NIS2 in four action areas

NIS2 does not ask for paperwork, it asks for security that demonstrably works. In practice, implementation falls into four action areas: governance and reporting, logging and detection, vulnerability and patch management, and incident response. The self-check scores exactly those four.

Your answers stay in your browser. We store nothing and set no cookie for it.

NIS2 self-assessment in 5 minutes

Question 1 of 15Do you know whether NIS2 applies to your organisation (sector, size, supply chain)?
Question 2 of 15Is accountability for cyber security formally assigned at management level?
Question 3 of 15Are management and staff trained on cyber risks on a recurring basis?
Question 4 of 15Are supply chain and supplier risks assessed and contractually addressed?
Question 5 of 15Are security-relevant events logged consistently and retained?
Question 6 of 15Do you operate a SIEM for detection, analysis and incident documentation?
Question 7 of 15Do you use threat intelligence feeds for current threat data?
Question 8 of 15Is an EDR solution deployed and actually operated on endpoints?
Question 9 of 15Do you run regular vulnerability scans across systems and networks?
Question 10 of 15Is there a process to assess and prioritise identified vulnerabilities?
Question 11 of 15Is patch management operated effectively and evidenced?
Question 12 of 15Do you run penetration tests to find gaps that scans miss?
Question 13 of 15Do you have a documented and exercised incident response plan?
Question 14 of 15Is an incident response team available (internal, external or as a service)?
Question 15 of 15Can you report incidents within the NIS2 deadlines (24h / 72h / 1 month)?

Requirements and matching building blocks

What NIS2 requires — and which building block covers it.

Logging and monitoring

Planning and operating continuous monitoring and logging of security-relevant events — with defined retention.

SIEM (monitoring)

SIEM platform

Detection, analysis, response and documentation of security incidents across the corporate network on one platform.

CyStrat SOC Suite

Threat intelligence

Integrating TI feeds to continuously use current data on cyber threats, vulnerabilities and attack techniques.

Threat intelligence

Endpoint detection and response

EDR for fast detection and response on endpoints — including operations, containment and audit trails.

EDR operations & response

Regular vulnerability scans

Recurring scans to identify potential security gaps across systems and networks.

Vulnerability management

Assessment and prioritisation

Processes to assess and prioritise vulnerabilities and to meet the agreed remediation window per criticality.

Vulnerability management

Penetration testing

Testing system security and uncovering weaknesses that regular scans do not surface.

Red teaming & pentest

Patch management

Effective patch management to remediate known vulnerabilities quickly and verifiably.

Consulting

Cyber security analysis

Continuous analysis and handling of security incidents within an appropriate timeframe by a skilled analyst team.

Managed SOC

Incident response

Building an incident response plan plus setting up and training a response team (internal, external or as a service).

Incident response

SOAR automation

Automation for detection and response — automation supports, the human analyst decides.

SOAR

Reporting obligations

A clear process to detect and report incidents within 24 to 72 hours.

Incident response

Recommended next steps

Governance & reporting

Clarify applicability, assign accountability at management level, define the 24h / 72h / 1 month reporting process and assess your supply chain.

Strengthen evidence: exercise the reporting process, tighten supplier contracts and plan recurring training.

Consulting · Security awareness

Logging & detection

Build central logging and an operated SIEM, put EDR into operations and connect threat intelligence.

Measure detection coverage against MITRE ATT&CK, cut false positives and extend use cases.

SIEM (monitoring) · EDR operations & response

Vulnerabilities & patching

Establish regular scans, define criticality and remediation deadlines and operate patch management verifiably.

Sharpen remediation SLAs and reporting, schedule penetration tests with retesting.

Vulnerability management · Red teaming

Incident response

Write an incident response plan, name a response team and secure forensic capacity with response times.

Exercise response: tabletop drills, containment automation and regular compromise assessments.

Incident response · Compromise assessment

NIS2 questions and answers

Scope, obligations and reporting deadlines.

Who does NIS2 apply to?
NIS2 applies to essential and important entities across 18 sectors, depending on sector, company size and turnover. Suppliers are often pulled in through their customers' supply chain requirements.
What obligations does NIS2 introduce?
Risk management, logging and detection, incident response processes, vulnerability and patch management, supply chain security, training and reporting within 24 hours, 72 hours and one month.
How quickly must incidents be reported?
An early warning within 24 hours, an incident notification within 72 hours and a final report within one month.
Does a managed SOC make us NIS2 compliant?
A managed SOC covers the technical core requirements for detection, analysis, response and evidence. Governance topics such as applicability and supply chain are covered by our consulting.
What does the NIS2 self-check cost?
Nothing. The 15 questions run entirely in your browser — no registration, no email required and no answers stored.