Why Start With an Assessment?
NIS2 (Directive (EU) 2022/2555) does not apply to every company — it applies by sector (Annex I essential, Annex II important) and size. Before spending a single hour on security documentation, the first question is simply: is my organisation in scope? Member states have transposed the directive at different speeds and with different national registrations, so a structured screening beats guessing. The good news: the scope criteria are mechanical enough that a short questionnaire can answer them, and the follow-up obligations — risk measures under Article 21, incident reporting within 24h/72h/1 month under Article 23, management accountability under Article 20 — are well documented.
🎯 Step 1: Scope
Sector + size + entity type determines whether NIS2 applies to you directly. Two minutes with a structured questionnaire settles it.
🛡️ Step 2: Gap
If in scope, compare your current practices against the ten minimum risk-measure areas of Article 21. Most gaps are documentable in days, not months.
📋 Step 3: Evidence
Incident response plan, security policy, vendor profile. Regulators and enterprise customers both ask for documents — have them ready.