NIS2 directive · readiness check
Registered with your national cybersecurity authority? The clock on implementing the measures is already running. DCcost turns ~20 control questions into a readiness score and the financial impact on your IT budget: what you already cover, what's missing, and what it will cost in CapEx and 5-year operations.
Answer the controls as they really stand (yes / partially / no) and get a readiness score plus a gap list ordered by priority.
Every gap carries a benchmark-based cost estimate (EDR, SIEM, tested backups, MFA, training…) — one-off investment + annual run cost + 5-year TCO impact. Output goes straight into the budget.
The advisor reads your DCcost model — you see the NIS2 impact in the context of the whole budget, not as an isolated number. Output: BOM + a management-ready summary.
If you fall under the essential/important entity criteria of the NIS2 directive (or your national transposition), yes. Deadlines differ by member state — check your national transposition; the measures themselves are the same across the EU.
It depends on your starting point. Companies with a below-benchmark security share (under ~6 % of IT spend) typically face a one-off investment in the hundreds of thousands of euros plus a higher annual run cost. That is exactly what the advisor computes from your answers.
No. DCcost quantifies costs and readiness; it does not replace legal interpretation or an audit. The output is a basis for budgeting and for conversations with management and vendors.
The gap analysis and the score are free with no sign-up. Watermark-free report export, project saving and the AI summary are part of Pro.
DCcost does not replace legal advice. NIS2 is an EU directive — obligations and deadlines are set by each member state's transposition.