Free check

NIS2 Readiness Check

26 questions based on Section 30(2) BSIG — get a sense of where your company stands on NIS2 security requirements in about 5 minutes. Free, no signup, no email required.

An orientation aid based on Sections 30, 32, 33 and 38 BSIG (as amended by the German NIS2 implementation act), not legal advice. Check whether your company falls within scope using the BSI scope self-assessment.

Registration duty: within three months of first qualifying as an affected entity (Section 33 BSIG). For entities already in scope when the act took effect on 6 December 2025, the deadline expired on 6 March 2026.

Received a questionnaire from a regulated client? How to answer it.

Category 1 of 60 of 26 answered

Risk Management, Security Concepts & Management Duties

1. Do you have a documented risk analysis covering your most important IT systems and processes?

2. Is there a written information security policy that is reviewed and updated regularly?

3. Are responsibilities for information security clearly assigned — and does top management itself implement the risk management measures and oversee their implementation (Section 38(1) BSIG)?

4. Are identified risks prioritized and tied to concrete mitigation measures?

5. Does top management regularly attend training so it can assess information security risks and risk management practices (Section 38(3) BSIG)?