October 6, 2026 · 4 minutes read

Check NIS 2 status, supervisory authority, fines and gaps in your browser. 27 EU Member States, 24 languages, no account, no data sent.

We are releasing a tool that shows a network operator or data centre, as soon as the company profile is filled in, what it is under NIS 2, who supervises it, what maximum fine it faces and how much work is left. It runs in 24 languages, for every EU Member State, and sends no data anywhere.

Open the NIS 2 compliance assessment

Start page of the NIS 2 compliance assessment tool
Start page: choice of country and language, scope of the assessment and the legal acts behind the questionnaire.

Why we built the NIS 2 compliance assessment

NIS 2 brought thousands of companies under cybersecurity regulation for the first time, most internet service providers and data centre operators among them. The first questions are always the same: are we in scope, essential or important, who supervises us, how high can a fine go, and where do we start. The tool answers them straight away and then shows the state of readiness area by area.

We built it so that companies in our sector get through that first stage faster and know at once how much work lies ahead.

What you get

  • entity status: essential, important or out of scope, with the provision it follows from;
  • the competent supervisory authority;
  • the maximum fine, both the fixed amount and the percentage of turnover, computed for the revenue entered;
  • statutory deadlines counted down to today;
  • a readiness level on a 0–5 scale and a list of gaps by priority, each with a reference to the provision behind it.

The management report is ready as soon as the company profile is filled in, before the first question, because status, authority and the fine ceiling follow from the law, not from the answers.

NIS 2 compliance report for a fictional operator
Report for the board, built on a fictional Irish company: entity status, readiness level, formal obligations, upcoming deadlines and financial liability.

27 countries, 24 languages

The page recognises the browser language and proposes the matching country. For every Member State the tool names the act transposing NIS 2 in its official wording, links to the source and ships its text: 77 files from 24 countries in total. Where no transposing act has been adopted yet (France, Spain, Ireland), it says so plainly.

For Poland the assessment runs on the national act on the cybersecurity system as amended in 2026. For the other countries it runs on the common EU layer: Implementing Regulation (EU) 2024/2690 and the obligations following directly from the Directive. The report states this, rather than pretending to know national provisions that have not been mapped yet.

Questionnaire with the legal basis for each question
Questionnaire: each question shows its legal basis in the Directive and the implementing regulation; answers use the scale fulfilled, in progress, not fulfilled, not applicable.

Your data stays with you

There is no account and no server. Answers are stored in the browser and in files you export yourself. The tool also runs opened from disk, on a machine with no internet access, which matters where answers about security controls should not leave the company.

See a report before you start

For every country there is a sample PDF report in its language, built on a fictional company. It shows exactly what you get at the end: sample reports for all Member States.

Gap analysis by priority
Gap analysis: areas ranked by priority, with current and target level and the provision behind each area.

Open source

The code is public on GitHub under AGPL-3.0; the substantive content under CC BY-SA 4.0. The tool is free, including for commercial use. National-law modules for further countries, register readers and translation fixes are welcome as pull requests.

The tool is for self-assessment. It is neither an audit nor legal advice.

Assessments often reveal gaps in business continuity and incident handling. If yours concern DDoS attacks, see how we protect operator and data centre networks.