Free tool · Checklist

Are you ready for NIS2?

Check what's already in place. Get your readiness level and the points to close first.

Check the measures already in place in your organization:

0% covered

Get your NIS2 report

Your detailed level and the compliance roadmap, by email.

Your gaps to close

Each gap leads to the solution that closes it.

Method

Who this checklist is for

NIS2 is a European directive: it does not directly apply to a Quebec SME with no ties to the EU. The checklist reuses its 10 requirements because they describe good practice for a mature organization, not because the law targets you.

Three situations where NIS2 genuinely concerns you: you supply services to a company or subsidiary subject to NIS2 in Europe (their supplier compliance obligations extend to you) ; you operate a subsidiary or legal entity in the EU ; or you're benchmarking your controls against a stricter framework than Quebec's Law 25, anticipating that regulation here often follows European standards a few years later.

If none of these apply to you, the result is still useful as a maturity indicator — the 10 points cover governance, risk management, detection, continuity and supply-chain security, the same pillars as Law 25 and most cyber-insurance frameworks, worded differently.

The percentage shown is a simple ratio (measures checked / 10), not a legal compliance assessment. Real NIS2 compliance requires a review by legal counsel and a formal assessment by the relevant EU authorities.

FAQ

Frequently asked questions

Is a Quebec SME subject to NIS2?

In most cases, no — NIS2 is a European Union directive. It can concern you indirectly if you supply a European entity subject to it, or if you operate a subsidiary in the EU.

Why use a NIS2 checklist if it doesn't apply to me?

Because its 10 requirements describe a mature cybersecurity organization, independent of the legal framework. It's a maturity test, not a compliance test.

Does this replace a Law 25 assessment?

No, these are two distinct frameworks. Quebec's Law 25 has its own requirements — use our ISO 27001 checklist or talk to an expert for a Law 25 assessment.