NIS2 Readiness Check
Before you spend $50,000 on a full NIS2 implementation, check where you stand. NIS2 Readiness Check is a quick assessment: legal verification (do you fall under NIS2?), current state vs requirements gap analysis, and a concrete action roadmap. Clear answers without breaking the bank.

What is NIS2 Readiness Check?
NIS2 Readiness Check is a rapid 2-week assessment that answers two critical questions before you commit to a costly full NIS2 implementation: does your organization legally fall under the directive (Essential Entity, Important Entity, or out of scope), and if so, where are your specific gaps across the 10 NIS2 requirement areas? nFlo delivers a gap analysis report, an executive summary for the board, a prioritized implementation roadmap, and a cost estimate — so you invest in what is actually needed rather than a blanket €50,000+ project. With 70% of companies unsure of their NIS2 status, this diagnostic investment of $5,000-8,000 regularly saves organizations from unnecessary spending or from being caught unprepared for fines up to €10 million.
Don't know if NIS2 applies to you - and fines are up to EUR 10M
Clear answer in 2 weeks - without spending a fortune
Legal status
Do you fall under NIS2? Essential or Important?
Gap Analysis
Where you are vs where you need to be
Roadmap
What to do, in what order
“I don’t know if NIS2 applies to us - and I’m afraid to ask”
IT Director of a mid-sized manufacturing company: “I hear about NIS2 from everywhere. EUR 10 million fines. But when I ask lawyers, they say ‘it depends.’ When I ask consultants, they propose a $50,000 implementation. And I don’t even know if we fall under this regulation. 18 sectors, size thresholds, essential vs important… I need a simple answer, not a six-month project.”
Typical problems before NIS2 Readiness Check:
- You don’t know if your company falls under NIS2 (18 sectors, various thresholds)
- You’re afraid the consultant will “invent” problems to sell a bigger project
- You don’t want to spend $50k+ on implementation before knowing actual scope
- Board asks “how much will it cost?” - and you have no answer
- Deadline is approaching, and you’re still in “research” mode
Clear diagnosis in 2 weeks - no commitments
NIS2 Readiness Check is a quick initial assessment. We’re not selling you an implementation - we’re selling knowledge about whether you need one and to what extent. After 2 weeks you know exactly: (1) do you fall under NIS2, (2) where are your gaps, (3) how long and how much will it cost to close them.
What you get:
- Legal verification of NIS2 status (Essential/Important/Not in scope)
- Current security state assessment vs 10 NIS2 requirement areas
- Gap analysis - specific gaps with criticality rating
- Implementation roadmap with priorities and dependencies
- Implementation cost estimate (scope and costs)
- Executive summary for the board (1 page, no jargon)
- Results discussion session with recommendations
Who is this for?
NIS2 Readiness Check is for you if:
- You don’t know if your company falls under NIS2
- You want to know the scope of work before committing to a big project
- Board requires a business case and estimate before budget decision
- You already have “something done” (ISO 27001, policies) and want to know how much is missing
- You’d rather spend $5-8k on diagnosis than $50k on a “maybe needed” implementation
How it Works
Week 1: Qualification and Discovery
Day 1-2: Legal verification
- Company profile analysis (sector, size, revenue)
- Assessment if company meets NIS2 criteria
- Status determination: Essential Entity / Important Entity / Not in scope
- If not in scope - you get a report and save on implementation
Day 3-5: Discovery session (1 day on-site or remote)
- Interview with IT (infrastructure, security, backup)
- Interview with management (risk appetite, business priorities)
- Review of existing documentation (policies, procedures)
- Critical systems walkthrough
Week 2: Analysis and Report
Day 6-8: Gap Analysis
- Assessment vs 10 NIS2 requirement areas
- Maturity scoring (1-5) for each area
- Quick wins and critical gaps identification
- Mapping to existing controls (ISO 27001, other frameworks)
Day 9-10: Report and Roadmap
- Gap Analysis report (20-30 pages)
- Executive Summary (1 page for board)
- Implementation roadmap (Gantt with priorities)
- Estimated implementation costs
- Results discussion session (2h)
What’s in the Report?
