Where you stand on NIS2. Fifty questions across the ten measures of Article 21(2), and a report that says which three to take first.

  • Ten screens, five questions each. About ten minutes.
  • Your answers are saved in the browser — stop and come back whenever.
  • The report arrives by email, which we ask for only at the end.

This is a self-assessment of maturity against Article 21(2) of NIS2, not a determination of compliance.

1 of 10

Risk analysis

  1. 1. Is there a written policy for the security of your networks and information systems, approved by management?

  2. 2. Do you carry out a regular risk assessment covering every significant system and process?

  3. 3. Do you keep a risk register in which every risk has an owner and a date?

  4. 4. Does management explicitly approve which risks are accepted and which are treated?

  5. 5. Is the assessment revisited on a material change — a new system, a new supplier, a reorganisation?

0 of 5 answered

Your answers are saved in this browser as you go.