Cybervize
Free of charge, 30 minutes, no software demo

Where do we stand? A focused assessment in 30 minutes

Where do we stand? In 30 minutes we give you an indicative assessment of your NIS-2 applicability, the five most important gaps and a clear next step. Financial firms, for which DORA is the leading regime, have a session of their own: the DORA classification. The binding legal assessment remains the task of a specialised law firm.

The vCISO in detail

What happens during the 30 minutes

We work along the statutory NIS-2 criteria (sector, size, thresholds) and the ten minimum measures from § 30 of the German BSI Act. No slides, no tool demo, no sales pitch.

  1. 1
    Min. 0 to 5

    Context and key data

    You tell us about your industry, size, sites, prior experience with ISO 27001 or similar standards, and which concrete NIS-2 question is on the table.

  2. 2
    Min. 5 to 15

    Indicative NIS-2 classification

    We check sector match (Annexes 1 and 2 of the German BSI Act), the size and revenue thresholds, and place you indicatively as likely essential, important or not affected. With reasoning. The legally binding assessment remains a matter for counsel.

  3. 3
    Min. 15 to 25

    Top 5 gaps from the minimum measures

    We run through the ten NIS-2 minimum measures (risk management, incident handling, business continuity, supply chain, access controls, cryptography, personnel, awareness, vulnerability management, effectiveness evaluation) at pace and go deeper on the five with the most open ground for your organisation. A full evaluation of all ten is what the gap assessment delivers, not this session.

  4. 4
    Min. 25 to 30

    Path recommendation and cost estimate

    We name the suitable next step: a vCISO mandate for organisations without an in-house CISO function, a NIS-2 gap assessment, or a platform onboarding project for organisations with an in-house CISO. Plus a cost estimate as a range, depending on size and number of sites.

What you take away from the call

You receive the substance of the call in writing, one page, in a form you can use further with management, IT leadership or your legal counsel.

Indicative NIS-2 classification

Sector match, size and threshold indicator, indicative classification likelihood (likely essential, important or not affected), with reasoning and a note that the legally binding assessment remains a matter for counsel.

Top 5 gaps from the NIS-2 minimum measures

The five most relevant open items from the ten minimum measures per § 30 of the German BSI Act, with a brief reasoning per item.

Path recommendation

Which next step makes economic sense: vCISO mandate, NIS-2 gap assessment or platform onboarding project. If none of the three fits, we say so.

Cost estimate as a range

Rough range in euros and weeks, depending on company size, number of sites and internal availability. Not a fixed-price quote, but a planning figure.

Expert pre-assessment, not legal advice

We deliver an expert assessment based on the statutory NIS-2 criteria. The legally binding evaluation of your status under NIS-2 is a matter for a law firm with an IT-security-law focus. In our experience, the legal advice becomes more targeted and cheaper if you bring our pre-work to the conversation.

Who should ideally join the call

The risk check works with one person on the line but is markedly more productive with two or three roles at the table. You can invite colleagues after booking.

  • Management board

    Decides on investments, carries legal responsibility for NIS-2 obligations and needs a clear statement on the next step.

  • IT lead or CIO

    Knows the actual IT architecture, supplier relationships and prior work. Without that view the gap assessment stays superficial.

  • Compliance, data protection or quality management

    If present. These roles know whether ISO 27001, TISAX or other standards are already running and where duplicate work can be avoided.

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT

Frequently asked questions about the NIS-2 risk check

No. We deliver an expert pre-assessment based on the NIS-2 criteria. The legally binding evaluation of your NIS-2 status is a matter for a law firm with an IT-security-law focus. Most clients arrive better prepared at the legal conversation if they bring our note.

Nothing. The call is free and non-binding, 30 minutes by video or phone. The written summary afterwards is also free of charge.

Directly bookable online, free slots typically in the current or coming week. For acute pressure (auditor deadline, board meeting, customer enquiry) please note this in the booking comment and we will try for a tighter slot.

That is exactly the question the risk check exists for. The NIS-2 thresholds run at 50 employees, or at an annual turnover and a balance sheet total of more than 10 million euros each, in the sectors of Annexes 1 and 2 of the German BSI Act. Being a supplier to an affected company does not make you subject to NIS-2 yourself, but the requirements reach you through your contracts. We assess that during the call.

A maintained ISMS covers many NIS-2 minimum measures, but not all. Reporting obligations (24-hour initial report, 72-hour follow-up), supplier risks and management accountability are more specific under NIS-2 than under ISO 27001. In the risk check we clarify what you can carry over from the ISO scope and where NIS-2 adds requirements.

Yes. Whoever sits in a NIS-2 supply chain increasingly receives requirements passed down from customers (contract annexes, security audits, reporting obligations). In the risk check we clarify which requirements typically travel through the supply chain and how you can prepare without overspending.

30 minutes, free of charge, no software demo

You book a slot, we prepare for your industry. Management and IT leadership should ideally both attend. After the call we send you the one-page summary by email.

Book the risk check

Conducted by a Senior CISO from Cybervize.

Not ready for a call yet? 5-minute self-assessment maturity check · Or get the overview first: the journey in 5 stations