NIS2 Quick Check
NIS2 Readiness

Structured assessment of your technical and organisational readiness

NIS2 Quick Check

NIS2 requirements increasingly reach mid-market organisations, often for the first time. The Quick Check delivers a substantiated assessment of your technical and organisational readiness and a prioritised action path – without the overhead of a full compliance programme.

What this check is — and is not

The NIS2 Quick Check is a technical and organisational readiness assessment. We evaluate where your organisation stands against the core NIS2 requirement areas and prioritise the gaps by risk and effort.

The check does not constitute legal advice. For legal edge cases and detailed regulatory assessments, Blackfort Technology cooperates with specialised law firms where required.

What we assess

The assessment covers the areas where the technical and organisational obligations sit:

  • Asset visibility — inventory, ownership, critical systems
  • Vulnerability and patch management
  • Logging and monitoring
  • Incident detection and response capability
  • Backup, recovery and business continuity
  • Administrator protection and privileged access
  • MFA and access control
  • Security governance — roles, responsibilities, reporting lines
  • Technical security measures against the current threat landscape
  • Supply chain and third-party risk
  • Evidence and provability for internal and external audits
  • Incident response capability

Methodology and tooling

Structured collection matrix — a proven question catalogue that maps the core NIS2 requirement areas against operational reality.

Mapping against existing controls — where your organisation already operates under ISO 27001, TISAX or BSI IT-Grundschutz, we reuse existing evidence rather than duplicating work.

Operational, not formal — the report is built for executable next steps, not for maturity scoring alone.

What you receive after the check

The report is written as a basis for executive decision-making and shows a clear operational path for the next steps.

  • Structured readiness indication with rationale (all tiers)
  • Top-10 gap view against the core NIS2 requirement areas (Gap, Roadmap)
  • Mapping of existing controls from ISO 27001 / TISAX / BSI
  • Prioritised action catalogue with risk and effort
  • 12-month implementation roadmap (Roadmap)

Phases

1½ day

Scoping

Sector, size, existing certifications, tier selection

21–2 days

Data collection

Workshops, document review, targeted technical samples

32–4 days

Analysis

Readiness and gap evaluation, prioritisation

41 day

Report & walkthrough

Delivery + workshop

Report typically within 10 business days after data collection is complete.

Pricing

Tier selected by depth of insight required.

Indication

Rapid readiness indication across the core requirement areas

from €2,900

Gap

Plus top-10 gap analysis and prioritised actions

from €4,900

Roadmap

Plus 12-month implementation roadmap with effort estimates

from €8,500

Indicative figures; final fixed price after scoping call.

Frequently asked questions

Is the Quick Check legal advice?

No. We assess your technical and organisational readiness. For legal edge cases and detailed regulatory assessments, Blackfort Technology cooperates with specialised law firms where required.

We are ISO 27001 certified — do we still need the check?

Often yes. ISO 27001 covers a large share of the NIS2 requirement areas, but is not equivalent. We map your existing controls and identify the areas where NIS2 demands additional operational steps.

How early should we run the check?

As early as possible. A Quick Check rapidly establishes a basis for decision and avoids a wait-and-see posture in which operational measures are delayed.

What happens after the Quick Check?

You have a substantiated basis for decisions. Common follow-ups: NIS2 implementation programme, external CISO / ISB, ISO 27001 ISMS, or targeted technical hardening engagements.

Roadmap or Gap — which tier should we choose?

If you intend to move into implementation directly after the check and need a 12-month budget basis, Roadmap is the right tier. If you first want clarity, Gap is sufficient.

How authoritative is the report?

The report does not make legally binding statements, but it is methodologically traceable and serves as a basis for internal risk and investment decisions, audit preparation, and alignment with specialised law firms.

Kontakt aufnehmen

Let's clarify where your organisation stands today.

A scoping call is enough to choose the right tier. No commitment up front.