NIS2 Readiness Check

How NIS2-ready is your organization?

8 questions, 2 minutes. Get instant insight into your security awareness program's readiness for NIS2 compliance.

1/8
Does your organization have a designated owner of the security awareness program at board level?
NIS2 art. 20 — board-level accountability
2/8
Do all in-scope employees receive at least one security awareness training per year?
NIS2 art. 21 — periodic training for all staff
3/8
Does your organization run regular phishing simulations as part of risk management?
NIS2 art. 21(f) — behavioral risk measure
4/8
Can you export participation rates and behavioral results (click rate, report rate) for management or auditors?
Audit evidence — exportable reporting
5/8
Have board members demonstrably completed a cybersecurity training?
NIS2 art. 20 — board training is explicitly required
6/8
Are trainings differentiated by role, department or risk group?
Segmentation improves effectiveness and demonstrability
7/8
Do you have a documented annual plan for awareness activities with set themes and moments?
Program structure vs. one-off actions
8/8
Are awareness results and KPIs periodically reviewed by management or the board?
Governance linkage — evidence of active steering