NIS2SelfCheck
NIS2 Public scan plus business questionnaire
External cyber readiness

Discover your organization's cybersecurity readiness.

Get a fast first view of your external cyber risk, visible security gaps, and NIS2 readiness so you can see where your organization may need attention.

https://

Next, you will answer 5 short questions. Then the scan will start. After that, you can optionally add a little more context before viewing your report.

This is a fast passive self-check for indication only. It is designed to explain what public signals suggest, why they matter for NIS2 readiness, and what should be reviewed next.

No login attempts Results in minutes PDF by email
NIS2SelfCheck live preview
Live
Target domain yourcompany.eu
Email authentication checked
! HTTP security headers review
TLS and certificates checked
! Attack surface exposure review
NIS2 questionnaire context ready
Readiness snapshot
Technical plus organizational view
Built for practical review
Why this is useful

More than a free domain check.

This self-check does not try to be a penetration test. It adds business context, NIS2 relevance, evidence language, and a practical next-step view around the same public signals.

01

Business context

The questionnaire adds sector, size, and operational dependency context so the report can explain why a finding matters to your organization.

02

Clear next steps

The report translates public findings into an owner, a likely effort level, and a concrete next action instead of stopping at a raw scan result.

03

NIS2 relevance

Each major issue is framed in terms of external evidence, likely impact, and what still needs internal validation before treating it as a compliance conclusion.

Testimonials

Trusted by organizations that value practical security insight.

See how teams use NIS2SelfCheck as a starting point for external risk visibility and follow-up action.

"Clear scan with practical recommendations. Within minutes, we knew where the main risks were."
A. Software company, Amsterdam
"Fast, clear and actionable. A useful first step toward better security and NIS2 readiness."
J. Cybersecurity company, Milan
How it works

Fast input. Clear output.

The flow is simple: enter your domain, answer 5 quick questions, let the scan run, and then optionally add more context before viewing your report.

01

Enter your domain

Use the main domain your customers and staff rely on. No installation or credentials required.

Start point
02

Answer 5 quick questions

We collect just enough context to make the results more relevant without slowing you down.

NIS2 context
03

View your report

After the scan, you can optionally answer a few more questions before opening the report and receiving the PDF by email.

Actionable output
What we scan

Eight public-facing checks that matter.

Coverage stays aligned with the existing backend logic and report output.

Email security

SPF, DKIM and DMARC posture for public email trust signals.

🔒

TLS and certificates

Certificate validity and visible transport security basics.

🌐

HTTP hardening

Security headers and web-facing hardening signals.

Attack surface

Subdomains, exposed admin paths and public footprint clues.

🧩

Technology stack

Visible software and stack-related exposure indicators.

🍪

Cookie signals

Public privacy and consent behavior from the website itself.

🛡

Admin exposure

Visible administrative endpoints and access hygiene indicators.

📋

NIS2 readiness context

Questionnaire input and sector/size context carried into the assessment.

Try the experience

See what a real NIS2SelfCheck looks like.

Walk through the same flow your users follow: domain, questionnaire, scan, and report. No email required, no data stored.

Let's start with your domain

We only scan publicly visible information. Nothing intrusive, no login attempts, no exploits.

https://
Step 1 of 4Estimated time: 3 minutes

Tell us about your organization

The real questionnaire is longer. This demo shows a representative sample using the same content and thresholds as the current self-check.

Step 2 of 4NIS2 context included

Scanning example-it.eu

Checking publicly visible information across the current self-check categories.

Your NIS2SelfCheck result

For example-it.eu in IT / software / digital services.

68
Overall Security Score
Combined technical and organizational baseline
Technical scan score 64 / 100
Questionnaire score 72 / 100
NIS2 applicability Potentially in scope as an essential entity in ICT Service Management

Top findings

  • DMARC policy is not fully enforced, leaving room for stronger email spoofing protection.
  • Several HTTP security headers need review on the public website.
  • Backup testing is not performed regularly according to the questionnaire response.
Step 4 of 4Web report plus PDF by email in the real flow
Services

Start with NIS2SelfCheck, expand only if needed.

Use the pricing style from the new frontend as a clear follow-up path, while the current free NIS2SelfCheck flow stays intact.

Included now

NIS2SelfCheck Free

EUR 0per scan

Domain scan, questionnaire, immediate web results, and the basic PDF report by email.

  • Public scan across 8 categories
  • NIS2 questionnaire context
  • Overall score plus sub-scores
  • Top findings and attention points
  • PDF by email
Start free scan

Technical Quick Wins

EUR 750package

Fast remediation of the most urgent technical issues found in the scan.

  • SPF, DKIM and DMARC fixes
  • Security headers and HTTPS redirects
  • Admin exposure reduction advice
  • Free re-scan and proof report
Request quote
Contact

Request a service.

Use one form for every paid service. We will reply based on the package you select.

How it works

Tell us which service you need and how to reach you.

Your request goes to the Optimaize team. We use the selected service to route the request properly, whether you want remediation support, an expert session, or recurring monitoring.

  • Service interest is prefilled from the pricing section
  • Optional domain helps us prepare the conversation
  • Message field can include timing, scope, or priorities
  • We reply personally via info@optimaize.io
EUR 750 package
Best for a limited number of practical technical fixes from the scan.
May include the paid full report after intake and scope confirmation.
FAQ

Questions that usually come up first.

Clear answers on what the NIS2SelfCheck does, what it does not do, and what happens next.

No. The NIS2SelfCheck is a readiness indication based on publicly visible technical evidence and your questionnaire answers. It does not replace a legal or organizational NIS2 compliance assessment.
Eight categories: email security (SPF, DKIM, DMARC), TLS and SSL, HTTP security headers, technical hygiene, cookie and privacy signals, attack surface, technology stack, and admin exposure. Only publicly visible information is used.
We look at information that is visible from the outside, such as DNS records, TLS certificates, web security headers, exposed subdomains, visible software indicators, and publicly reachable admin-related paths. We do not log in, bypass controls, or perform intrusive testing.
No. You provide your domain and answer the questionnaire. The scan only uses publicly accessible information and the report typically arrives within minutes.
The report flow stores your domain, contact details, questionnaire answers, and scan results for the service. The frontend language states that data is processed and stored within the EU and handled in line with GDPR.
Continuous Monitoring is a follow-up service for organizations that want regular visibility after the first scan. It can include recurring scans, alerts for important changes or expiries, score history, and periodic reviews so you can track whether your external security posture is improving over time.
The free report gives you your scores, the top technical findings, and the main organizational attention points. The detailed report adds full technical evidence, branch-specific prioritization, NIS2 relevance per finding, and a step-by-step remediation plan.
Optimaize is the company behind NIS2SelfCheck. It provides the platform, handles follow-up requests, and offers practical support such as expert review sessions, remediation guidance, and recurring monitoring for organizations that want help after the scan.
Yes. The Quick Wins and Full Technical Support packages cover common remediation work such as email security, web hardening, admin exposure reduction, and attack surface reduction, followed by a re-scan.
Ready when you are

See what your domain says about your cybersecurity posture.

Free scan. No commitment. Results in minutes.

Start free scan