Orientation in eight questions

NIS 2 Check for in-scope entities

In a few minutes, assess how clearly scope, registration, incident reporting, management accountability, risk measures, cyber hygiene, the supply chain and business continuity are organised. The evaluation identifies initial priorities without collecting personal data.

A transparent quick check, not an audit

The check follows Directive (EU) 2022/2555 (NIS 2) and the German implementation in the NIS 2 Implementation Act (BGBl. 2025 I No. 301), including the revised BSI Act (BSIG). The BSI provides guidance for NIS 2-regulated entities. Scoring is explicit: Yes = 3, Partly = 2, Unknown = 1, No = 0. The result provides orientation and is neither an audit, a BSI registration, nor legal advice. For methodological orientation along BSI IT-Grundschutz, see the BSI IT-Grundschutz Check.

Evidence Review · 8 questions
Step 1 of 2
Step 1: Scope and duties
01 · ScopeHas your organisation determined whether it is an essential entity or an important entity under NIS 2 and the BSI Act?

Requirement from Directive (EU) 2022/2555, Article 3 and BSIG section 28. The BSI offers a scope self-assessment.

02 · RegistrationIs your entity registered with the BSI: or has registration been initiated if you qualify as an essential or important entity?

Requirement from BSIG section 33. The BSI describes the registration process in the BSI portal.

03 · Incident reportingIs there a robust reporting path for significant incidents: an early warning without undue delay and at the latest within 24 hours, a notification within 72 hours, and a final report within one month?

Requirement from Directive (EU) 2022/2555, Article 23 and BSIG section 32.

04 · ManagementDoes management implement the cybersecurity risk-management measures, oversee their implementation, and regularly attend training to identify and assess cyber risks?

Requirement from Directive (EU) 2022/2555, Article 20 and BSIG section 38.

Step 2: Risk measures and operations
05 · Risk measuresAre appropriate, proportionate technical and organisational risk-management measures in place, including policies on risk analysis and information-system security?

Requirement from Directive (EU) 2022/2555, Article 21(1) and 21(2)(a) and BSIG section 30(1) and 30(2) no. 1.

06 · Cyber hygieneAre basic cyber-hygiene practices and regular cybersecurity training or awareness measures established?

Requirement from Directive (EU) 2022/2555, Article 21(2)(g) and BSIG section 30(2) no. 7.

07 · Supply chainAre security-related aspects of relationships with direct suppliers and service providers included in the risk measures?

Requirement from Directive (EU) 2022/2555, Article 21(2)(d) and 21(3) and BSIG section 30(2) no. 4.

08 · Business continuityIs business continuity organised, including backup management, disaster recovery and crisis management?

Requirement from Directive (EU) 2022/2555, Article 21(2)(c) and BSIG section 30(2) no. 3.

Regulatory context and target groups

For IT operations

IT owners in pharma and life science gain an initial view of registration, reporting paths, cyber hygiene and business continuity: independently of GxP CSV.

For management

The check helps prioritise gaps in accountability, training and the supply chain before supervisory or reporting deadlines tighten.

Develop NIS 2 with robust evidence

Discuss scope, reporting paths or secure IT operations with our advisory team.

Contact us