1. NIS2 Legal Status
| Element | Result |
|---|---|
| Sector | Manufacturing (sector 11 - manufacturing) |
| Size | Medium enterprise (>50 employees) |
| Revenue | >EUR 10 million |
| NIS2 Status | Important Entity |
| Supervisory authority | National cybersecurity authority |
2. Gap Analysis - 10 NIS2 Areas
| NIS2 Area | Current | Required | Gap |
|---|---|---|---|
| 1. Risk management policies | 2/5 | 4/5 | High |
| 2. Incident management | 1/5 | 4/5 | Critical |
| 3. Business continuity (BCP/DR) | 3/5 | 4/5 | Medium |
| 4. Supply chain security | 1/5 | 3/5 | High |
| 5. Security in SDLC | N/A | N/A | Not applicable |
| 6. Control effectiveness assessment | 2/5 | 3/5 | Medium |
| 7. Basic cyber hygiene | 3/5 | 4/5 | Medium |
| 8. Cybersecurity training | 2/5 | 3/5 | Medium |
| 9. Cryptography and encryption | 3/5 | 4/5 | Medium |
| 10. HR security | 3/5 | 3/5 | OK |
3. Implementation Roadmap
Phase 1: Quick Wins (Month 1-2)
- MFA implementation for admins
- Incident reporting procedure to CSIRT
- Backup policy and recovery tests
Phase 2: Foundations (Month 3-6)
- Incident management system
- Security policies (complete set)
- Security awareness program
Phase 3: Maturation (Month 7-12)
- Vendor risk management
- Penetration testing and vulnerability management
- Continuous monitoring (SIEM/SOC)
4. Cost Estimate
| Element | Scope | Estimate |
|---|---|---|
| Documentation (policies, procedures) | 15 documents | $8,000 - $15,000 |
| Technical implementation (SIEM, VM) | Licenses + deployment | $25,000 - $50,000 |
| Training | Board + employees | $5,000 - $8,000 |
| vCISO / oversight (12 months) | Gold package | $120,000 - $192,000 |
| TOTAL | $158,000 - $265,000 |
Estimate only, final quote after detailed scoping
Why Start with Readiness Check?
Scenario A: Without Readiness Check
- You sign a contract for “NIS2 implementation” for $60,000
- After 2 months you find out you don’t fall under NIS2
- Or: you do fall under it, but already have 60% of requirements covered by ISO 27001
- You overpaid - but contract is signed
Scenario B: With Readiness Check
- You pay $5,000 for Readiness Check
- You find out you don’t fall under NIS2 → you save $60,000
- Or: you do fall under it, but gap is only 40% → implementation for $25,000 instead of $60,000
- You have full knowledge before making a decision
Pricing
Standard Readiness Check
For companies up to 200 employees:
- Legal status verification
- 1-day discovery session
- Gap analysis vs 10 NIS2 areas
- Implementation roadmap
- Cost estimate
- 2h results session
Time: 2 weeks Price: $5,000 - $8,000
Enterprise Readiness Check
For larger organizations or complex structures:
- Multiple locations/business units
- Extended discovery (2-3 days)
- Detailed technical review
- Multiple stakeholder interviews
- Board presentation
Time: 3-4 weeks Price from: $12,000
Related Glossary Terms
Learn more about key concepts related to this service:
Contact your account manager
Discuss NIS2 Readiness Check with your dedicated account manager.

How we work
Our proven service delivery process.
Qualification
Verification if your company falls under NIS2
Discovery
1-day session with IT, security, legal
Analysis
Current state vs 10 NIS2 requirement areas
Report
Gap analysis + roadmap + implementation estimate
Benefits for your business
What you gain by choosing this service.
Clarity
You know if you're in scope and what to do
Cost savings
Don't overpay for full implementation before knowing scope
Speed
2 weeks instead of 2 months of discovery
Prioritization
You know where to start
Related Articles
Expand your knowledge with our resources.
Cyber threat landscape 2026: a report for Polish companies in the NIS2 era
CERT Poland registered a record 260,783 incidents in 2025 (+152% YoY), and the amendment to the KSC act implementing NIS2 took effect on 3 April 2026. See what really threatens Polish companies and where to start preparing.
Read more →Essential Entity in Energy — a KSC/NIS2 Obligations Checklist and Key Deadlines
The energy sector falls under essential entities within the meaning of KSC/NIS2 — with the highest level of supervision and requirements. We have gathered the organisational, technical and reporting obligations into one practical checklist, along with the key deadlines from which it is worth planning your work.
Read more →NIS2 in the Energy Sector: From a "Paper Audit" to Real, Risk-Based Resilience
Meeting NIS2 requirements is not a completed checklist but a living risk-management programme. We explain how compliance "on paper" differs from real resilience and how a power utility should set priorities when not everything can be secured at once.
Read more →Frequently Asked Questions
Common questions about NIS2 Readiness Check.
How will I know if my company falls under NIS2?
As part of the Readiness Check, we verify your sector (18 NIS2 sectors), company size, and revenue. You receive a clear-cut answer: Essential Entity, Important Entity, or Not in scope - with legal justification.
How much does the NIS2 Readiness Check cost and how long does it take?
The Readiness Check costs from $5,000 and takes 2 weeks. In the first week, we conduct legal verification and a one-day discovery session; in the second week - gap analysis and a report with roadmap.
What if it turns out I don't fall under NIS2?
You receive a report with legal justification explaining why you are not in scope - you can present it to the board or auditors. You save on unnecessary implementation. This is one of the main reasons to start with a Readiness Check instead of a full project.
After the Readiness Check, do I have to purchase full implementation from you?
No. The Readiness Check is an independent service. You receive a report with a roadmap and estimate - you can implement on your own, with us, or with another provider. There is no lock-in.
We already have ISO 27001 - is NIS2 the same thing?
No, but ISO 27001 covers a significant portion of NIS2 requirements. The Readiness Check will show you exactly which areas you already have covered and how much work remains - typically, companies with ISO 27001 have 40-60% of NIS2 requirements fulfilled.