Skip to main content
3/16/2026NIS2

NIS2 quick scan: Are you on track?

The NIS2 Directive is not a paper exercise. It is a management responsibility with operational consequences. Many organizations are now “working on NIS2,” but the real… Read more

The NIS2 Directive is not a paper exercise. It is a management responsibility with operational consequences. Many organizations are now “working on NIS2,” but the real question is: are you demonstrably on track or mostly just talking?

In this blog, you will find a practical quick scan that allows you to determine your position in 10 minutes.

The quick scan: five questions that reveal a lot

Answer the questions below honestly with yes or no. The goal is not to achieve a perfect score, but to gain insight into where the organization stands.

1. Is management aware of its formal responsibility?

One of the most important changes in NIS2 is that directors explicitly become responsible for cyber risks. This means that cybersecurity must be an integral part of governance and decision-making.

Practically, this means that cyber risks are structurally on the management agenda, that responsibilities are formally documented, and that periodic reports are made on digital risks and incidents. If management is not actively involved, NIS2 almost automatically becomes a paper exercise without real impact.

2. Does the organization have an up-to-date risk analysis?

The NIS2 Directive obliges organizations to take measures based on risks. This means that it must first be clear which processes and systems are truly critical for the organization.

In a good risk analysis, the most important business processes – often referred to as the “crown jewels” – are identified. Subsequently, threats and vulnerabilities are mapped, and it is determined which risks have priority. Without this analysis, it becomes difficult to substantiate security measures or explain why certain choices were made.

3. Can a serious incident be reported within 24 hours?

Another important part of NIS2 is the reporting obligation for serious cyber incidents. Organizations must be able to provide an initial warning to the competent authority within 24 hours and deliver a more extensive report within 72 hours.

This requires clear detection and escalation processes. Employees must know when an incident is reportable, who is responsible for the report, and how the procedure works. Organizations that do not practice these processes beforehand often discover during a crisis that the reporting obligation is difficult to implement.

4. Are critical suppliers actively monitored?

Digital dependencies on suppliers constitute one of the biggest risks in modern organizations. Software vendors, cloud providers, and IT service providers are often directly connected to critical processes.

The NIS2 Directive therefore explicitly calls for attention to supply chain security: the security of digital chains. This means that organizations must have insight into their critical suppliers, that these suppliers are assessed for risk, and that security requirements are contractually stipulated.

Many organizations appear to be reasonably mature internally in terms of cybersecurity but have limited visibility into risks with suppliers.

5. Can the organization demonstrate what is happening?

NIS2 not only requires measures but also demonstrability. Supervisors expect organizations to be able to show which decisions have been made, which risks have been assessed, and which measures have been implemented.

This means that policies must be documented, decisions must be recorded, and incidents must be registered. In a legal sense, a simple rule often applies: what cannot be demonstrated is considered as if it does not exist.

Score and interpretation

The outcome of the quick scan provides an indication of the organization's maturity.

  • 5x yes → You are likely on track, but a formal gap analysis remains advisable.
  • 3–4x yes → You have started, but there are still clear risks.
  • 0–2x yes → NIS2 is likely not yet sufficiently embedded.

It is important to emphasize that NIS2 does not demand perfection. The directive focuses on demonstrable, proportional, and structural control of cyber risks.

What does this mean in practice for organizations?

The quick scan can be a valuable tool to initiate internal discussions. By jointly discussing the questions with management, CISO, and risk management, clarity often quickly emerges regarding where the biggest gaps lie.

Many organizations use such a scan as a starting point for a formal NIS2 gap analysis, a management discussion about cyber risks, or an evaluation of the digital supply chain. In other cases, it helps to determine priorities for improvement measures.

The biggest mistake organizations can make is waiting until supervision, regulation, or an incident forces them to take action. Then the pressure is often greater and the room for maneuver smaller.

The role of supply chain monitoring

One of the most challenging aspects of NIS2 is gaining insight into the digital chain. Modern organizations work with dozens to hundreds of external IT service providers, software vendors, and cloud platforms. Each of these parties can form a potential entry point for cyber risks.

Therefore, attention is growing for solutions that continuously monitor supplier risk. Platforms like RiskStudio specifically address this issue. RiskStudio was developed to provide organizations with insight into digital dependencies and cyber risks with external parties.

The platform maps critical suppliers, monitors the digital footprint of these parties, and identifies potential vulnerabilities or incidents early. This is done according to a so-called outside-in approach: a method where risks are assessed based on publicly observable digital signals, without relying on questionnaires or cooperation from suppliers.

For organizations falling under NIS2, this can help make supply chain risks more visible and demonstrable.

Conclusion

The NIS2 Directive explicitly makes cybersecurity a management topic. It is no longer just about technical measures, but about structural risk management within the entire organization.

With a simple quick scan, it can quickly be determined whether the organization is actually on its way towards NIS2 compliance. It often turns out that the biggest steps are not technical but lie in governance, responsibility, and insight into the digital chain.

Organizations that now begin to structurally set up these processes are not only building compliance but, more importantly, a more resilient digital organization. This prevents cyber risks from becoming visible only when it is already too late.

Frequently Asked Questions

Does every organization fall under NIS2?

No. The directive applies to specific sectors and size criteria. However, many organizations indirectly deal with NIS2 through customers or suppliers.

Is ISO 27001 sufficient for NIS2?

Not automatically. ISO helps, but NIS2 sets additional requirements, especially concerning governance, incident reporting, and supply chain.

How often should you monitor suppliers?

NIS2 requires appropriate and proportional measures. In practice, this means continuous or periodic monitoring, depending on criticality.

What is the first step if we haven't done anything yet?

Start with management awareness and a formal risk analysis. Without that foundation, everything remains ad hoc.

FAQ

Questions about this analysis

What does this article explain?

The NIS2 Directive is not a paper exercise. It is a management responsibility with operational consequences. Many organizations are now “working on NIS2,” but the real… Read more

How is this analysis connected to current intelligence?

Related signal context is selected from current published reporting using the article subject, content and topic tags.

Where can I find related analysis?

Follow the article tags or return to the analysis archive to browse other reporting on connected subjects.