NIS2 checkContact

NIS2 check

Get a first reading of your position under NIS2

Answer five questions about your situation, sector, size, current measures and the countries you operate in. You immediately receive a first assessment of your position and the SmartCyber level that may fit it. The result is an indication and not a formal legal opinion.

NIS2 check

Your answers stay in your browser

The check runs entirely in your browser. Your answers are not sent to Think Smart Europe or to any other party. You do not have to create an account and you receive no automatic commercial follow-up afterwards.

  • Your answers stay in your browser
  • Five questions, no account and no follow-up call
  • A first indication, never a legal opinion

Step 1 of 5

What brings you here today?

The questions, in full

  1. What brings you here today?
    • We think we have an incident right now
    • NIS2 or its national version applies to us
    • A customer or tender is asking us for proof
    • We want to professionalise how our IT is run
  2. Which description fits your sector best?
    • Energy, transport, banking, financial market infrastructure, health, drinking or waste water, digital infrastructure, ICT service management, public administration or space
    • Postal and courier, waste management, chemicals, food, manufacturing, digital providers or research
    • None of these describes us
    • I am not sure which one applies
  3. How large is the organisation?
    • Fewer than 50 people
    • 50 to 249 people
    • 250 people or more
  4. Where do you stand today?
    • We have not started, we do not know if we are in scope
    • We have registered, but the measures are not in place
    • Some measures are in place, the evidence is not
    • We are ISO 27001 certified or close to it
  5. In how many EU member states do you operate?
    • One
    • Two to five
    • More than five

This is the same set of questions the interactive check asks. It gives a reading of your position and is never legal advice.

What the answers mean

Three positions, one duty of care

The directive splits organisations in scope into two categories and reaches a third group through them. The obligations are close to identical; what differs is how you are supervised.

Probably an essential entity

Your sector and size suggest your organisation may be classified as an essential entity. The ten security areas and the fixed reporting deadlines apply to these organisations. Supervision is proactive: the regulator can investigate without an incident having occurred first. A formal classification is needed to confirm this per country and per legal entity.

Highest supervision

Probably an important entity

Your sector and size suggest your organisation may be classified as an important entity. Largely the same security and reporting obligations apply to these organisations. Supervision is reactive and usually starts after an incident, a signal or a specific indication. A formal classification is needed to confirm this per country and per legal entity.

Same duty, later scrutiny

Probably a supplier in the chain

Your organisation may not fall directly under NIS2. Customers that are in scope can still ask you for security measures, contractual arrangements and evidence. These requirements usually arrive through tenders, contracts and supplier questionnaires.

Contractual, not statutory

One directive, twenty-seven national laws

The result can differ per country

Every member state has written NIS2 into national law. The competent authority, the registration system, the entry into force and sometimes the precise definitions and thresholds therefore differ. If you operate in several countries, the classification has to be carried out per legal entity and per country.

NIS2 transposition in the countries Think Smart Europe covers today
CountryNational lawCompetent authorityIn forceRegistration route
NetherlandsCyberbeveiligingswet (Cbw)NCSC, RDI and sector supervisors15 August 2026Entity register via mijn.ncsc.nl. No transition period.
GermanyNIS2UmsuCG, replacing the BSIGBSI6 December 2025BSI portal, after a Mein Unternehmenskonto account. Deadline passed.
BelgiumLaw of 26 April 2024 and Royal DecreeCentre for Cyber security Belgium18 October 2024Safeonweb@Work. CyberFundamentals or ISO 27001 as the framework.
FranceLoi résilience, awaiting promulgationANSSIExpected 2026MesServicesCyber pre-registration. ReCyF is the reference framework.
DenmarkNIS2-loven, plus sector actsSAMSIK with sector supervisors1 July 2025Sector regulator. Deadline passed.
SwedenCybersäkerhetslagen SFS 2025:1506MSB and PTS with sector authorities15 January 2026Report to the sector supervisor. Duties applied immediately.
FinlandKyberturvallisuuslaki 124/2025Traficom NCSC-FI plus seven supervisors8 April 2025Sector supervisor. Deadline passed.
NorwayDigitalsikkerhetsloven. NIS2 not yet incorporated.NSM1 October 2025 (NIS1)EEA state. Expansion to NIS2 expected during 2026.

Status August 2026. National laws, registration routes and deadlines can change. Think Smart Europe maintains a transposition tracker for all 27 member states and reviews it monthly. Use this overview as the starting point for a classification scan and check the current position with the competent authority.

About this check

What it is, and what it is not

Is the result a legal assessment?

No. The check gives an indication based on sector, size and a few practical questions.

Your actual classification follows the national law of every country where your organisation is active. The legal structure, the activities, the turnover, the balance sheet total, linked undertakings and exemptions also have to be assessed. A classification scan establishes it properly, entity by entity.

For the Netherlands you can compare the result with the current guidance from the NCSC at ncsc.nl.

Are my answers stored?

No. The check runs entirely in your browser. Your answers are not sent to us, no account is created for the check, and no cookie is set by it.

Getting in touch after the result is a separate step you choose to take.

What does it mean if we are probably not directly in scope for NIS2?

Customers that are in scope have to manage their supplier risks. They can therefore set comparable security requirements through contracts, tenders and annual reviews.

You may then need the same measures and the same evidence, but on the basis of a commercial arrangement rather than a direct statutory obligation.

Is an ISO 27001 certification sufficient?

ISO 27001 covers many subjects that also appear in NIS2, and in Belgium the CyberFundamentals framework treats ISO 27001 as a route to compliance. The certification does not, however, automatically settle the legal classification, the registration, the 24-hour, 72-hour and one-month reporting deadlines, or the accountability of the board under Article 20.

You also have to check whether the certificate covers all the relevant legal entities, sites and systems. In our experience an ISO 27001-certified organisation typically meets seven or eight of the ten measures and needs work on reporting, supply chain and board evidence.

If you would rather just ask

Have your situation formally assessed

The NIS2 check gives a first indication. With a classification scan we establish, per country and per legal entity, whether the law applies, how your organisation is classified and which measures or evidence are missing.

Your first step

The classification scan, one member state at a time

The scan has a fixed price per country. You learn whether the law captures you, how it classifies you, and which of the ten areas you already cover, with evidence gaps listed apart from control gaps.

The price, the lead time and any credit against follow-on work are confirmed in the intake call.
Plan an intake callOne call, free of charge.
Cyber Incident