NIS2 check
Get a first reading of your position under NIS2
Answer five questions about your situation, sector, size, current measures and the countries you operate in. You immediately receive a first assessment of your position and the SmartCyber level that may fit it. The result is an indication and not a formal legal opinion.
NIS2 check
Your answers stay in your browser
The check runs entirely in your browser. Your answers are not sent to Think Smart Europe or to any other party. You do not have to create an account and you receive no automatic commercial follow-up afterwards.
- Your answers stay in your browser
- Five questions, no account and no follow-up call
- A first indication, never a legal opinion
Step 1 of 5
What brings you here today?
The questions, in full
- What brings you here today?
- We think we have an incident right now
- NIS2 or its national version applies to us
- A customer or tender is asking us for proof
- We want to professionalise how our IT is run
- Which description fits your sector best?
- Energy, transport, banking, financial market infrastructure, health, drinking or waste water, digital infrastructure, ICT service management, public administration or space
- Postal and courier, waste management, chemicals, food, manufacturing, digital providers or research
- None of these describes us
- I am not sure which one applies
- How large is the organisation?
- Fewer than 50 people
- 50 to 249 people
- 250 people or more
- Where do you stand today?
- We have not started, we do not know if we are in scope
- We have registered, but the measures are not in place
- Some measures are in place, the evidence is not
- We are ISO 27001 certified or close to it
- In how many EU member states do you operate?
- One
- Two to five
- More than five
This is the same set of questions the interactive check asks. It gives a reading of your position and is never legal advice.
What the answers mean
Three positions, one duty of care
The directive splits organisations in scope into two categories and reaches a third group through them. The obligations are close to identical; what differs is how you are supervised.
Probably an essential entity
Your sector and size suggest your organisation may be classified as an essential entity. The ten security areas and the fixed reporting deadlines apply to these organisations. Supervision is proactive: the regulator can investigate without an incident having occurred first. A formal classification is needed to confirm this per country and per legal entity.
Highest supervisionProbably an important entity
Your sector and size suggest your organisation may be classified as an important entity. Largely the same security and reporting obligations apply to these organisations. Supervision is reactive and usually starts after an incident, a signal or a specific indication. A formal classification is needed to confirm this per country and per legal entity.
Same duty, later scrutinyProbably a supplier in the chain
Your organisation may not fall directly under NIS2. Customers that are in scope can still ask you for security measures, contractual arrangements and evidence. These requirements usually arrive through tenders, contracts and supplier questionnaires.
Contractual, not statutoryOne directive, twenty-seven national laws
The result can differ per country
Every member state has written NIS2 into national law. The competent authority, the registration system, the entry into force and sometimes the precise definitions and thresholds therefore differ. If you operate in several countries, the classification has to be carried out per legal entity and per country.
| Country | National law | Competent authority | In force | Registration route |
|---|---|---|---|---|
| Netherlands | Cyberbeveiligingswet (Cbw) | NCSC, RDI and sector supervisors | 15 August 2026 | Entity register via mijn.ncsc.nl. No transition period. |
| Germany | NIS2UmsuCG, replacing the BSIG | BSI | 6 December 2025 | BSI portal, after a Mein Unternehmenskonto account. Deadline passed. |
| Belgium | Law of 26 April 2024 and Royal Decree | Centre for Cyber security Belgium | 18 October 2024 | Safeonweb@Work. CyberFundamentals or ISO 27001 as the framework. |
| France | Loi résilience, awaiting promulgation | ANSSI | Expected 2026 | MesServicesCyber pre-registration. ReCyF is the reference framework. |
| Denmark | NIS2-loven, plus sector acts | SAMSIK with sector supervisors | 1 July 2025 | Sector regulator. Deadline passed. |
| Sweden | Cybersäkerhetslagen SFS 2025:1506 | MSB and PTS with sector authorities | 15 January 2026 | Report to the sector supervisor. Duties applied immediately. |
| Finland | Kyberturvallisuuslaki 124/2025 | Traficom NCSC-FI plus seven supervisors | 8 April 2025 | Sector supervisor. Deadline passed. |
| Norway | Digitalsikkerhetsloven. NIS2 not yet incorporated. | NSM | 1 October 2025 (NIS1) | EEA state. Expansion to NIS2 expected during 2026. |
Status August 2026. National laws, registration routes and deadlines can change. Think Smart Europe maintains a transposition tracker for all 27 member states and reviews it monthly. Use this overview as the starting point for a classification scan and check the current position with the competent authority.
About this check
What it is, and what it is not
Is the result a legal assessment?
No. The check gives an indication based on sector, size and a few practical questions.
Your actual classification follows the national law of every country where your organisation is active. The legal structure, the activities, the turnover, the balance sheet total, linked undertakings and exemptions also have to be assessed. A classification scan establishes it properly, entity by entity.
For the Netherlands you can compare the result with the current guidance from the NCSC at ncsc.nl.
Are my answers stored?
No. The check runs entirely in your browser. Your answers are not sent to us, no account is created for the check, and no cookie is set by it.
Getting in touch after the result is a separate step you choose to take.
What does it mean if we are probably not directly in scope for NIS2?
Customers that are in scope have to manage their supplier risks. They can therefore set comparable security requirements through contracts, tenders and annual reviews.
You may then need the same measures and the same evidence, but on the basis of a commercial arrangement rather than a direct statutory obligation.
Is an ISO 27001 certification sufficient?
ISO 27001 covers many subjects that also appear in NIS2, and in Belgium the CyberFundamentals framework treats ISO 27001 as a route to compliance. The certification does not, however, automatically settle the legal classification, the registration, the 24-hour, 72-hour and one-month reporting deadlines, or the accountability of the board under Article 20.
You also have to check whether the certificate covers all the relevant legal entities, sites and systems. In our experience an ISO 27001-certified organisation typically meets seven or eight of the ten measures and needs work on reporting, supply chain and board evidence.
If you would rather just ask
Have your situation formally assessed
The NIS2 check gives a first indication. With a classification scan we establish, per country and per legal entity, whether the law applies, how your organisation is classified and which measures or evidence are missing.
