Where you stand on NIS2. Fifty questions across the ten measures of Article 21(2), and a report that says which three to take first.
- Ten screens, five questions each. About ten minutes.
- Your answers are saved in the browser — stop and come back whenever.
- The report arrives by email, which we ask for only at the end.
This is a self-assessment of maturity against Article 21(2) of NIS2, not a determination of compliance.
1 of 10
Risk analysis
1. Is there a written policy for the security of your networks and information systems, approved by management?
2. Do you carry out a regular risk assessment covering every significant system and process?
3. Do you keep a risk register in which every risk has an owner and a date?
4. Does management explicitly approve which risks are accepted and which are treated?
5. Is the assessment revisited on a material change — a new system, a new supplier, a reorganisation?
0 of 5 answered
Your answers are saved in this browser as you go.