Skip to main content

New Look NIS2 Assessment

New Look NIS2 Assessment


​

Overview

We've updated the NIS2 self-assessment in the CyberSmart platform to make it easier to understand and use — both for your own review and in conversations with your account manager or partner.

You'll find the updated assessment in the Assessments section of the CyberSmart platform. It's designed to help you understand and improve your organisation's alignment with the NIS2 Directive — and to support ongoing progress, not just a one-time check.

What is the NIS2 Assessment?

The NIS2 assessment is a guided self-assessment within CyberSmart that helps you:

  • See where your organisation currently stands on security

  • Identify gaps across key areas

  • Prioritise what to fix first

  • Track your progress over time

It includes:

  • 81 questions

  • Covering 10 security areas aligned with NIS2

  • Mapped to NIS2 and ISO 27001 requirements

  • A mix of multiple-choice answers and free-text notes

Please note: this is a self-assessment. It doesn't result in a certification, and CyberSmart doesn't audit your answers.

Why We Built It This Way

NIS2 is an EU-wide directive, but there's no single certification or standard assessment for it — each EU member state implements it differently.

You may be subject to NIS2 if your organisation is classified as an Essential or Important entity, and has either:

  • More than 50 employees, or

  • More than €10 million in annual turnover

Non-compliance can carry significant penalties:

  • Essential entities: up to €10 million or 2% of global turnover

  • Important entities: up to €7 million or 1.4% of global turnover

Since there's no universal certification to work toward, we built this assessment to give you a clear, practical, and repeatable way to track your alignment.

What's New

A clearer experience

  • Easier navigation

  • Organised by security domain

  • See your completion status at a glance

Clearer results
Each answer is automatically categorised as:

  • Compliant

  • Non-compliant

  • Partially compliant

  • Not applicable

  • Unanswered

This makes it easy to see what's done, what needs attention, and where to focus next.

Visibility as you go
You (and your partner, if applicable) can see:

  • Your overall completion percentage

  • A breakdown by question

  • Which areas have outstanding issues

Update anytime
This isn't a one-off form. You can save your progress, come back later, and update your answers as your security posture changes. We recommend reviewing your answers periodically to keep them accurate.

How It Works

In your dashboard
An Assessments column shows any assessments assigned to you, along with status and completion percentage. Click through to go straight to your assessment.

On the assessment page
You'll see an overview of the assessment, easy navigation between sections, and your current completion status.

Within each section
You can:

  • Choose from four structured answer options

  • Add extra context in a free-text field

  • Hover over questions for guidance and to see which controls they relate to

  • View a summary for that section

The left-hand menu also gives you a running overview of your questions, any outstanding issues, which areas need focus, and a summary you can use for reporting.

Availability

  • EU-based organisations: the NIS2 assessment is switched on by default for new accounts.

  • UK and elsewhere: available as part of a subscription — speak to your account manager for details.

Note: access to the Assessments module may need to be switched on for your account while this feature rolls out.

NIS2 Course in Learn

We've also added a dedicated NIS2 course to CyberSmart Learn, to help you understand:

  • What NIS2 is, and why it replaced the original NIS Directive

  • Who it applies to

  • What your business needs to do to prepare

This course is included if you have the Complete package, or if you've purchased Learn as a standalone product.

What This Means for You

  • Clarity — understand exactly where you stand against NIS2 requirements.

  • Focus — see the gaps that matter most, across governance, risk, incident response, and more.

  • Accountability — keep notes and context directly alongside your answers.

  • Reporting — generate a clear summary to share with your board or leadership.

  • A better approach — treat NIS2 as an ongoing process, not a one-time deadline to hit.

Frequently Asked Questions

Will I get a certificate for completing the NIS2 assessment?
No — this is a self-assessment and doesn't result in a certification.

Will someone from CyberSmart review my answers?
No — there's no audit or review by CyberSmart involved.

Do I need to complete this every year?
There's no formal annual requirement, but we recommend reviewing and updating your answers periodically to keep them accurate.

Why does this section of the platform look different?
We've rebuilt it using modern technology for a smoother, more responsive experience — while keeping it fully integrated with the rest of your dashboard.

Is the assessment available in other languages?
Yes. Based on your browser's language setting, it's available in French, Dutch, Italian, Polish, German, and Swedish. Free-text notes you add yourself aren't translated.

Did this answer your question?