What Is a NIS2 Gap Assessment?
A NIS2 gap assessment compares your current cybersecurity practices against the ten minimum measures that Article 21(2) of Directive (EU) 2022/2555 requires. It answers one question: where are you today, and what is missing to reach the baseline?
The gap assessment is not an audit. It is a structured self-check — a systematic way to identify blind spots before a regulator, a client, or an incident does it for you.
For small web agencies (3–49 employees), the challenge is usually not unwillingness to comply — it is knowing what to check. The NIS2 directive runs 60+ pages. Article 21 itself lists ten broad areas without a simple checklist. A good gap assessment turns that complexity into 20 concrete yes/no/partial questions.
🎯 10 Measure Areas
Risk analysis, incident handling, business continuity, supply chain security, secure development, effectiveness testing, cyber hygiene, cryptography, access control, and MFA/secure communications.
⚡ Instant Score
Each check scores 0 (missing), 1 (partial), or 2 (documented). Total is shown as a percentage with a grade from A to D, plus a prioritised fix list.
🔒 Stays in Your Browser
Everything runs client-side. No data is sent to any server — not your answers, not your score. You print or save the report yourself.