Skip to content

We secure networks and protect them against DDoS attacks.

itoro.com.pl

Free tools

Regulatory risk assessment for the board

The NIS 2 Directive introduces personal liability of the management. The management body approves the risk-management measures, oversees their implementation and can be held liable for infringements (Article 20(1)). The fine for an essential entity reaches EUR 10,000,000 or 2 % of the total worldwide annual turnover, and the supervisory authority may temporarily prohibit a member of the management from exercising managerial functions (Article 32(5)(b), Article 34(4)).

NIS 2 compliance assessment — choose your country

Determines the entity's status (essential or important), the competent supervisory authority, the maximum fines and the deadlines, then guides you through a module-by-module assessment of readiness.

Directive (EU) 2022/2555Regulation (EU) 2024/269027 EU Member States · 24 languages
  • Management report as soon as the profile is filled in — entity status, supervisory authority, maximum fines, deadlines and the management's own tasks, before the first question is answered
  • Assessment scope tailored to the entity's profile — the tool skips requirements that do not apply to the entity
  • National law as the basis, EU law as the common layer — every requirement names the provision it stems from, with a link to the text of the act
  • All Member States and the 24 official EU languages — for states without a national-law module the assessment follows Regulation (EU) 2024/2690 and the NIS 2 Directive
  • Progress saving, snapshots, comparison over time, export to XLSX and JSON

Choose the country whose law applies to your entity — see the list below.

Management report in about 10 minutes. The sample shows a finished report on the data of a fictitious company — with classification, maximum fines and gap analysis.

Version 1.2.0 · 6 October 2026 · changelog

The tools were built so that network operators and data centres can prepare for NIS 2 faster and see at once how much work lies ahead. We provide them free of charge and without registration. They run entirely in the browser, and the data entered never leaves the user's device.

Choose your country

The same tool for the 27 Member States, in the 24 official languages of the Union. For states without a national-law module the assessment follows the common layer — the directly applicable Regulation (EU) 2024/2690 and the obligations arising directly from the NIS 2 Directive. The interface language can be changed in the tool independently of the country.

AustriaÖsterreich NIS-Gesetz 2026 (NISG 2026), BGBl. I Nr. 94/2025 common EU layer BelgiumBelgië · Belgique · Belgien Loi du 26 avril 2024 établissant un cadre pour la cybersécurité / Wet van 26 april 2024 common EU layer BulgariaБългария Закон за изменение и допълнение на Закона за киберсигурност, ДВ бр. 17/2026 common EU layer CroatiaHrvatska Zakon o kibernetičkoj sigurnosti, NN 14/2024 common EU layer CyprusΚύπρος Ο περί Ασφάλειας Δικτύων και Συστημάτων Πληροφοριών Νόμος, Ν. 60(Ι)/2025 common EU layer CzechiaČesko Zákon č. 264/2025 Sb., o kybernetické bezpečnosti common EU layer DenmarkDanmark Lov nr. 434 af 6. maj 2025 om foranstaltninger til sikring af et højt cybersikkerhedsniveau common EU layer EstoniaEesti Küberturvalisuse seadus (KüTS) common EU layer FinlandSuomi · Finland Kyberturvallisuuslaki 124/2025 common EU layer FranceFrance no national act GermanyDeutschland BSI-Gesetz in der Fassung des NIS2UmsuCG (BGBl. 2025 I Nr. 301) common EU layer GreeceΕλλάδα Νόμος 5160/2024 (ΦΕΚ Α΄ 195) και νόμος 5305/2026 (ΦΕΚ Α΄ 85) common EU layer HungaryMagyarország 2024. évi LXIX. törvény Magyarország kiberbiztonságáról common EU layer IrelandÉire · Ireland no national act ItalyItalia Decreto legislativo 4 settembre 2024, n. 138 common EU layer LatviaLatvija Nacionālās kiberdrošības likums common EU layer LithuaniaLietuva Lietuvos Respublikos kibernetinio saugumo įstatymas (nauja redakcija, Nr. XIV-2902) common EU layer LuxembourgLuxembourg · Luxemburg Loi du 5 mai 2026, Mémorial A 225 common EU layer MaltaMalta Subsidiary Legislation 460.41 — Measures for a High Common Level of Cybersecurity common EU layer NetherlandsNederland Cyberbeveiligingswet, Stb. 2026, 187 common EU layer PolandPolska Ustawa o krajowym systemie cyberbezpieczeństwa (tekst jednolity), Dz.U. 2026 poz. 20 national law + common EU layer PortugalPortugal Decreto-Lei n.º 125/2025 — Regime Jurídico da Segurança do Ciberespaço common EU layer RomaniaRomânia OUG nr. 155/2024, aprobată cu modificări prin Legea nr. 124/2025 common EU layer SlovakiaSlovensko Zákon č. 69/2018 Z. z. v znení zákona č. 366/2024 Z. z. common EU layer SloveniaSlovenija Zakon o informacijski varnosti (ZInfV-1), Uradni list RS 40/25 common EU layer SpainEspaña no national act SwedenSverige Cybersäkerhetslag (2025:1506) common EU layer

Data stays on the device

Answers, evidence and financial data are stored in the browser and in files exported by the user.

Works without a network connection

Once the page has loaded, the tool works locally. The Online / Offline switch also suspends queries to public registers.

Legal basis at every question

Every question names the provision it stems from, and the link opens the act at the right page.