NIS2 is in active enforcement in most EU member states. Directors can be personally liable for non-compliance. Get your compliance report →
NIS2 gap analysis · EU SMEs · 50–500 employees

Is your company NIS2-compliant? Find out in 30 minutes, not 3 months.

A guided assessment mapped to Article 21 of the NIS2 Directive, with a scope check for all 27 member states. You get an instant score, a professional gap analysis report with costed action plan, and a review call with an analyst.

€349 one-time · no subscription · no login · no software to install · 14-day guarantee

€10,000+what consultants charge for a NIS2 assessment
€7M · 1.4%max fine for important entities (Art. 34)
30 minyour time to complete the assessment
160,000EU entities estimated in scope (16× NIS1)
The problem

NIS2 is not optional. Most SMEs don't know where they stand.

Enforcement is active: Germany's registration window with the BSI has closed, the Netherlands' Cyberbeveiligingswet entered into force on 15 August 2026, and the Commission referred four member states to the Court of Justice in July 2026.

01

Fines are GDPR-scale — and managers are liable

Up to €10M or 2% of global turnover (essential entities) and €7M or 1.4% (important). Unlike GDPR, NIS2 makes management personally liable: fines can be directed at executives themselves (Art. 20).

Art. 34 · max fines
02

You're likely in scope

50+ employees and €10M+ turnover in Annex I or II sectors — or a supplier to someone who is. IT services and managed service providers sit in Annex I, high criticality.

Annex I · II
03

Customers will ask

In-scope companies must manage supplier risk (Art. 21(2)(d)). Your large clients will request NIS2 evidence — in contract renewals.

04

Deadlines are real

23 of 27 member states have transposed. The "wait and see" window is closing — registration deadlines are passing, not coming.

05

Ignorance is not a defense

You don't need to be perfect. You need demonstrable progress. A documented gap analysis is the first evidence of good faith.

06

"I don't know where to start"

The directive is 30+ pages of legalese; enterprise platforms cost €850–4,800/year and are built for teams that already have compliance. We meet you at the start: one structured questionnaire, one report, one price.

Check your readiness — free →

What this is

A professional service, not another tool.

You receive a document you can act on and show to your board, insurer, auditor and customers.

Not a platform

No login, no dashboard to maintain, no monthly fee, no implementation project. Your IT team doesn't touch a single configuration.

Not a certification

It's a gap analysis: the documented starting point. Certification comes later with an auditor — you'll arrive prepared.

Not a €10k engagement

Fixed price, delivered in 48 hours, with a 30-minute review call included. The report is written for your company, not generic output.

Not legal advice

We map your posture against Article 21 and your national law, and we tell you exactly where to confirm with your authority.

How it works

Thirty minutes of your time. A professional report in 48 hours.

Answer honestly: the report is only as useful as your answers.

1

Take the assessment

~30 questions across the 10 categories of Article 21, plus a scope check by country. Score is instant.

2

Choose your report

Gap Analysis Report (€349) or Compliance Pack (€599). One-time payment, no subscription.

3

Receive it in 48h

PDF with score, per-category gaps, costed action plan, 12-month roadmap. Plus a 30-minute review call.

4

Act and show progress

Use it with your board, insurer or customers. Re-assess anytime to evidence continuous improvement.

See it in 30 seconds

What NIS2 means for your company

And how to fix it fast.

Inside the €349 report

This is the document you receive.

Four pages that answer the questions your board, insurer and customers will ask. See the full sample report for the complete document.

Page 1Executive summary
64/100
Partial readiness

Readiness score · scope determination · max fine exposure · bottom line for the board.

Page 2Category scores
Risk & policy22
Incident handling44
Continuity33
MFA & comms67
Page 3Action plan
Quick wins0–4 wks
Short term1–3 mo
Strategic3–12 mo
Review call30 min

Every action with effort and cost estimate.

Page 4Roadmap & cost
M1 → M1243 → 70+
Est. remediation€3–8k
ISO crosswalk
See the full sample report → white-label PDF · delivered in 48h · 14-day guarantee
Methodology

Built around Article 21 — not a generic quiz.

Every question maps to a specific requirement of the directive. Scoring is structured and documented, so the report holds up when an auditor, insurer or customer reads it.

The 10 categories of Art. 21(2)

(a)Risk analysis & policy
(b)Incident handling
(c)Business continuity
(d)Supply-chain security
(e)Secure acquisition & development
(f)Effectiveness assessment
(g)Cyber hygiene & training
(h)Cryptography
(i)HR security & access
(j)MFA & secure comms
1

30-minute assessment

Structured questions plus a scope check by country and company size.

2

Structured scoring

Weighted 0–100 per category, documented in the report.

3

Gap analysis

Requirement → your current state → what's missing → risk of inaction.

4

Prioritized plan

Quick wins first, with effort and cost estimates, and a 12-month roadmap.

