FREE NIS2 CHECK

Are you affected by NIS2? Take the test.

Answer 3-4 short questions and receive an immediate initial assessment of your NIS2 applicability - specifically for healthcare institutions. Free of charge, with no registration required.

Question 1 of 3

Which type of organisation are you?

Choose the category that best describes your organisation.

Who is affected by NIS2?

Under NIS2, healthcare is classified as a sector of high criticality. Whether your facility is affected depends essentially on two criteria: its activity within the sector and the size of the organization.

Particularly important facilities

Large enterprises in the healthcare sector: 250 or more employees or over €50 million in turnover and over €43 million in balance sheet total - as well as all critical infrastructure (KRITIS) operators, e.g., hospitals with 30,000 or more fully inpatient cases per year.

Important facilities

Medium-sized enterprises in the healthcare sector: starting from 50 employees or over €10 million in turnover and balance sheet total. This includes many private clinics, care providers, medical care center (MVZ) groups, laboratories, and health-tech providers.

Not directly affected?

Smaller facilities often fall below the thresholds - but are increasingly being contractually obligated to implement cybersecurity measures as service providers or suppliers of affected facilities (supply chain security, § 30 BSIG).

These obligations apply to affected entities.

The NIS2UmsuCG has been in force since December 6, 2025 - with no transition period. The registration deadline with the BSI has already expired: anyone who has not yet registered should do so without delay.

§ 30 BSIG

Risk management: including awareness training, vulnerability management, incident handling, and supply chain security.

24/72h

Reporting obligations pursuant to Section 32 of the BSIG: Initial report within 24 hours, follow-up report within 72 hours, final report after 30 days.

§ 38 BSIG

Personal liability of management for the implementation of cybersecurity measures - including mandatory training.

Sources: NIS2UmsuCG / BSIG; BSI; Directive (EU) 2022/2555 (NIS2).

Frequently Asked Questions about the NIS2 Check

Are medical practices and medical care centers (MVZs) affected by NIS2?

Are medical practices and medical care centers (MVZs) affected by NIS2?

What is the difference between NIS2 and KRITIS?

What is the difference between NIS2 and KRITIS?

What penalties apply to violations?

What penalties apply to violations?

Is the result of this check legally binding?

Is the result of this check legally binding?

My facility is affected - what now?

My facility is affected - what now?

FREE RISK ASSESSMENT

30 minutes. An honest picture of your security posture.

Every conversation begins with a free risk assessment — 30 minutes, no obligation. You will then receive a written report with your cybersecurity maturity level, risk areas, and immediate measures.

FREE RISK ASSESSMENT

30 minutes. An honest picture of your security posture.

Every conversation begins with a free risk assessment — 30 minutes, no obligation. You will then receive a written report with your cybersecurity maturity level, risk areas, and immediate measures.

FREE RISK ASSESSMENT

30 minutes. An honest picture of your security posture.

Every conversation begins with a free risk assessment — 30 minutes, no obligation. You will then receive a written report with your cybersecurity maturity level, risk areas, and immediate measures.