Skip to content
deveca GRC
Free self-assessment

Are you in scope of NIS2?

The NIS2 Directive, implemented in Germany through the revised BSI Act, obliges tens of thousands of organisations to manage risk, report incidents, and provide evidence. Find out in 2 minutes whether that includes you.

An assessment in 2 minutes

Answer a few simple yes/no questions about your organisation. You then receive an assessment of whether you are likely an essential entity (bwE), an important entity (wE), or a KRITIS operator under the revised German BSI Act (BSIG).

  • Takes about 2 minutes
  • Usable anonymously — company details are optional
  • Follows the structure of the official BSI scope check

Common questions

Is the deveca NIS2 scope check legally binding?

No. Like the official BSI scope check, our self-assessment is an automated first estimate without legal effect. It does not replace a legal review of the individual case or self-identification to the BSI.

Do I have to enter company data to take the test?

No. Company, website, and email are optional and can be skipped at any time. The check itself works fully anonymously.

What is the difference between bwE and wE?

Essential entities (bwE) are under proactive BSI supervision and higher fines (up to €10 million / 2% of annual turnover). Important entities (wE) are under ex-post, reactive supervision with a lower fine cap (up to €7 million / 1.4% of annual turnover).

What if I am not in scope today?

That can change — through growth beyond the thresholds, or because regulated customers pass security requirements to you through the supply chain.

What is a provider of non-qualified trust services?

A provider of non-qualified trust services offers digital trust services that do not meet the qualified requirements of the eIDAS Regulation. Under NIS2 those providers can still be classified as important or essential entities.

What is a non-qualified trust service?

A non-qualified trust service is a digital service (such as email encryption, electronic seals, or time-stamping) that does not meet the strict requirements of the European eIDAS Regulation. Providers of these services can still count as important or essential entities under NIS2.