complete a paid diagnostic, we issue an official NIS2Ready-branded readiness certificate. It attests that your company carried out a NIS2 preparedness audit with us on a given date, together with the classification and preparedness score reached.

  • A dated certificate under our own NIS2Ready brand, with a unique reference
  • Useful evidence of due diligence for your board, a customer or an insurer
  • Shows the classification, preparedness score and scope of the assessment

Our certificate is a private-brand attestation of the audit you completed with us. NIS2Ready is not an accredited certification body or public authority, so it does not replace an official conformity assessment or legal advice — see the full note below.

A hand holding a brass padlock, representing verified cybersecurity readiness

05 · Pricing

Clear prices. Clear limits. No "contact sales."

Pick a one-off report to see where you stand, or add a quarterly recheck so a new subsidiary or a missed patch doesn't quietly reopen the risk.

Essential Report

€79 one-off

Limit: 1 legal entity, 1 country

  • Full classification (essential / important / out of scope)
  • Gap list mapped to Article 21 risk-management measures
  • PDF delivered by email the same business day
  • No country-specific transposition notes, no supply-chain template
Start with Essential
Most requested

Full Report

€129 one-off

Limit: up to 3 EU countries, 1 legal entity

  • Everything in Essential Report
  • Country-specific transposition notes for up to 3 EU jurisdictions
  • Supply-chain questionnaire template to send to your own vendors
  • Management-body briefing summary for Article 20 evidence
Get the full report

Quarterly Recheck

€49 / month

Requires a completed report first

  • Re-run the diagnostic every quarter, same entity
  • Updated PDF only if your score or the regulation changed
  • Tracks your readiness trend over time
  • Cancel anytime, no minimum term
Add quarterly recheck

NIS2Ready is a fit if…

  • You're not sure whether NIS2 applies to your company or a subsidiary
  • You need a first structured gap-analysis before briefing your board or hiring a specialist
  • You want evidence of due diligence — for Article 20, for a customer, for an insurer
  • You'd rather pay a fixed, transparent fee than an hourly GRC-consultancy retainer

…and not a fit if

  • You need an accredited certification or a statutory conformity assessment (we are not a certification body — see FAQ)
  • You're a large group needing continuous, integrated GRC tooling across dozens of subsidiaries
  • You want someone else to implement technical controls without any internal IT or security involvement
  • You're looking for formal legal advice on a specific enforcement case

Why this price? Because the classification logic and the Article 21 gap-mapping are a rules engine, not billable consulting hours — we're not charging you for a partner's day rate on a first pass. Enterprise GRC and compliance-automation platforms commonly list from roughly €7,000 to well over €100,000 per year and are built for organisations that already have an integration budget. NIS2Ready answers the question most companies actually have first — "are we in scope, and what's missing?" — in minutes, for a fixed €79–€129, which is why the Quarterly Recheck at €49/month exists as the lightweight way to keep that answer current instead of re-buying a full report every time.

06 · The maths

What staying unprepared could cost, versus getting ahead of it

These are the regulatory ceilings set by the directive itself, not a worst-case scare number — see the risk section above for sources.

🔴 Cost of staying unprepared

Essential entity fine ceilingup to €10M or 2%
Important entity fine ceilingup to €7M or 1.4%
Personal liability exposure for directorsup to a management ban
Typical enterprise GRC platform, per year€7,000–€100,000+

Fine figures: NIS2directive.eu. Liability: DLA Piper.

🟢 Cost of getting ahead of it

NIS2Ready Full Report€129 one-off
12 months of Quarterly Recheck€49 × 4 = €196
Your total first-year cost≈ €325
Share of the essential-entity fine ceiling≈ 0.003%

Calculation: €325 ÷ €10,000,000 maximum essential-entity fine. Your own exposure depends on your classification and turnover.

Even if you're never investigated, the diagnostic pays for itself the first time it stops you signing a customer contract you can't fulfil, or flags a missing MFA policy before a regulator or an auditor does.

Run the numbers for your company

07 · Free self-diagnostic

Your NIS2 gap-analysis, right here, right now

17 questions across scope and security controls. Nothing is sent anywhere until you choose to request your report. This is a structured first-pass assessment, not a substitute for a full audit.

NIS2 scope & readiness diagnostic

Runs entirely in your browser. Answer all 17 questions to see your result.

