NIS2 · ISO 27001 · NIST SP 800-53
Know where you stand before the audit
Audit41 Readiness assesses your organization against the framework you are facing and returns a scored report: every gap, ranked, with the actions that close it. The methodology is the one validated across 600+ live audit engagements.
Free. It tells you whether NIS2 applies to your organization and which category you fall into. ISO 27001 and NIST SP 800-53 have no scope test, so there you start with the assessment.

There is no single NIS2 deadline
Every member state transposed NIS2 into its own law, with its own chain of obligations: register, put measures in place, pass a first audit, then repeat on a cycle. The dates below are what those chains look like across five markets.
30 June 2026
First audit deadline passed
Audits repeat every 2 years.
Registration deadline, 3 October 2026
1 year
Measures due 1 year from your registration decision, commonly 31 December 2026.
Transitional period ends, 31 December 2026
150 days
Measures due in stages, 60 plus 60 plus 30 days from your registration.
Audit periodicity is set by DNSC order, still in draft.
Two of these five have no fixed national date at all, because the clock starts from your own registration. One regulator has not set the audit periodicity yet. In Hungary the first audit deadline passed on 30 June, and registered entities missed it.
The self-check tells you whether you are in scope, which category you fall into, and which of these dates apply to you.
Start the free self-checkWhat the assessment returns
A scored report against the framework you selected. Every control assessed, every gap ranked by severity, and the actions that close them in priority order. The example below scores 48 out of 100: partial readiness, gaps remediable within 90 days.

The method is an auditor's. The decisions are yours.
The assessment follows the path a working auditor takes: register the systems in scope, submit the policies, interview the people who run them, submit the evidence, then evaluate each requirement group against what was actually produced. It does not certify you and it does not replace the audit your regulator or your certification body requires. It gives you the same picture they will build, earlier.

Meet Sage. Your AI compliance advisor.
The decisions are yours, but you are not left to work them out alone. Frameworks are written for auditors, not for the people being audited. Sage explains what a requirement is actually asking for, at the point where you are answering it, in the context of what you have already submitted. It reads your report, tells you which gaps to close first, and drafts the policy text that closes them. Available on Professional and Programme. It identifies itself as AI in its first message.

Audit firms deliver client engagements on this methodology
Audit41 Core is the workflow layer for audit and consulting firms running NIS2 and ISO 27001 engagements at scale. The method under your assessment is the one they work in.
See Audit41 CoreBacking

Audit41 is an Amazon Web Services partner. The platform is built end to end on the AWS security and compliance framework, hosted in European data centers with enterprise-grade data protection.
Audit41 won the Audience Award at V4 Startup Force 2026, the cross-border accelerator for Hungary, Czechia, Poland, and Slovakia, supported by the International Visegrad Fund.
Founders
The team behind Audit41.


Dr. Petra Pozsgai
Co-founder, NIS2, EU AI Act & GDPR legal counsel
You cannot close a gap you have not found
Start with the free self-check. It tells you whether NIS2 applies to your organization and which category you fall into. The assessment comes after, and it works the same way for ISO 27001 and NIST SP 800-53.