Skip to content

NIS2 Checker

Is your organisation affected by NIS2?

Answer questions about activity, size and security organisation. The result shows review needs and next topics but does not replace legal scope assessment.

01 / 05

What sector does your organisation operate in?

Method

What the checker tests — and what it cannot decide

The checker separates a first scope signal from an operational self-assessment. Read the signal as a documented question to verify, not as a binding decision on NIS2 or the German BSIG.

01

Start with the legal gate

The first stage combines your broad activity, employee and revenue band, EU activity and KRITIS answer. Section 28 BSIG instead refers to exact entity types in Annexes 1 and 2, so selecting a sector is only an initial filter.

02

Sample operational readiness

The second stage asks 20 questions across nine working areas, including governance, incident handling, continuity, supply-chain security and access control. They sample topics in Section 30 BSIG; they are not a complete legal control catalogue or an audit programme.

03

Keep the score transparent

Each answer is assigned 0 points for not started, 50 for in progress or 100 for implemented. The overall result is the arithmetic mean. The review list shows up to three incomplete controls with the lowest scores; ties keep questionnaire order and do not imply a higher risk. This is KaitoSec's simple self-assessment method, not a BSI score.

Your result

What you receive after completing the check

The output is designed for triage: it makes assumptions and next questions visible so the responsible team can validate them against official sources and evidence.

A scope signal

The checker indicates a possible particularly important entity, possible important entity or no direct match from the supplied answers. It does not issue a legal determination.

A readiness breakdown

You see an overall percentage and the status of every answered control. The result reflects only your selections; it does not test documents, configurations or operating effectiveness.

A short review list

Up to three incomplete controls with the lowest scores are surfaced for review. Equal scores stay in questionnaire order, not risk order. The emailed report records the self-assessment, but it is not compliance evidence by itself.

Worked example: interpreting a scope signal

Scenario
A fictional organisation's actual activity matches an entity type in Annex 2 BSIG. It has 120 employees, operates in the EU and does not operate a critical facility.
Checker signal
The employee band produces a possible important entity result. That result identifies a review path; it does not establish that every organisation in the broader selected sector is covered.
Verification
Confirm the precise Annex 2 entity type, the Section 28 size calculation, data from partner or linked enterprises, turnover and balance-sheet total, German jurisdiction, and any special or sector-specific rule. Record the evidence and owner for each conclusion.

Limits

Four checks that still require human review

A short questionnaire cannot represent every threshold, exception and factual dependency in the BSIG. Use the following gaps as a review checklist before relying on the result.

Exact entity type

The sector menu is broader than the entity types in Annexes 1 and 2. For example, a general manufacturing label does not mean every manufacturer is within scope; the actual goods or services matter.

Complete size test

The checker does not ask for balance-sheet total. Where Section 28 uses a financial route, both the stated turnover and balance-sheet thresholds must be tested; revenue alone is only a warning signal.

Company and jurisdiction facts

Employee and financial data may need to include partner or linked enterprises under Recommendation 2003/361/EC. Establishment, main establishment, services offered and special size-independent categories can also affect the competent jurisdiction and classification.

Evidence and sector rules

The readiness answers are self-reported and do not test effectiveness. DORA, telecommunications, energy and other sector-specific provisions or exclusions may change which duties apply. Current law, BSI guidance and qualified advice prevail.

Official sources used for this methodology

Sources checked 3 September 2026

FAQ

Questions to settle before using the result

Is the NIS2 checker result legally binding?

No. It is a simplified orientation based only on the answers supplied. A defensible classification requires the exact statutory entity type, all relevant size and group data, jurisdiction and applicable special rules. Obtain qualified legal advice where the conclusion is material.

Why does the checker not ask for balance-sheet total?

The current flow is intentionally a short screen. Section 28 BSIG uses turnover and balance-sheet total together for its financial threshold routes. Because the checker captures only turnover, a result driven by that answer must be verified against both figures.

How is the readiness percentage calculated?

Not started counts as 0, in progress as 50 and implemented as 100. The checker averages the 20 answers and highlights up to three incomplete controls with the lowest scores. Ties retain questionnaire order. It is a review aid, not a risk ranking, official BSI maturity level or proof that a measure is effective.

Do parent, partner or linked companies count toward size?

They may. Section 28(4) BSIG refers to Recommendation 2003/361/EC for employee and financial calculations, including rules for partner and linked enterprises. The applicable aggregation and the BSIG's independence provision are fact-specific and are not modelled here.

What should we do after a possible in-scope result?

Verify and document the exact entity type and size calculation first. If the classification is confirmed, assign owners for Sections 30, 32 and 38 and check the BSI Portal process. Section 33 generally sets a registration deadline of no later than three months after the organisation first or again qualifies.

Does a 'not directly affected' result settle the question?

No. The result means only that these simplified inputs found no direct match. Recheck omitted special categories, group and jurisdiction facts, and contractual supply-chain requirements from regulated customers.

Which NIS2 step can your team make defensible next?

KaitoSec connects scope rationale, controls, owners and evidence with your existing ISMS and BCMS.