Does NIS2 apply to your organisation?
Sector, size — including group structures under Recommendation 2003/361/EC — and the size-independent triggers, with an ordered, cited reason chain and the German categories under § 28 BSIG.
Start the checkFour questions every organisation in the DACH market meets first: Does NIS2 apply to us? Is this incident reportable, and by when? How deeply must we review this supplier? Which ISO/IEC 27001 controls cover which Art 21 measure? Each check runs on the same cited engines as the platform and stores nothing.
Sector, size — including group structures under Recommendation 2003/361/EC — and the size-independent triggers, with an ordered, cited reason chain and the German categories under § 28 BSIG.
Start the checkArt 23(3) two-limb test plus the thresholds of Implementing Regulation (EU) 2024/2690 for your entity type; the 24 h / 72 h / 1 month deadlines from the moment of awareness; what is still missing per report.
Start the checkFrom your own answers — data access, privileges, outage tolerance, replaceability — to a review depth, the evidence to ask for, the questionnaire scope and the contract clauses.
Start the checkArt 21(2)(a)–(j) mapped to ISO/IEC 27001:2022 Annex A, NIST CSF 2.0 and NIST SP 800-53, with the evidence auditors expect and the matching section of Implementing Regulation 2024/2690.
Open the table