Skip to content
otatel.com
NIS2 · Directive (EU) 2022/2555 · BSIG

Preliminary checks without a login

Four questions every organisation in the DACH market meets first: Does NIS2 apply to us? Is this incident reportable, and by when? How deeply must we review this supplier? Which ISO/IEC 27001 controls cover which Art 21 measure? Each check runs on the same cited engines as the platform and stores nothing.

no login

Does NIS2 apply to your organisation?

Art. 2, 3 NIS2 · Empf. 2003/361/EG · § 28 BSIG

Sector, size — including group structures under Recommendation 2003/361/EC — and the size-independent triggers, with an ordered, cited reason chain and the German categories under § 28 BSIG.

Start the check
no login

Is this incident reportable — and by when?

Art. 23 NIS2 · DVO (EU) 2024/2690 · § 32 BSIG

Art 23(3) two-limb test plus the thresholds of Implementing Regulation (EU) 2024/2690 for your entity type; the 24 h / 72 h / 1 month deadlines from the moment of awareness; what is still missing per report.

Start the check
no login

How deeply must you review this supplier?

Art. 21 Abs. 2 lit. d, Abs. 3 NIS2 · DVO 2024/2690 Anhang Nr. 5

From your own answers — data access, privileges, outage tolerance, replaceability — to a review depth, the evidence to ask for, the questionnaire scope and the contract clauses.

Start the check
no login

Measures crosswalk: Art 21 ↔ ISO/IEC 27001

Art. 21 Abs. 2 lit. a–j NIS2 · ISO/IEC 27001:2022 Anhang A

Art 21(2)(a)–(j) mapped to ISO/IEC 27001:2022 Annex A, NIST CSF 2.0 and NIST SP 800-53, with the evidence auditors expect and the matching section of Implementing Regulation 2024/2690.

Open the table

How the checks work

  • Every verdict comes from a pure, unit-tested engine that cites the article it applied; the same engines run inside the NIS2 platform for real assessments.
  • Nothing you enter is stored, no cookie is set, no third party is called. Print the result if you want to keep it.
  • Every result names the points that need human judgement — borderline figures, Member-State options, a 'not affected' verdict — instead of hiding them behind a green tick.
  • The platform behind the checks adds what a check cannot: entities, controls with owners and evidence, incident timers, supplier records, audit trail. A read-only demo account is shown on the login page.