EU · NIS2 Free scan + organizational questionnaire

Discover your visible cyber risks and basic NIS2 readiness.

Combine a public domain scan with a short questionnaire to get a clear picture of where you stand — without installing anything, signing contracts, or running a full audit.

https://
No signup for scan 5-minute setup GDPR-compliant
TLS configured
Scanning 8 categories
selfcheck.eu / live
Scanning
acme-logistics.eu DEPTH · DEEP
SPF record present PASS
DMARC policy not enforced REVIEW
TLS 1.3 supported PASS
HSTS header missing FAIL
/wp-admin exposed REVIEW
Cookie banner detected PASS
68
NIS2 Selfcheck score
Moderate — review needed
Built for the EU · trusted by
The journey

From unknown exposure to a clear roadmap.

The NIS2 Selfcheck follows a simple, transparent path. Each step builds on the previous one and gives you something useful in return.

01

Scan & answer

Enter your domain and complete a short 12-question survey. The public scan runs in parallel — no installation, no internal access required.

~5 minutes
02

Receive your basic report

A free report delivered by email with your overall NIS2 score, top three technical findings and top three organizational attention points.

Free · within minutes
03

Improve & re-scan

Optionally request a paid detailed report, a remediation package or ongoing monitoring. Re-scan anytime to prove measurable improvement.

Optional follow-up
Eight scan categories

Everything an attacker can see, before they see it.

The public domain scan reviews eight categories of visible technical risk and combines those results with your questionnaire answers for full context.

Email security

SPF, DKIM, DMARC and MX configuration to prevent spoofing and invoice fraud.

SPF · DKIM · DMARC

TLS / SSL

Certificate validity, expiry windows and protocol strength for trusted connections.

TLS 1.2+ · HSTS

HTTP headers

CSP, X-Frame-Options, Referrer-Policy and other browser protection headers.

CSP · XFO · HSTS

Technical hygiene

DNS records, redirects, deprecated services and other configuration cleanliness.

DNS · MX · CNAME

Cookie & privacy

Cookie banners, tracking scripts and privacy policy visibility on your domain.

GDPR signals

Attack surface

Open ports, exposed services, subdomains and forgotten test environments.

Ports · Subdomains

Technology stack

CMS, server software and framework versions visible to outside observers.

CMS · Server · JS

Admin exposure

Publicly accessible login portals, admin panels and management interfaces.

/wp-admin · /login
Try the experience

See what a real Selfcheck looks like.

Walk through a sample scan and questionnaire — no email required, no data stored. The full flow takes under a minute.

Let's start with your domain

We only scan publicly visible information. Nothing intrusive, no login attempts, no exploits.

https://
Step 1 of 4

Tell us about your organization

A few quick questions to interpret your scan results in context. The full questionnaire has 12 questions — we'll show you three here.

Step 2 of 4

Scanning acme-logistics.eu

Checking publicly visible information across all eight categories…

Your NIS2 Selfcheck result

For acme-logistics.eu — sector: Logistics · scanned just now

68
/ 100

NIS2 Selfcheck score

Moderate — review needed

Technical scan 72 / 100
8 categories · 4 issues found
Organizational readiness 63 / 100
12 questions · 3 attention points
Questionnaire confidence High
Based on 12 of 12 answers

Top findings

3 of 7 shown · upgrade for full report
High
DMARC policy not enforced
Your domain has DMARC but the policy is set to p=none — attackers may impersonate your email.
Medium
HSTS header missing
Browsers are not instructed to force HTTPS, leaving room for downgrade attacks on first connection.
Medium
Backups not tested regularly
You indicated backups are made but not tested. Recovery may fail during a real incident.

Want the full picture?

Get the detailed report with all findings, evidence, business impact and a step-by-step remediation plan.

View detailed report
Done
Packages

Start free, scale as you need.

Six packages cover the full journey — from first scan to ongoing monitoring. Choose what fits and combine packages as needed.

Entry · Free

Free Selfcheck

€0 / one-time

Domain scan + 12-question survey + basic report by email. The starting point.

  • Public scan across 8 categories
  • Basic NIS2 questionnaire
  • Overall + sub-scores
  • Top 3 findings + attention points
Start scan
Quick wins

Technical Quick Wins

€750 / package

We fix the most urgent technical issues found in the scan. Fast, measurable improvement.

  • SPF / DKIM / DMARC fixes
  • Security headers & HTTPS redirects
  • Admin exposure reduction advice
  • Free re-scan & proof report
Request quote
Remediation

Full Technical Support

From €2,400 / project

Hands-on remediation across email, web, admin and attack surface — from diagnosis to validation.