Start the assessment — free →

Who this is for

Built for companies that need an answer — not another project.

IT / Security

Know what needs fixing

Prioritized gaps with effort and cost, so a small team knows exactly where to start.

Management

Board-ready view of exposure

One score, one document, personal liability understood.

Procurement / Sales

Keep the contracts

Show customers a documented remediation plan when they ask for NIS2 evidence.

MSPs / Consultants

A starting point

Use the assessment to scope remediation work for your own clients.

Pricing

Simple, one-time, honest.

No monthly fees. No per-user licenses. Every paid plan includes a review call with an analyst and a 14-day money-back guarantee.

Self-Assessment
€0
Know where you stand in 30 minutes.
  • ~30 questions mapped to Article 21
  • Scope check for all 27 member states + EEA
  • Instant score /100, 10 color-coded categories
  • No email wall, no login
Start free
Gap Analysis Report
Most chosen
€349
The report you can show your board, insurer, or customers.
  • Everything in Self-Assessment
  • Gap analysis of all 10 categories, with legal references
  • Prioritized action plan with cost estimates
  • 12-month roadmap with score targets
  • White-label PDF in 48 hours
  • 30-min review call with an analyst
  • 14-day money-back guarantee
Buy report: €349
Compliance Pack
€599
Everything in the report, plus templates to start fixing gaps immediately.
  • Everything in Gap Analysis Report
  • Policy templates (security, incident response, access)
  • Board-ready executive summary
  • 1 hour of consulting included
Buy pack: €599

VAT per EU rules (reverse charge for B2B with valid VAT number) · proper invoice included with every purchase

FAQ

Questions you'll ask before buying

Is my company actually in scope of NIS2?

NIS2 covers "essential" and "important" entities: broadly, companies with 50+ employees and €10M+ turnover in sectors like energy, transport, healthcare, digital infrastructure, manufacturing, food, and IT services. If you're a supplier to those sectors, you're likely expected to comply too. The assessment tells you if you're in scope.

Is this a legal or compliance consultancy?

No. We're not a law firm and this isn't legal advice. We provide a practical, structured gap analysis based on Article 21, so you can see where you stand and where to focus. For formal certification, you'd engage your national authority or a certified auditor — you'll go in prepared.

How is this different from hiring a consultant?

Know where you stand before paying thousands for remediation. In 30 minutes you get an instant score, and in 48 hours a documented gap analysis with a prioritized action plan — so you can target your budget where the report shows it matters.

What do I actually receive?

A professional PDF report (white-label) with: your overall score, per-category scores, a list of concrete gaps, a prioritized action plan with cost estimates (quick wins, short-term, strategic), and a 12-month compliance roadmap.

Is my data safe?

Yes. Your answers are used only to generate your report and are never sold or shared. We delete your data on request after delivery (GDPR).

Can I re-take the assessment later to show progress?

Yes, any time, free. Many customers run it quarterly to demonstrate continuous improvement to their board or customers.

What if the report doesn't help me?

You have a 14-day money-back guarantee. If the report doesn't give you a clear, actionable picture of where you stand, email us and we refund you in full.

Which national NIS2 law applies to me?

NIS2 is transposed nationally: Germany (NIS2UmsuCG, BSI registration deadline already passed), Netherlands (Cyberbeveiligingswet, in force since 15 August 2026), Portugal (DL 125/2025), and all other member states. The assessment's scope check tells you which law applies and what to do first.

What happens after I pay?

You get a confirmation email with the assessment link (30 minutes). Once you submit your answers, we score and analyze them, and you receive your report by email within 48 hours, together with your VAT invoice and a link to book the included 30-minute review call. If you're not satisfied, the 14-day guarantee applies.

Can this replace an auditor or certification?

No. This is a gap analysis: the documented starting point. Formal certification still requires a certified auditor or your national authority — but you'll arrive prepared, with the evidence trail already structured.

Do I need to install software or create an account?

No. The assessment runs entirely in your browser, on any device, without an account. Your answers stay on your machine until you choose to send them to us for the report.

What happens next

Low risk, clear process.

After you pay

  • Confirmation email with your assessment link (30 min)
  • Your answers are scored and analyzed
  • Report delivered by email within 48 hours
  • 30-minute review call to validate priorities
  • Proper VAT invoice, always included
  • Not satisfied? 14-day money-back guarantee

Your data

  • Your answers are used only to prepare your report
  • Never sold, never used for advertising
  • GDPR: deletion on request after delivery
  • Assessment runs in your browser — no account, no install
  • Data stored on EU/EEA infrastructure where possible

Full details: Privacy Policy · Terms of Service

The window is closing

The report is 30 minutes away.

Take the free assessment now and see your score instantly. No commitment, no email wall.

Take the free self-assessment →

nis2.saevelis.com · hello@saevelis.com