BLOG · NIS2 TOOLS

Free NIS2 Assessment Tools
& Checklists

A 12-question scope self-assessment, readiness guides and printable incident checklists compared — what each covers, what to do with the result, and where a checklist stops being enough.

Updated August 2026 · Reading time: 6 minutes

Why Start With an Assessment?

NIS2 (Directive (EU) 2022/2555) does not apply to every company — it applies by sector (Annex I essential, Annex II important) and size. Before spending a single hour on security documentation, the first question is simply: is my organisation in scope? Member states have transposed the directive at different speeds and with different national registrations, so a structured screening beats guessing. The good news: the scope criteria are mechanical enough that a short questionnaire can answer them, and the follow-up obligations — risk measures under Article 21, incident reporting within 24h/72h/1 month under Article 23, management accountability under Article 20 — are well documented.

🎯 Step 1: Scope

Sector + size + entity type determines whether NIS2 applies to you directly. Two minutes with a structured questionnaire settles it.

🛡️ Step 2: Gap

If in scope, compare your current practices against the ten minimum risk-measure areas of Article 21. Most gaps are documentable in days, not months.

📋 Step 3: Evidence

Incident response plan, security policy, vendor profile. Regulators and enterprise customers both ask for documents — have them ready.

The Free Tools

All tools below run entirely in your browser or are plain downloads. No account, no email address, nothing you type leaves your machine.

✅ NIS2 Self-Assessment (scope)

12 questions on establishment, sector, size and entity type. Instantly shows whether you fall under Annex I (essential) or Annex II (important), which obligations follow — Art. 21 risk measures, Art. 23 reporting deadlines, Art. 20 management liability — and what to do first. Works for non-EU companies offering services in the EU too.
Open the self-assessment →

📖 NIS2 Readiness Guide (plain language)

A three-question supply-chain test plus a 7-step action plan that takes one afternoon per step: security policy, MFA, backups, vendor profile, contract clauses, scanning, incident plan. Written for agencies with 1–50 employees who have no security team.
Read the guide →

🚨 Incident Report Checklist

NIS2 requires an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. This free checklist walks through exactly what to capture at each stage, so the clock never catches you unprepared.
Get the checklist →

🔗 Supply Chain Security Guide

Article 21(2)(d) makes supplier security a core obligation. This guide explains how in-scope clients will assess their vendors — and the exact questions your own agency should be able to answer before they ask.
Read the guide →

📄 Printable Checklist PDF

A compact offline checklist covering scope screening through evidence documents — print it, work through it, file it as evidence of due diligence.
Download the checklist →

⚖️ GDPR vs NIS2 Overlap

Many organisations must comply with both directives. This comparison maps where they overlap (incident handling, vendor management, documentation) so you can build one process instead of two.
See the overlap →

🇩🇰 Dansk version

Hele denne guide findes også på dansk — gratis NIS2-værktøjer sammenlignet for danske virksomheder.
Læs den danske version →

A Workflow That Takes One Week

(1) Run the 12-question self-assessment. If out of scope, stop — but keep the result; your in-scope clients may still assess you as a supplier. (2) If in scope, read the readiness guide and start the 7-step plan. (3) Set up the incident reporting process early — the 24-hour deadline is the hardest obligation to meet retroactively. (4) Document everything as you go; the paperwork is the compliance evidence. Total effort for a small organisation: roughly one working week spread over a month.

Where a Checklist Stops Being Enough

Self-assessments screen; they do not certify. Three situations call for professional help: your national regulator has formally notified you, you are designated an essential entity subject to audits, or your infrastructure spans multiple member states with conflicting national rules. For everyone else — MSPs, hosting providers, agencies serving enterprise clients — a documented scope decision, a completed Article 21 gap analysis and a rehearsed incident plan put you ahead of most organisations your size.

The assessment also matters in reverse: even if you are below the size threshold, in-scope clients must assess their suppliers under Article 21(2)(d). Being able to hand over a security profile is increasingly part of winning the contract.

Going Deeper

Our NIS2 e-book expands this workflow with fill-in policy templates, five paste-ready contract clauses, a vendor security profile and day-by-day 30-day checklist.

View the NIS2 E-Book →    All Free Compliance Tools →    EAA Accessibility Scanner →

Related Guides