Docply Browse kits
Free · No sign-up to start

Where do you actually stand against NIS-2?

Twelve questions, one per obligation — Article 20, the ten Article 21(2) measures, and the Article 23 reporting clock. Answer honestly and you get a score per measure and a list of what to fix first.

One rule makes this useful: answer Yes only where you could produce the evidence in an hour. "We do that" and "we can show that we do that" are different answers, and a supervisory check grades the second.

0 of 12 answered
01 Art. 20 · Governance

Has your management body formally approved the cybersecurity risk-management measures, and is that approval on record with a date and a name?

Article 20 requires approval and oversight — two distinct acts. Members can be held personally liable.

02 Art. 20(2) · Governance

Have the members of the management body completed cybersecurity training, recorded individually?

"The board was briefed" is not evidence. A dated attendance record per member is.

03 Art. 21(2)(a) · Risk analysis

Do you have a documented risk methodology and a current risk register covering all hazards — not only cyber-attacks?

The all-hazards approach covers technical failure, human error, malicious acts and natural events.

04 Art. 21(2)(b) · Incident handling

Is there a written incident-handling procedure with severity levels, and a named person authorised to declare an incident significant?

Teams lose hours of the 24-hour window debating who decides.

05 Art. 23 · Incident reporting

Are the 24-hour, 72-hour and one-month submissions pre-drafted, with your CSIRT contact route already on file?

Missing the deadline is a compliance failure independent of how well you handled the incident.

06 Art. 21(2)(c) · Continuity

Have you tested a full restore — not just a backup job — and measured the time against your recovery objective?

A successful backup proves data was written, not that it can be read back.

07 Art. 21(2)(d) · Supply chain

Do your contracts with critical suppliers contain security requirements in writing, including an incident-notification deadline that fits inside your own 24 hours?

A supplier who notifies you in ten days has already consumed your deadline.

08 Art. 21(2)(e) · Secure operations

Are patch timeframes defined by severity and exposure — and met — with a route for outsiders to report a vulnerability to you?

Vulnerability handling and disclosure are both named in the directive.

09 Art. 21(2)(f) · Effectiveness

Do you measure whether the controls work, and does the management body review the results at least annually with minuted decisions?

The measure most often forgotten, because it has no obvious deliverable.

10 Art. 21(2)(g) · Training

Is security training delivered at planned intervals and role-based, so administrators and developers get more than the baseline — contractors included?

Contractors are the population most often missed, and the first an inspection asks about.

11 Art. 21(2)(h)-(i) · Assets & crypto

Do you have a reconciled asset inventory, an encryption policy covering key management, and access revoked on the day someone leaves?

Reconciled, not merely maintained. And key recovery matters as much as key rotation.

12 Art. 21(2)(j) · MFA

Is multi-factor authentication applied to all remote access and all privileged access, with any exception dated and compensated?

"Legacy" without an expiry date is a permanent exception under a temporary name.