Free, no sign-up, about 2 minutes

Does NIS2 apply to your company?

NIS2 covers medium and large organisations in eighteen sectors, plus some providers regardless of size. Answer these questions to see where you stand under the Directive and, in Estonia, the Cybersecurity Act (KüTS).

0 of 7 answered

Where is your organisation established?

NIS2 generally applies in the member state where you are established. This kit is written for Estonia's Cybersecurity Act and works as a baseline elsewhere in the EU.

Which sector is your main activity in?

Sectors of high criticality are listed in Annex I of the Directive, other critical sectors in Annex II.

Does any of these apply to you?

These are in scope regardless of size.

Select all that apply

How many people work for the organisation (full-time equivalent)?
Annual turnover?
Balance sheet total?
Do customers ask you to meet NIS2 or cybersecurity requirements (questionnaires, contract clauses, audits)?

Organisations in scope must manage the security of their direct suppliers (Art. 21(2)(d)), so the requirements flow down to suppliers who are not in scope themselves.

Based on Articles 2 and 3 of Directive (EU) 2022/2555 and Estonia's Cybersecurity Act. General information, not legal advice.

Does NIS2 apply to my company? Free 2-minute check | Parendum