Achieve end-to-end NIS2 audit-readiness in just 12 weeks.
Read more about our NIS2 Compliance →
Services
Case Studies
Careers
About us
Contact us
NIS2 SaaS Readiness Check
5-minute compliance assessment
Part 1:The Scope (Are you affected?)
The “Essential” Criteria
Does your SaaS company have more than 50 employees OR an annual turnover exceeding €10 million?
(Required)
Yes → You are legally obligated to comply (In Scope)
No (< 50 staff AND < €10m revenue)
Not sure
Even if you are smaller: Do you provide software as a service to enterprise clients in critical sectors (Banking, Energy, Healthcare, Transport, Public Administration)?
(Required)
Yes, we serve critical industries
No, purely B2C or non-critical B2B
We are planning to
PART 2: The CEO Liability Check
These questions determine personal liability.
Has your management board formally approved and signed off on a cybersecurity risk management methodology?
(Required)
Yes, signed and documented
We have IT policies, but no board sign-off
No
Do you have a current Risk Heat Map that identifies specific threats to your CI/CD pipeline and cloud infrastructure?"
(Required)
Yes, updated quarterly
We have a general risk assessment from last year
No, we rely on our Cloud Provider’s security
PART 3: Operational Reality (The Killer Questions)
How your systems perform under pressure?
If a breach occurs at 3:00 AM on a Sunday, how long until a qualified engineer actively responds?
(Required)
Immediately (< 15 mins). We have 24/7 monitoring
Monday morning, unless a customer calls
We rely on automated alerts
Have you legally agreed on security requirements with your direct sub-processors (hosting, dev-tools, 3rd party APIs)?
(Required)
Yes, updated contracts are in place
We use standard T&Cs (AWS/Azure/Google)
Not systematically
Can you restore your entire SaaS environment from an immutable backup within a defined RTO after a ransomware attack?
(Required)
Yes, tested within the last 6 months
Theoretically yes, but untested
We rely on cloud snapshots
PART 4: The 10 Mandates (Quick Scan)
Check all that apply!
Which of these mandatory Article 21 measures are fully implemented and documented?
Multi-Factor Authentication (MFA) for all access
Vulnerability Disclosure Policy
Regular Security Awareness Training for all staff
Cryptography & Encryption policies
HR Security (Background checks, offboarding)
Open toolbar
Accessibility Tools
Accessibility Tools
Increase Text
Increase Text
Decrease Text
Decrease Text
Grayscale
Grayscale
High Contrast
High Contrast
Negative Contrast
Negative Contrast
Light Background
Light Background
Links Underline
Links Underline
Readable Font
Readable Font
Reset
Reset
Feedback
Feedback