01Which sector best describes your company?
02Country of your main EU establishment
03How many staff does your company have?
04What's your annual turnover?
05Are you a DNS provider, TLD registry, trust service provider, or public electronic-communications provider?
06Do you supply critical digital services, software or hardware to a company that is itself in scope of NIS2?
07Do you have a written, board-approved cybersecurity risk-management policy?
08Do you have a documented, tested incident-response plan (detection, handling, escalation)?
09Do you run regular backups and a tested business-continuity / disaster-recovery plan?
10Do you enforce multi-factor authentication for remote and admin access?
11Do you encrypt sensitive data in transit and at rest (TLS, disk/database encryption)?
12Do you apply access control and least-privilege (role-based access, prompt de-provisioning)?
13Do you have vulnerability handling and patch management (timely updates, disclosure process)?
14Do you keep an asset inventory and basic network security (segmentation, firewalls, monitoring)?
15Do you have a supply-chain security policy covering your own vendors and critical providers?
16Has your management body received cybersecurity risk training in the last 12 months?
17Do you have a process to report significant incidents to your national CSIRT within 24h / 72h?

What your NIS2Ready certificate means

NIS2Ready is a cybersecurity readiness-audit tool. When you complete a paid diagnostic, we issue a NIS2Ready-branded readiness certificate confirming that your company carried out — and paid for — a NIS2 preparedness audit with us on a specific date, along with the classification and preparedness score you reached. It's a genuine, dated attestation you can share with your board, a customer or an insurer.

To be clear and fair: our certificate is a private-brand attestation, not an official accreditation. NIS2Ready is not an accredited certification body, notified body or public authority, so it does not replace a statutory audit, an official conformity assessment, or advice from a qualified lawyer in your jurisdiction. We are not responsible for misuse of the certificate or the platform, for a customer's failure to act on the recommendations, or for infringements caused by third parties. For essential entities or complex multi-country groups, use your report and certificate as the starting brief for a deeper review.

09 · Questions

Frequently asked questions

Is NIS2Ready an official EU certification body?

No. NIS2Ready is not an accredited certification body, notified body or public authority, and we do not perform statutory audits. We provide a self-assessment tool and supporting documentation that helps you understand your likely NIS2 status and gaps. It does not replace an official audit, a conformity assessment, or advice from a qualified lawyer in your jurisdiction.

Does NIS2 really apply to my company?

It depends on your sector and size. NIS2 covers 18 sectors split into Annex I ("high criticality": energy, transport, banking, health, digital infrastructure, public administration, and more) and Annex II ("other critical": food, chemicals, manufacturing, digital providers, postal services, and more). In general, medium enterprises (50+ staff or over €10M turnover) and large enterprises (250+ staff or over €50M turnover) in these sectors are in scope, regardless of whether you feel like a "critical infrastructure" company. Some entities — DNS providers, TLD registries, trust service providers, public electronic-communications providers — are in scope regardless of size. Our diagnostic applies these rules to your specific situation in about 5 minutes.

What happens if we do nothing?

Two separate risks. First, financial penalties: essential entities face fines of up to €10,000,000 or 2% of total worldwide annual turnover, whichever is higher; important entities face up to €7,000,000 or 1.4%. Second, and often overlooked, Article 20 of the directive makes your management body personally responsible for approving and overseeing cybersecurity risk-management measures — national laws can impose personal sanctions on directors, including temporary bans from management roles, for serious or repeated non-compliance.

My country hasn't finished transposing NIS2 into national law yet — can I wait?

We would not recommend it. Several member states, including Germany and Poland, already have national NIS2 laws in force. Others, including Spain and France, were still finalising their transposition as of mid-2026, after the European Commission sent reasoned opinions to 19 member states in May 2025 for missing the original deadline. Once your national law enters into force it typically applies to your existing security posture, not to a project plan you haven't started — starting your gap-analysis now avoids a scramble later.

How is this different from hiring a GRC consultancy or a platform like Vanta or Drata?

Enterprise GRC and compliance-automation platforms are built for large organisations with integration budgets and commonly list from roughly €7,000 to well over €100,000 per year. NIS2Ready is a self-service rules engine: you answer structured questions about your sector, size and current measures, and our engine — built directly on NIS2's Annex I/II classification rules and Article 21 risk-management measures — returns your likely classification and a prioritised gap list in minutes, from €79 one-off. It is a first-pass diagnostic, not an enterprise platform replacement.

Do you fix the gaps for us?

No. Your report gives you a prioritised, plain-language list of what NIS2's Article 21 measures require and where your current setup falls short, so your own IT team, CISO or an external specialist can act on it directly. We are not a certifying or auditing body and we do not implement technical controls on your systems.

How accurate is a self-assessment questionnaire?

It is a structured first-pass gap-analysis built on NIS2's own classification rules (sector, size, special-case entities) and the risk-management measure categories in Article 21. It is reliable for figuring out whether you are likely in scope and which broad areas need attention. It is not a substitute for a full technical audit, a legal opinion, or a certified conformity assessment — for essential entities or complex multi-country groups, use your report as the starting brief for that deeper review, not as its replacement.

Stop guessing whether NIS2 applies to you

A short questionnaire, a few minutes, and a report — plus a readiness certificate — you can actually hand to your board.

Start my free diagnostic