0 of 7 answered
Where is your organisation established? NIS2 generally applies in the member state where you are established. This kit is written for Estonia's Cybersecurity Act and works as a baseline elsewhere in the EU.
Estonia Another EU member state Outside the EU
Which sector is your main activity in? Sectors of high criticality are listed in Annex I of the Directive, other critical sectors in Annex II.
Energy (electricity, heating, oil, gas, hydrogen, EV charging) Transport (air, rail, water, road) Banking or financial market infrastructure Healthcare, pharma, medical devices, labs Drinking water or waste water Digital infrastructure (cloud, data centre, CDN, IXP, telecoms) Managed IT or managed security services (MSP / MSSP) for businesses Public administration Space Postal and courier services Waste management Chemicals manufacture or distribution Food production, processing or wholesale Manufacturing: medical devices, electronics, electrical equipment, machinery, vehicles Online marketplace, search engine or social network Research organisation None of these (e.g. software, consulting, retail)
Does any of these apply to you? These are in scope regardless of size.
Select all that apply
Public electronic communications network or service provider Trust service provider (e-signatures, certificates, timestamps) DNS service provider, TLD registry or domain registrar Sole provider in the country of a service essential to society or the economy Designated by the authority as essential, critical or a vital-service provider None of these
How many people work for the organisation (full-time equivalent)? Fewer than 10 10-49 50-249 250 or more
Annual turnover? Up to €10 million €10-50 million More than €50 million
Balance sheet total? Up to €10 million €10-43 million More than €43 million
Do customers ask you to meet NIS2 or cybersecurity requirements (questionnaires, contract clauses, audits)? Organisations in scope must manage the security of their direct suppliers (Art. 21(2)(d)), so the requirements flow down to suppliers who are not in scope themselves.
Yes, already Not yet, but we expect it No