Free self-check
NIS2 self-check: are we in scope?
Answer six questions and see an indicative result: whether NIS2 is likely to apply to you, in which category, and the sensible next step. Your answers stay in your browser.
Indicative result
Public administration is covered
Under NIS2, public administration entities of central government are covered, and many Member States go further. In Bulgaria, for example, administrative bodies are essential entities regardless of size. Obligations follow from the law, without waiting for a letter.
A sensible next step
- Management training — from €1 400, half a day.
- Quick assessment in 10 working days — from €2 900.
- Public-sector programme.
Indicative result
Further checking is needed
NIS2 and national laws cover more than central public administration: depending on the country, public bodies at other levels, judicial bodies, critical entities, educational institutions doing critical research and organisations providing administrative services electronically. Whether and how it applies depends on the specific legal basis and the Member State.
A sensible next step
- Written applicability assessment — from €900.
- Public-sector page.
Indicative result
The result depends on your group data
Size is calculated together with linked and partner enterprises. Without aggregated group data it is not possible to say reliably whether you are in scope and in which category.
A sensible next step
- Written applicability assessment with your group data — from €900.
- Quick assessment if you already know you are in scope — from €2 900.
Indicative result
DORA usually applies to your ICT risk
For financial entities DORA is the specific regime for ICT risk management, incidents, testing and suppliers. We check which regime applies to your particular activity.
A sensible next step
- DORA or NIS2 — which applies.
- DORA readiness and evidence pack — from €7 900.
- Written applicability assessment — from €900.
Indicative result
You are probably covered regardless of size
Some providers are covered at any size, for example trust service providers, top-level domain name registries, DNS service providers and some providers of public electronic communications networks and services. The exact activity needs to be checked.
A sensible next step
- Written applicability assessment — from €900.
- Quick assessment in 10 working days — from €2 900.
Indicative result
You are probably an essential entity
A large enterprise in a highly critical sector (Annex I) is as a rule an essential entity. Management approves the measures and is trained, and significant incidents are reported within 24 and 72 hours.
A sensible next step
- Quick assessment in 10 working days — from €2 900.
- Full readiness and evidence pack — from €7 900.
- Management training — from €1 400.
Indicative result
You are probably an important entity
A medium-sized enterprise in an Annex I sector, or a medium-sized or large enterprise in an Annex II sector, is as a rule an important entity. Measures and reporting are the same as for essential entities; the differences are mainly in supervision and fines.
A sensible next step
- Quick assessment in 10 working days — from €2 900.
- Management training — from €1 400.
- Written applicability assessment if the category is unclear — from €900.
Indicative result
You are probably not directly covered because of your size
Small enterprises are as a rule outside NIS2 unless their activity is one covered regardless of size or the authority identifies them. Your in-scope customers may still require measures from you by contract.
A sensible next step
- Security questionnaire response when a customer asks for evidence — from €1 300.
- Written applicability assessment if you are unsure — from €900.
Indicative result
No basis found in the listed sectors
This is not a conclusion that you are out of scope: the law has other bases, for example being the sole provider of an essential service or an identified critical entity. If you work for organisations that are covered, they must manage supplier risk and may ask you for measures and evidence.
A sensible next step
- Security questionnaire response — from €1 300.
- Requirements for ICT providers.
You are part of a group: size is calculated together with linked and partner enterprises, so the result may differ.
You supply organisations that are covered: they must manage supplier risk and will probably ask you for evidence. See requirements for ICT providers.
The self-check is indicative, not a legal opinion. The category also depends on other circumstances, and authorities identify entities. Your answers are not sent or stored.