EUSEC
Dashboard
Pricing Services Insurance
NIS2 applicability check · NIS2-Betroffenheitsprüfung

Find out before the authority does.

Is your company affected by NIS2?

The free, anonymous NIS2 self-assessment for essential and important entities — check your scope under Art. 21 NIS2 and BSIG §30 in minutes.

This is a preliminary self-assessment, not legal advice. National transposition differs between Member States — for example, Germany's NIS2UmsuCG / BSIG §30 uses the terms besonders wichtige and wichtige Einrichtung. Always confirm the result officially.

01
02
03
04
Step 01 — Jurisdiction

Where are you established, and do you operate in the EU?

Yes
We serve EU customers / operate in the EU
No
No activity within the EU
Step 02 — Sector

Which activity best matches your core business?

Pick the closest fit. If nothing fits cleanly, choose the last option — and we'll tell you what that means.

Step 03 — Size-independent rules

Do any of these apply to you?

Some entities are in scope of NIS2 regardless of their size. Tick everything that applies — or the last box if none do.

Trust service provider
Qualified or non-qualified
DNS service provider or TLD name registry
Operating DNS resolution or a top-level domain registry
Domain name registration services
Registrar / registration provider (for the relevant provisions)
Public electronic communications network or service
Publicly available e-communications
Public administration entity
Central government — or another level designated by your Member State
Designated critical entity under the CER Directive
Directive (EU) 2022/2557
Sole provider in your Member State of an essential service
Essential for societal or economic activity
Disruption could cause significant or systemic impact
On public safety, security or health — or systemic risk / national-regional importance
Specifically designated by your Member State authority
By name or by national rule
None of the above
No size-independent rule applies
Step 04 — Size

How large is your organisation?

Per Commission Recommendation 2003/361/EC. If you are part of a group, enter the figures including linked and partner enterprises.

Yes
We have a parent, subsidiaries or partner holdings
No
Standalone, independent enterprise

Size band: at least medium = ≥ 50 staff, or turnover > €10M and balance sheet > €10M. Large = ≥ 250 staff, or turnover > €50M and balance sheet > €43M. A small subsidiary of a large group can count as large.

Step 1 of 4
Your result
Verdict
Triggering rule

Rationale

Next steps to confirm

Preliminary self-assessment based on the inputs you provided — not legal advice. National transposition of NIS2 may differ, and group-size calculations can be complex. For borderline cases, confirm officially and seek legal review.

In scope — or supplying someone who is

Article 21(2)(d) makes your supply chain your problem.

Even out-of-scope suppliers are increasingly required, by contract, to meet NIS2-aligned security — because their in-scope customers must manage supply chain risk. Rate your whole supply chain with EUSEC: 10 company ratings free, no card, no obligation.

See how it works