BLOG · NIS2 COMPLIANCE

NIS2 Gap Assessment:
A Free 20-Point Readiness Check

Map your current security setup against all ten minimum measures in NIS2 Article 21(2). Get an instant readiness grade and a prioritised list of what to fix — no signup, nothing leaves your browser.

Updated August 2026 · Reading time: 5 minutes

What Is a NIS2 Gap Assessment?

A NIS2 gap assessment compares your current cybersecurity practices against the ten minimum measures that Article 21(2) of Directive (EU) 2022/2555 requires. It answers one question: where are you today, and what is missing to reach the baseline?

The gap assessment is not an audit. It is a structured self-check — a systematic way to identify blind spots before a regulator, a client, or an incident does it for you.

For small web agencies (3–49 employees), the challenge is usually not unwillingness to comply — it is knowing what to check. The NIS2 directive runs 60+ pages. Article 21 itself lists ten broad areas without a simple checklist. A good gap assessment turns that complexity into 20 concrete yes/no/partial questions.

🎯 10 Measure Areas

Risk analysis, incident handling, business continuity, supply chain security, secure development, effectiveness testing, cyber hygiene, cryptography, access control, and MFA/secure communications.

⚡ Instant Score

Each check scores 0 (missing), 1 (partial), or 2 (documented). Total is shown as a percentage with a grade from A to D, plus a prioritised fix list.

🔒 Stays in Your Browser

Everything runs client-side. No data is sent to any server — not your answers, not your score. You print or save the report yourself.

Why Your Agency Needs a Gap Assessment Now

NIS2 enforcement is underway across the EU. Several member states have already started issuing fines — Sweden's first NIS2 penalty reached €900,000. Here is how the gap assessment affects a typical small web agency:

  1. Your clients will ask. If you serve companies with 50+ employees in critical sectors (IT services, digital infrastructure, food processing, healthcare), their NIS2 compliance requires them to audit their supply chain. Your cybersecurity posture becomes a contractual requirement.
  2. You need a baseline to improve. You cannot fix what you have not measured. Running a structured assessment once gives you a score you can improve over time.
  3. Documentation matters. NIS2 does not just ask you to be secure — it asks you to demonstrate that you are secure. A completed gap assessment is evidence that you have evaluated your measures against the directive's requirements.
  4. The bar is lower than you think. Most small agencies already do some of these things (backups, access control, encryption). The gap is usually in formal documentation, incident response planning, and supply-chain security — three areas that are cheap to fix once you know they are missing.
Start the Free Gap Assessment →    Not sure if you are in scope? →

How the Free Assessment Works

The tool walks you through 20 questions, two per Article 21 measure area. You answer each on a three-point scale:

When you finish, you get:

The tool covers all ten areas of Article 21(2), including the ones that are easy to overlook: cryptography policy, supply-chain security requirements in contracts, and secured emergency communications.

Take the Free Assessment →    Also: NIS2 Incident Report Generator →

Understanding Your Readiness Grade

Grade A (90–100%)

Strong readiness. All ten measure areas are addressed in a documented, tested way. Maintain with periodic reviews — enforcement bodies expect this level from essential entities.

Grade B (70–89%)

Reasonable readiness but gaps remain. Documentation is probably informal or incomplete in some areas. Focus on supply-chain security, incident response planning, and formalising existing practices.

Grade C (50–69%)

Significant gaps. Several measure areas are missing entirely. This is the most common profile for small agencies that have not started NIS2 work. Start with the lowest-scoring areas and work up.

Grade D (0–49%)

Critical gaps. Most required measures are not in place. Urgent remediation needed — especially incident handling, access control, and basic cyber hygiene, which are the foundation everything else builds on.

Important: This is a self-check based on the directive text, not a legal opinion. National implementing laws may add specific requirements. Use the result as a starting point, not a certification.

Beyond the Gap Assessment

The free gap assessment gives you a starting point. To move from assessment to compliance, most small agencies need three things: documented policies, incident templates, and contract clauses for clients. That is what the NIS2 Compliance Kit covers.

📋 NIS2 Compliance Kit (E-Book)

Complete 30-day compliance checklist, incident response plan, 5 supply-chain contract clauses, policy templates, and a readiness tracker. For agencies with 3–49 employees.

Available on Amazon →

📝 Incident Report Generator

Free tool that structures your NIS2 Article 23 notification: early warning (24h), formal notification (72h), and final report (1 month). All client-side, no data stored.

Use Free Generator →

🔍 Scope Self-Assessment

Not sure if your agency is actually in scope of NIS2? Take the free 12-question scope checker first. It covers size thresholds, sector classification, and the "important vs essential" distinction.

Check Scope →

Frequently Asked Questions

Is this the same as a formal NIS2 audit?

No. A gap assessment is a self-check. A formal audit is conducted by an independent party and produces a legally defensible result. This tool helps you prepare for an audit by identifying gaps beforehand.

How often should I run it?

At least once per year, and after any significant change in your IT infrastructure, client portfolio, or headcount. Quarterly is better if you are actively working on compliance improvements.

Do I need to keep the results?

Yes. Save a copy of each completed assessment. It demonstrates due diligence if a regulator asks what measures you have evaluated. Use the print/PDF option to archive your results.

What about Danish specific requirements?

Denmark implemented NIS2 through the "Lov om cybersikkerhed" (Act on Cybersecurity), which entered force in July 2025. The ten Article 21 measures are identical at EU level, but the Danish act adds sector-specific registration duties. Check with the Centre for Cybersecurity (CFCS) for Danish specifics.

What is the difference between this and the scope check?

The scope check (/nis2-check) tells you whether your company is in scope of NIS2 at all — it covers size thresholds, sector classification, and exemptions. The gap assessment assumes you are in scope and checks your actual security measures against Article 21.

Take the Free Assessment →

Related Guides

Dansk version af denne guide