New Look NIS2 Assessment
Overview
We've updated the NIS2 self-assessment in the CyberSmart platform to make it easier to understand and use — both for your own review and in conversations with your account manager or partner.
You'll find the updated assessment in the Assessments section of the CyberSmart platform. It's designed to help you understand and improve your organisation's alignment with the NIS2 Directive — and to support ongoing progress, not just a one-time check.
What is the NIS2 Assessment?
The NIS2 assessment is a guided self-assessment within CyberSmart that helps you:
See where your organisation currently stands on security
Identify gaps across key areas
Prioritise what to fix first
Track your progress over time
It includes:
81 questions
Covering 10 security areas aligned with NIS2
Mapped to NIS2 and ISO 27001 requirements
A mix of multiple-choice answers and free-text notes
Please note: this is a self-assessment. It doesn't result in a certification, and CyberSmart doesn't audit your answers.
Why We Built It This Way
NIS2 is an EU-wide directive, but there's no single certification or standard assessment for it — each EU member state implements it differently.
You may be subject to NIS2 if your organisation is classified as an Essential or Important entity, and has either:
More than 50 employees, or
More than €10 million in annual turnover
Non-compliance can carry significant penalties:
Essential entities: up to €10 million or 2% of global turnover
Important entities: up to €7 million or 1.4% of global turnover
Since there's no universal certification to work toward, we built this assessment to give you a clear, practical, and repeatable way to track your alignment.
What's New
A clearer experience
Easier navigation
Organised by security domain
See your completion status at a glance
Clearer results
Each answer is automatically categorised as:
Compliant
Non-compliant
Partially compliant
Not applicable
Unanswered
This makes it easy to see what's done, what needs attention, and where to focus next.
Visibility as you go
You (and your partner, if applicable) can see:
Your overall completion percentage
A breakdown by question
Which areas have outstanding issues
Update anytime
This isn't a one-off form. You can save your progress, come back later, and update your answers as your security posture changes. We recommend reviewing your answers periodically to keep them accurate.
How It Works
In your dashboard
An Assessments column shows any assessments assigned to you, along with status and completion percentage. Click through to go straight to your assessment.
On the assessment page
You'll see an overview of the assessment, easy navigation between sections, and your current completion status.
Within each section
You can:
Choose from four structured answer options
Add extra context in a free-text field
Hover over questions for guidance and to see which controls they relate to
View a summary for that section
The left-hand menu also gives you a running overview of your questions, any outstanding issues, which areas need focus, and a summary you can use for reporting.
Availability
EU-based organisations: the NIS2 assessment is switched on by default for new accounts.
UK and elsewhere: available as part of a subscription — speak to your account manager for details.
Note: access to the Assessments module may need to be switched on for your account while this feature rolls out.
NIS2 Course in Learn
We've also added a dedicated NIS2 course to CyberSmart Learn, to help you understand:
What NIS2 is, and why it replaced the original NIS Directive
Who it applies to
What your business needs to do to prepare
This course is included if you have the Complete package, or if you've purchased Learn as a standalone product.
What This Means for You
Clarity — understand exactly where you stand against NIS2 requirements.
Focus — see the gaps that matter most, across governance, risk, incident response, and more.
Accountability — keep notes and context directly alongside your answers.
Reporting — generate a clear summary to share with your board or leadership.
A better approach — treat NIS2 as an ongoing process, not a one-time deadline to hit.
Frequently Asked Questions
Will I get a certificate for completing the NIS2 assessment?
No — this is a self-assessment and doesn't result in a certification.
Will someone from CyberSmart review my answers?
No — there's no audit or review by CyberSmart involved.
Do I need to complete this every year?
There's no formal annual requirement, but we recommend reviewing and updating your answers periodically to keep them accurate.
Why does this section of the platform look different?
We've rebuilt it using modern technology for a smoother, more responsive experience — while keeping it fully integrated with the rest of your dashboard.
Is the assessment available in other languages?
Yes. Based on your browser's language setting, it's available in French, Dutch, Italian, Polish, German, and Swedish. Free-text notes you add yourself aren't translated.