  • Email security hardening
  • Website TLS + header hardening
  • Attack surface reduction
  • Proof-of-improvement re-scan
Talk to us
Advisory

Readiness Consultation

€450 / session

A 90-minute expert session walking through your results and a roadmap for improvement.

  • Detailed report walkthrough
  • Organizational gap discussion
  • Prioritized roadmap
  • Optional follow-up advice
Book a session
Monitoring

Continuous Monitoring

€89 / month

Recurring scans, change alerts and periodic questionnaire refreshes. Stay ahead, not behind.

  • Monthly or quarterly scans
  • Change & expiry alerts
  • Score history & trend reports
  • Optional advisory calls
Subscribe
The detailed report

A report your management will actually read.

Plain-language explanations, branch-specific context and concrete next steps — designed so leadership, IT and external suppliers can act on it together.

  • Management summary — a one-page overview suitable for board reporting.
  • Evidence per finding — exact DNS records, header values and configuration snippets.
  • NIS2 relevance — why each finding matters for your readiness, in plain language.
  • Step-by-step remediation — concrete actions with estimated effort and priority.
  • Branch-specific prioritization — risks weighed against your sector and dependencies.
NIS2
Selfcheck
Report
NIS2 Selfcheck
REPORT · 2026-05-26
Detailed Readiness Report
acme-logistics.eu · Sector: Logistics · 14 pages
68
Overall
72
Technical
63
Organizational
Top Findings
DMARC policy not enforced HIGH · email
HSTS header missing MED · web
Backups not tested regularly MED · org
CMS version exposed in headers LOW · stack
Why the NIS2 Selfcheck

Built for clarity, designed for action.

What separates the Selfcheck from a generic security scanner.

01

Scan + context, not just data

Public technical evidence is combined with organizational context from the questionnaire. The same finding can be low or critical depending on your sector and dependencies — and we treat it that way.

02

Plain language, board-ready

Every finding is explained in plain language, with its business impact and NIS2 relevance. No jargon walls. Reports are designed for both IT teams and non-technical decision-makers.

03

From insight to improvement

The Selfcheck doesn't stop at identifying risks. Remediation packages, advisory sessions and re-scans turn diagnosis into measurable improvement — at your pace.

04

Honest about limits

The Selfcheck does not certify NIS2 compliance, replace a legal audit or run penetration tests. We say so up front — and explain exactly what the service does and doesn't cover.

05

EU-first, GDPR-aligned

Built for European organizations from day one. No data leaves the EU, all processing is GDPR-aligned and the questionnaire is sector-aware for European business realities.

06

Measurable progress

Every improvement can be re-scanned and proven with a before-and-after report — useful for management updates, supplier discussions and internal documentation.

Sectors served

Tailored to your industry context.

Findings are weighed and prioritized against the realities of your branch — because a CMS version exposure is not the same risk for a hospital and a print shop.

Healthcare
Logistics
Manufacturing
Professional services
Financial
Retail
Construction
Education
IT & software
Energy
Agriculture
Government
Frequently asked

Honest answers, no fine print.

If something isn't here, just ask. We'd rather over-explain than overpromise.

No. The Selfcheck is a readiness indication based on publicly visible technical evidence and your questionnaire answers. It does not replace a legal or organizational NIS2 compliance assessment, and we say so clearly on every report.
Eight categories: email security (SPF/DKIM/DMARC), TLS/SSL, HTTP security headers, technical hygiene, cookie & privacy signals, attack surface, technology stack and admin exposure. Only publicly visible information — no logins, exploits or intrusive testing.
No. Everything the scan needs is publicly accessible. You provide your domain and answer 12 questions. The basic report arrives by email — typically within minutes.
All data is processed and stored within the EU and handled in line with GDPR. You can request deletion at any time. The free scan stores your domain, contact details, questionnaire answers and scan results for the purposes described in our privacy policy.
The free report gives you your scores, the top three technical findings and the top three organizational attention points. The detailed report adds full technical evidence, branch-specific prioritization, NIS2 relevance per finding and a step-by-step remediation plan with estimated effort.
Yes. The Quick Wins and Full Technical Support packages cover the most common remediation work — email security, web hardening, admin exposure reduction and attack surface reduction. Every remediation engagement ends with a re-scan and proof-of-improvement report.
Ready when you are

Find out what your domain says about your cybersecurity posture.

Free scan. No commitment. Results in minutes. The first step is always the easiest.

https://