Does NIS2
apply to you?

An estimated 160,000 European entities are in scope. Most of them don't know it yet.
This page is the short version: what NIS2 requires, how to find out where you stand, and which requirements Stoïk's 360° approach helps you cover.

Let's get the uncomfortable part out of the way.

Before any product argument, two things need to be clear about what NIS2 is and about what an insurer can and cannot do for you.

What NIS2 actually is.

The EU's revised cybersecurity directive. It replaces NIS1 and widens formal cybersecurity obligations from roughly 1,500 entities to an estimated 160,000.

Two types of entities

A directive, not a regulation.

NIS2 was published at EU level on 27 December 2022. Because it is a Directive, each Member State must transpose it into national law, and the only legal source of truth is always the national transposed law.

  • ItalyTransposed — October 16, 2024In force
  • BelgiumTransposed — October 18, 2024In force
  • GermanyTransposed — December 6, 2025In force
  • NetherlandsTransposed — August 15, 2026In force
  • AustriaAdopted, not yet in force — October 1, 2026Adopted
  • FranceBefore ParliamentNot transposed
  • SpainDraft billNot transposed

Status as of August 31, 2026. Member States can adapt the content of the directive when transposing it, so scope and detail vary by country. Some deadlines run from the date an entity is identified rather than a single national date.

For almost every company, NIS2 collapses into three questions.

Strip away the legal vocabulary and this is what a management team actually needs to answer.

Am I in scope for NIS 2?

Answer a few questions to find out whether the NIS 2 directive applies to your organisation, and which compliance areas concern you.

Question 1 / 3

How many people does your company employ?

This self-assessment gives you a quick view of where you stand on NIS 2. It is not a compliance audit, nor evidence your national supervisory authority would accept. Real compliance requires documented evidence and expert advice. This tool is indicative only.

Compliance check: Three questions, one screen.

The Compliance Check module is free for every Stoïk insured, inside Stoïk Protect. It is a self-assessment, not an audit or a legal opinion, and it is not evidence opposable to any national authority. NIS2 is one of several compliance frameworks it covers.

Five pillars. Each one maps to different NIS2 requirements.

This is why the coverage above is possible. Stoïk is Europe's first cyber MGA, so insurance, cybersecurity and an in-house CERT sit under one roof instead of three vendors to coordinate.