Check NIS 2 status, supervisory authority, fines and gaps in your browser. 27 EU Member States, 24 languages, no account, no data sent.
We are releasing a tool that shows a network operator or data centre, as soon as the company profile is filled in, what it is under NIS 2, who supervises it, what maximum fine it faces and how much work is left. It runs in 24 languages, for every EU Member State, and sends no data anywhere.
Open the NIS 2 compliance assessment

Why we built the NIS 2 compliance assessment
NIS 2 brought thousands of companies under cybersecurity regulation for the first time, most internet service providers and data centre operators among them. The first questions are always the same: are we in scope, essential or important, who supervises us, how high can a fine go, and where do we start. The tool answers them straight away and then shows the state of readiness area by area.
We built it so that companies in our sector get through that first stage faster and know at once how much work lies ahead.
What you get
- entity status: essential, important or out of scope, with the provision it follows from;
- the competent supervisory authority;
- the maximum fine, both the fixed amount and the percentage of turnover, computed for the revenue entered;
- statutory deadlines counted down to today;
- a readiness level on a 0–5 scale and a list of gaps by priority, each with a reference to the provision behind it.
The management report is ready as soon as the company profile is filled in, before the first question, because status, authority and the fine ceiling follow from the law, not from the answers.

27 countries, 24 languages
The page recognises the browser language and proposes the matching country. For every Member State the tool names the act transposing NIS 2 in its official wording, links to the source and ships its text: 77 files from 24 countries in total. Where no transposing act has been adopted yet (France, Spain, Ireland), it says so plainly.
For Poland the assessment runs on the national act on the cybersecurity system as amended in 2026. For the other countries it runs on the common EU layer: Implementing Regulation (EU) 2024/2690 and the obligations following directly from the Directive. The report states this, rather than pretending to know national provisions that have not been mapped yet.

Your data stays with you
There is no account and no server. Answers are stored in the browser and in files you export yourself. The tool also runs opened from disk, on a machine with no internet access, which matters where answers about security controls should not leave the company.
See a report before you start
For every country there is a sample PDF report in its language, built on a fictional company. It shows exactly what you get at the end: sample reports for all Member States.

Open source
The code is public on GitHub under AGPL-3.0; the substantive content under CC BY-SA 4.0. The tool is free, including for commercial use. National-law modules for further countries, register readers and translation fixes are welcome as pull requests.
The tool is for self-assessment. It is neither an audit nor legal advice.
Assessments often reveal gaps in business continuity and incident handling. If yours concern DDoS attacks, see how we protect operator and data centre networks.