Interactive NIS-2 readiness check

 

Free NIS-2 checklist:
Self assessment for compliance and maturity level

   Excel questionnaire for implementation and evidence documentation

   Concrete action recommendations from ISMS experts

   Automatic evaluation with maturity level calculation 

   Mapping to standards such as ISO 27001, TISAX® and more
 

Download the free checklist now

Mockup HvS NIS-2 Self Assessment Tool
Download NIS-2 checklist (in German)

By submitting the form, you agree that we may contact you regarding the use of the NIS‑2 self-assessment tool. You can revoke this consent at any time. Information on how we handle your data can be found in our privacy policy.

What to expect in the checklist

With our free NIS-2 self-assessment tool, you can independently check how well your company meets the requirements of the NIS-2 directive.
The excel tool offers:

   Questionnaire for implementation and evidence of compliance

   Automatic evaluation with maturity level calculation

   Concrete action recommendations based on the results

   Mapping to ISO 27001, TISAX®, IT-Grundschutz, CIS Controls and VdS 10000

   Instructions for use

   No macros or external dependencies

500+ customers place their trust in us, from startups to large enterprises

Your benefits at a glance

How the tool supports you in NIS-2 readiness

With our practical self-assessment tool, you can confidently prepare your company for the NIS‑2 directive.
Structured questions, automatic maturity level calculation, and concrete action recommendations give you clarity in no time about where you stand and what to do next.

 

Field-tested for SMEs

Developed for the real needs of small and medium-sized enterprises. Simple, clear and without unnecessary complexity.

 

Reviewed by experts

Validated by ISO 27001 auditors and technically reviewed by certified experts.

 

Time savings

Quick clarity. Receive a complete readiness analysis in 45-120 minutes.

 

Cost efficiency

An initial self-assessment saves external audit and consulting costs.

 

Maturity level & actions

Transparent evaluation. Automatic maturity level calculation and prioritized action recommendations.

 

Leverage existing standards

Avoid duplicate work by consistently linking NIS-2 requirements with existing frameworks such as ISO 27001, TISAX®, BSI IT-Grundschutz and GDPR.

Download the checklist for free nowen

 

NIS-2 Self Assessment Tool Screenshot

All key information in one tool

What the self-assessment tool offers

  • Questionnaire
    Structured self-assessment: Answer questions on the implementation and evidence of security measures. Scoring is performed automatically.
  • Evaluation
    Clear results: Calculated maturity level per topic area as well as concrete action and measure recommendations for your roadmap.
  • Mapping to standards
    Alignment with standards: Link NIS-2 requirements with ISO 27001, TISAX®, IT-Grundschutz, GDPR, CIS Controls and VdS 10000 – ideal for audit preparation.
  • Guidance and resources
    Practical recommendations: Based on your evaluation, you receive suitable measures and additional resources to improve your NIS-2 compliance.

Convinced? Download for free now
 

Download for free now    Schedule a meeting

Frequently asked questions about the NIS-2 
self-assessment tool

The NIS‑2 self-assessment tool is a practical analysis tool that allows companies to quickly and systematically evaluate their current level of implementation of the NIS‑2 directive.
It is based on a scientific study conducted in collaboration with a Bavarian university (as part of a bachelor’s thesis) and is specifically designed for small and medium-sized enterprises.
The tool helps you:

  • Understand your NIS‑2 obligations
  • Determine your company’s maturity level
  • Identify gaps between implementation (practice) and documentation (evidence)

The evaluation is presented using a traffic light system and provides a clear management summary – ideal for prioritizing actions or requesting budget approval from management.
Technical requirement: Only Microsoft Excel is needed; no installation of external software.

It was specifically developed for information security officers (ISOs), IT managers and managing directors in small and medium-sized enterprises. It is ideal for anyone who wants to quickly and pragmatically determine their NIS‑2 status without deep legal knowledge.

Plan for the first run to take approximately 45-120 minutes - depending on prior knowledge and the level of documentation. The advantage: the tool saves your entries, so subsequent reviews and updates can be completed in just a few minutes.

It is best to have access to your organizational charts (responsibilities), existing IT policies, and emergency plans. If something is not available: no problem - the tool automatically flags it as an action item.

No. The tool is an internal gap analysis for preparation. It clearly shows you where you stand, helping you avoid unpleasant surprises in a real audit. It provides the roadmap but does not replace an assessment by a third party.

It is based on a scientific study conducted in collaboration with a Bavarian university and precisely distinguishes between implementation (practice) and documentation (evidence). This way, you can immediately see whether your company is not only secure but can also prove it in an audit.

Nothing. The tool runs locally on your computer. No data is transmitted to us or third parties. You retain full control.

Of course, you can contact us at any time if you have questions! However, if the inquiry requires significant consulting effort, it will need to be handled as a separate consulting project.

The dashboard shows you what is missing in your company. Use the HvS services linked in the tool to efficiently close these gaps instead of starting from scratch.

Yes. The tool identifies the specific NIS‑2 gaps (e.g., strict 24-hour reporting deadlines, personal liability) that are often not explicitly covered in standard certifications.

Many companies are technically secure (firewalls, backups), but documentation is lacking. In our study, this proved to be the biggest hurdle for SMEs. The tool deliberately separates these two levels. This way, you can immediately see whether you are truly at risk - or if you just need to complete your “homework” on paperwork to be audit-ready.

Definitely. In our expert interviews, this was the greatest benefit of the tool. The graphical evaluation (traffic light system) serves as an ideal argumentation aid (“management summary”) to visually show management where urgent action is needed to minimize personal liability.

Yes, based on the principle of “help for self-help.” Depending on your maturity level, we offer tailored solutions - from a template package to get started to an incident response retainer for ongoing operations.

Additional information you might find interesting

ISMS according to NIS-2 Preview

We work with you to design your company-specific ISMS in accordance with NIS-2, establish the necessary processes and guidelines and anchor them in the company. Request support now!

Read more
NIS-2 Training Teaser

One hour of training for management bodies in accordance with NIS-2 (§38 BSIG), available as an in-person event or e-learning course. Fast, efficient, developed by security and learning professionals. 

Read more
Informationssicherheit
NIS-2 Umsetzung:  Praxisleitfaden zur rechtssicheren Compliance [inkl. Checkliste]

Praxisnaher Leitfaden zur NIS-2-Umsetzung: Betroffenheitsprüfung, Reifegrad, ISMS, Anforderungen & vollständige Checkliste. 

Read more