Cybervize
Free, 5 minutes, no signup

NIS-2 maturity check: where do you stand on the ten §30 BSIG measures?

The official BSI check answers the question Whether. This check answers the question How far. 30 compact questions, three per measure, with an instant traffic-light evaluation, stated answer coverage and a list of your biggest gaps. Detailed evaluation optionally by email.

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT

30 questions, 10 measures

Three questions per measure: 29 implementation questions under §30 BSIG plus one reporting-process question under §32 BSIG. Scale: implemented, partial, not, unknown.

Instant traffic light

Per measure green, yellow or red. Plus overall maturity with answer coverage and a list of your biggest gaps.

Email-only

Detailed evaluation with 90-day roadmap optional via business email. No newsletter, no mandatory phone field.

Note on scope

This check assesses the implementation depth of your cybersecurity measures along the ten NIS-2 areas from §30 BSIG. It does not replace the official BSI applicability check, which answers the question Am I subject to NIS-2 at all? A legally binding assessment remains reserved for a specialised law firm.

0 of 30 questions answered

Measure 1 of 10 · §30(2) no. 1

Risk management

There is a documented methodology for assessing cybersecurity risks (for example ISO 27005).

Risks are recorded in a current risk register with owners and a treatment plan.

Risk management is reviewed at least annually and reported to executive management.

Measure 2 of 10 · §30(2) no. 2

Incident handling

A documented incident response plan with escalation paths is in place.

The 24- and 72-hour reporting obligations to the BSI (§ 32(1) BSIG) are organisationally in place.

Incidents are recorded centrally and systematically reviewed after each incident.

Measure 3 of 10 · §30(2) no. 3

Business continuity (BCM)

A documented business continuity and disaster recovery concept is in place.

Backups are separated following the 3-2-1 principle and tested for recoverability at least annually.

Crisis team and recovery exercises take place at least once a year.

Measure 4 of 10 · §30(2) no. 4

Supply chain security

A current list of critical suppliers with a security risk classification exists.

Security requirements are contractually anchored (audit rights, reporting duties, minimum measures).

The security status of suppliers is reviewed at least annually.

Measure 5 of 10 · §30(2) no. 5

Procurement, development and maintenance

Security requirements are an integral part of procurement and development processes.

Vulnerabilities are detected across the lifecycle (for example SAST/DAST, SBOM, pen tests).

Patch and update processes are documented and consistently executed.

Measure 6 of 10 · §30(2) no. 6

Effectiveness assessment

Security measures are backed by effectiveness indicators (KPI / KRI).

There is a recurring effectiveness review (internal or external).

Results feed back into the risk assessment and are reported to management.

Measure 7 of 10 · §30(2) no. 7

Training and awareness

All employees complete a security training at least once a year.

Phishing simulations or comparable exercises take place regularly.

Training status and lessons learned from incidents are documented and included in reports.

Measure 8 of 10 · §30(2) no. 8

Cryptography

A cryptography policy defines binding rules for algorithms, key lengths and lifecycle.

Confidential data is encrypted in transit (TLS 1.2 or higher) and at rest.

Key management is separated from the data and documented.

Measure 9 of 10 · §30(2) no. 9

Personnel security, access control, asset management

Joiner-mover-leaver processes are formally defined and followed.

Privileged access is managed separately (PAM or equivalent) and reviewed.

A current asset inventory (IT, OT, data) exists and is maintained.

Measure 10 of 10 · §30(2) no. 10

MFA and secure communication

MFA is mandatory for all administrative and remotely accessible accounts.

Communication services (email, video, chat) are hardened to the current state of the art.

Emergency communication channels are available separately from the regular network.

Please answer all 30 questions. Missing: 30.

Boundary versus the BSI check and legal advice

This maturity check does not replace the official BSI applicability check nor a legally binding assessment by a specialised law firm. It provides an indicative view of how far your cybersecurity measures are implemented along the ten areas in §30(2) BSIG. One question covers organisational reporting readiness; the 24- and 72-hour deadlines themselves are set out in §32(1) BSIG, and the question cites that source. Whether you are within NIS-2 scope at all is shown by the BSI check. What exactly needs doing is something we work out in an intro call. Whether you are legally in scope is for a law firm to confirm.

Open the official BSI check

Book an intro call