The official BSI check answers the question Whether. This check answers the question How far. 30 compact questions, three per measure, with an instant traffic-light evaluation, stated answer coverage and a list of your biggest gaps. Detailed evaluation optionally by email.
Three questions per measure: 29 implementation questions under §30 BSIG plus one reporting-process question under §32 BSIG. Scale: implemented, partial, not, unknown.
Per measure green, yellow or red. Plus overall maturity with answer coverage and a list of your biggest gaps.
Detailed evaluation with 90-day roadmap optional via business email. No newsletter, no mandatory phone field.
Note on scope
This check assesses the implementation depth of your cybersecurity measures along the ten NIS-2 areas from §30 BSIG. It does not replace the official BSI applicability check, which answers the question Am I subject to NIS-2 at all? A legally binding assessment remains reserved for a specialised law firm.
0 of 30 questions answered
Measure 1 of 10 · §30(2) no. 1
There is a documented methodology for assessing cybersecurity risks (for example ISO 27005).
Risks are recorded in a current risk register with owners and a treatment plan.
Risk management is reviewed at least annually and reported to executive management.
Measure 2 of 10 · §30(2) no. 2
A documented incident response plan with escalation paths is in place.
The 24- and 72-hour reporting obligations to the BSI (§ 32(1) BSIG) are organisationally in place.
Incidents are recorded centrally and systematically reviewed after each incident.
Measure 3 of 10 · §30(2) no. 3
A documented business continuity and disaster recovery concept is in place.
Backups are separated following the 3-2-1 principle and tested for recoverability at least annually.
Crisis team and recovery exercises take place at least once a year.
Measure 4 of 10 · §30(2) no. 4
A current list of critical suppliers with a security risk classification exists.
Security requirements are contractually anchored (audit rights, reporting duties, minimum measures).
The security status of suppliers is reviewed at least annually.
Measure 5 of 10 · §30(2) no. 5
Security requirements are an integral part of procurement and development processes.
Vulnerabilities are detected across the lifecycle (for example SAST/DAST, SBOM, pen tests).
Patch and update processes are documented and consistently executed.
Measure 6 of 10 · §30(2) no. 6
Security measures are backed by effectiveness indicators (KPI / KRI).
There is a recurring effectiveness review (internal or external).
Results feed back into the risk assessment and are reported to management.
Measure 7 of 10 · §30(2) no. 7
All employees complete a security training at least once a year.
Phishing simulations or comparable exercises take place regularly.
Training status and lessons learned from incidents are documented and included in reports.
Measure 8 of 10 · §30(2) no. 8
A cryptography policy defines binding rules for algorithms, key lengths and lifecycle.
Confidential data is encrypted in transit (TLS 1.2 or higher) and at rest.
Key management is separated from the data and documented.
Measure 9 of 10 · §30(2) no. 9
Joiner-mover-leaver processes are formally defined and followed.
Privileged access is managed separately (PAM or equivalent) and reviewed.
A current asset inventory (IT, OT, data) exists and is maintained.
Measure 10 of 10 · §30(2) no. 10
MFA is mandatory for all administrative and remotely accessible accounts.
Communication services (email, video, chat) are hardened to the current state of the art.
Emergency communication channels are available separately from the regular network.
Please answer all 30 questions. Missing: 30.
This maturity check does not replace the official BSI applicability check nor a legally binding assessment by a specialised law firm. It provides an indicative view of how far your cybersecurity measures are implemented along the ten areas in §30(2) BSIG. One question covers organisational reporting readiness; the 24- and 72-hour deadlines themselves are set out in §32(1) BSIG, and the question cites that source. The question Am I within NIS-2 scope is answered by the BSI check; the question What exactly do I have to do is answered by legal review.
Open the official BSI check