Skip to main content

NIS2 Directive Compliance Checker

The NIS2 Directive (Directive (EU) 2022/2555) strengthens cybersecurity requirements for essential and important entities across the EU, including healthcare providers, digital infrastructure, and ICT service providers. It introduces stricter incident reporting timelines (24 hours for early warning), mandatory supply chain security assessments, and personal liability for management. This tool evaluates your cyber risk management, incident reporting readiness, supply chain controls, business continuity planning, and vulnerability management practices.

European Union
23 Questions
5 Categories
Progress: 0/23

Risk Management

0/5

Incident Reporting

0/5

Supply Chain Security

0/5

Business Continuity

0/4

Vulnerability Management

0/4

Risk Management

Assessment of cybersecurity risk management policies, governance, and technical measures.

22 pts

Q1

Has your management body formally approved a cybersecurity risk management policy, and are management members personally accountable for overseeing its implementation as required by NIS2 Article 20?

critical
6 pts

Q2

Do you conduct a comprehensive cyber risk assessment at least annually that identifies threats, vulnerabilities, and potential impacts specific to your healthcare systems and patient data?

critical
5 pts

Q3

Have management members completed mandatory cybersecurity training that covers NIS2 obligations, threat landscape, and their personal accountability for non-compliance?

high
4 pts

Q4

Do you implement multi-factor authentication, network segmentation, and encryption of data at rest and in transit as baseline technical security measures?

high
4 pts

Q5

Have you classified your organization as an essential or important entity under NIS2 Annex I/II, and are you registered with the relevant national competent authority?

medium
3 pts
VertiComply

Build HIPAA-compliant healthcare applications with AI-powered code generation.

Product

Features

Pricing

Tools

Company

About

Blog

Contact

Legal

Privacy

Terms

Compliance

© 2026 VertiComply. All rights reserved.

Built for HIPAA + SOC 2 Type II

About the NIS2 Compliance Checker

This checker scores your organisation against Directive (EU) 2022/2555, known as NIS2, whose national transposition deadline was 17 October 2024. Healthcare sits squarely in scope: Annex I lists healthcare providers, EU reference laboratories, entities carrying out R&D of medicinal products, manufacturers of basic pharmaceutical products, and manufacturers of medical devices considered critical during a public health emergency. The questions are weighted toward the ten risk-management measures in Article 21 and the incident reporting timeline in Article 23, because those are the two areas with hard obligations and defined deadlines. Scoring also weights management accountability heavily — Article 20 makes management bodies responsible for approving and overseeing cybersecurity measures, and provides for their personal liability, which is a materially different exposure from most other frameworks.

What this NIS2 assessment covers

The 23-question assessment scores 100 points across 5 weighted categories. Each category reflects a distinct NIS2 control domain.

Risk Management · 22 pts · 5 questions

Assessment of cybersecurity risk management policies, governance, and technical measures.

Incident Reporting · 22 pts · 5 questions

Evaluation of incident detection, classification, and mandatory reporting capabilities.

Supply Chain Security · 20 pts · 5 questions

Assessment of third-party and supply chain cybersecurity risk management.

Business Continuity · 18 pts · 4 questions

Evaluation of backup, recovery, and crisis management capabilities.

Vulnerability Management · 18 pts · 4 questions

Assessment of vulnerability detection, patching, and coordinated disclosure practices.


Common NIS2 compliance gaps

The patterns we see most frequently in NIS2 self-assessments and remediation work. Each is the kind of finding an auditor flags first.

Entity classification has not been determined. Essential and important entities face the same risk-management obligations but different supervisory regimes and penalty ceilings — up to €10 million or 2% of global turnover for essential, €7 million or 1.4% for important. Many healthcare organisations have never formally established which they are.

The 24-hour early warning is not operationally possible. Article 23 requires an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. Organisations with a security process that routes through legal review before any external communication cannot meet 24 hours.

Management approval is undocumented. Article 20 requires management bodies to approve the cybersecurity risk-management measures and oversee implementation, and requires them to follow training. No board minute, no evidence.

Supply chain security stops at the direct supplier. Article 21(2)(d) covers security in relationships with direct suppliers and service providers, including their own secure development practices — which for a healthcare provider means the EHR vendor's sub-processors, not merely the vendor.

Business continuity lacks a tested crisis management component. Article 21(2)(c) explicitly names backup management, disaster recovery and crisis management. Backups alone do not satisfy it.

The same programme is assumed to satisfy NIS2 and GDPR. They overlap on security measures and incident handling but differ on scope, trigger and timeline — GDPR's 72-hour clock is for personal data breaches to a supervisory authority, NIS2's 24-hour clock is for significant incidents to the CSIRT. A single incident can trigger both, on different schedules, to different recipients.


What to do with your NIS2 results

Your score is a starting point — these are the steps that convert the assessment into actionable remediation.

Determine whether you are an essential or important entity, and register with the national authority. This is a prerequisite, and in several member states registration itself is a deadline you can miss.

Rehearse the 24-hour early warning specifically. Decide in advance who can send it without further approval, and what minimum information it must contain. The 24-hour obligation fails on authority, not on knowledge.

Get management approval on the record. A dated board or executive minute approving the risk-management measures, plus evidence of the training Article 20(2) requires.

Tier your suppliers by criticality and write security requirements into the agreements. Then define how you will actually monitor them, because the obligation is ongoing rather than at onboarding.

Check the transposition detail in every member state where you operate. NIS2 is a directive, not a regulation — national implementations differ on thresholds, registration mechanics and supervisory practice.


NIS2 compliance FAQ

Does NIS2 apply to healthcare providers?

Yes. Annex I of the directive lists the health sector explicitly, including healthcare providers, EU reference laboratories, entities conducting R&D of medicinal products, manufacturers of basic pharmaceutical products and preparations, and manufacturers of medical devices deemed critical during a public health emergency. Size thresholds also apply, and several member states have extended scope further in national law.

What is the NIS2 incident reporting timeline?

Three stages under Article 23: an early warning to the CSIRT or competent authority within 24 hours of becoming aware of a significant incident, an incident notification with an initial assessment within 72 hours, and a final report within one month. An intermediate report may be requested in between.

Can directors be held personally liable under NIS2?

Yes, and this is one of the directive's most significant departures from earlier EU cybersecurity law. Article 20 makes management bodies responsible for approving and overseeing cybersecurity risk-management measures, and member states must provide that they can be held liable for breaches of that duty. Some national implementations allow temporary suspension of individuals from management roles for essential entities.

How is NIS2 different from GDPR?

GDPR protects personal data; NIS2 protects the continuity and security of network and information systems. A ransomware incident that halts clinical systems is a NIS2 incident whether or not personal data was exposed. The reporting timelines, recipients and triggers are different, and a single event can require both — which is why the two processes should be designed together rather than sequentially.

Does NIS2 apply to a US company operating in the EU?

It can. Entities established outside the Union that provide in-scope services within it may fall under NIS2 and are generally required to designate a representative in a member state where they offer services. Establishment and service-provision tests vary by national transposition, so this needs checking per country rather than assumed.

Build it instead of buying it

Generate a NIS2-compliant healthcare app with the controls built in

VertiComply generates production-ready healthcare applications with NIS2 controls scaffolded from the first commit — no add-on tier, no platform lock-in, code exported to your GitHub.

Start free