This assessment evaluates your organisation's readiness against the EU NIS2 Directive (2022/2555) — the updated cybersecurity framework covering essential and important entities across energy, transport, health, digital infrastructure, and many other sectors. You'll be asked which sector your organisation falls under, and its approximate size, first — this tailors the guidance you receive on your likely Essential vs Important entity classification and the supervisory regime that applies. It does not hide any questions — every organisation answers the same 56 questions. 56 questions across 14 areas, covering risk management, incident handling and reporting obligations, business continuity, supply chain security, and more. You can save progress at any time and return later.
56 questions across 14 themes.
This tailors the guidance you receive on your likely Essential vs Important entity classification. It does not hide any questions — every organisation answers the same 56 questions.
NIS2's own Essential/Important entity thresholds are staff-count and turnover based. This combines with your sector to give a readiness indication only — it is not a legal determination of your actual classification.