Logging and monitoring
Planning and operating continuous monitoring and logging of security-relevant events — with defined retention.
15 questions, five minutes, instant result — no registration, no email required.
NIS2 does not ask for paperwork, it asks for security that demonstrably works. In practice, implementation falls into four action areas: governance and reporting, logging and detection, vulnerability and patch management, and incident response. The self-check scores exactly those four.
Your answers stay in your browser. We store nothing and set no cookie for it.
Critical gaps — Core NIS2 requirements are open. Priority is logging, detection and a workable reporting process.
In preparation — First building blocks exist, but continuous operations, evidence and exercised processes are missing.
Largely solid — Most requirements are met — coverage, evidence and exercises remain open.
Well positioned — High level of implementation. The leverage is in evidence, automation and continuous validation.
The score is passed into the contact form as text — you can edit or delete it before sending.
What NIS2 requires — and which building block covers it.
Planning and operating continuous monitoring and logging of security-relevant events — with defined retention.
Detection, analysis, response and documentation of security incidents across the corporate network on one platform.
Integrating TI feeds to continuously use current data on cyber threats, vulnerabilities and attack techniques.
EDR for fast detection and response on endpoints — including operations, containment and audit trails.
Recurring scans to identify potential security gaps across systems and networks.
Processes to assess and prioritise vulnerabilities and to meet the agreed remediation window per criticality.
Testing system security and uncovering weaknesses that regular scans do not surface.
Effective patch management to remediate known vulnerabilities quickly and verifiably.
Continuous analysis and handling of security incidents within an appropriate timeframe by a skilled analyst team.
Building an incident response plan plus setting up and training a response team (internal, external or as a service).
Automation for detection and response — automation supports, the human analyst decides.
A clear process to detect and report incidents within 24 to 72 hours.
Clarify applicability, assign accountability at management level, define the 24h / 72h / 1 month reporting process and assess your supply chain.
Strengthen evidence: exercise the reporting process, tighten supplier contracts and plan recurring training.
Build central logging and an operated SIEM, put EDR into operations and connect threat intelligence.
Measure detection coverage against MITRE ATT&CK, cut false positives and extend use cases.
Establish regular scans, define criticality and remediation deadlines and operate patch management verifiably.
Sharpen remediation SLAs and reporting, schedule penetration tests with retesting.
Write an incident response plan, name a response team and secure forensic capacity with response times.
Exercise response: tabletop drills, containment automation and regular compromise assessments.
Scope, obligations and reporting deadlines.