Free, open source, no signup

NIS2 Risk Assessment in under 5 minutes

Eight questions per asset. Per-Grundwert protection-need and a recommended implementation path in the spirit of BSI Grundschutz 200-2 §8.2.

Per-Grundwert (V/I/A) classification with Maximum-Prinzip. NIS2 Art 21(1) + Art 21(2)(a), BSIG §30. No signup, the result stays with you.

Once you have your inventory from Lesson 2.2 of our CEO course, every asset takes under a minute. Open the CEO course

Example result
Local HR workstation
riskAssessment.result.finalTierLabelBasis
Answers (condensed)
  • SensitivityEmployee data (HR files, contracts, salaries)
  • IntegritySome impact. Wrong data would cause operational confusion or take time to fix
  • OutageDays. We'd manage with workarounds.
  • AccessA few standard users (small team, no special privileges)
  • ReachFully offline, no network connection
  • UpdatesYes, the vendor actively maintains it and ships patches
  • HistoryNo known incidents, but we don't actively monitor the system
  • RecoveryWithin a day
Question 1 of 8
What kind of data does this system process?

Per-asset Schutzbedarfsfeststellung aligned with BSI-200-2 §8.2 (assumes your Sicherheitsleitlinie §4 and Strukturanalyse §8.1 are already in place). Per-Grundwert classification (V/I/A) on the BSI normal/hoch/sehr-hoch scale, Maximum-Prinzip per §8.2.3, Kumulationseffekt per §8.2.4, and documented Schadensszenarien per §8.2.1. Vererbung, Modellierung (§8.3), IT-Grundschutz-Check (§8.4), and BSI-200-3 ergänzende Risikoanalyse remain follow-on work. Not a certification: that requires a third-party DAkkS-accredited audit.