Directive NIS2 European Union
Cart 0
Art. 21(2) · Directive (EU) 2022/2555

The ten minimum measures


Article 21(2) is written as ten outcomes, not as a control catalogue. That is deliberate — and it is why the hard part is evidence, not intent.

Art. 21(1)
Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems […]
Directive (EU) 2022/2555

« Appropriate and proportionate » means the bar scales with your size, exposure and the societal impact of an outage. It does not mean optional.

Art. 21(2)(a)

Risk analysis and information system security policies


« policies on risk analysis and information system security »

A documented, repeatable method for identifying and rating risk, and a security policy set approved by management.

What an auditor will ask for

  • A risk methodology document
  • A populated risk register with owners and treatment decisions
  • Board-approved security policies with a review date
Art. 21(2)(b)

Incident handling


« incident handling »

Detection, triage, response and recovery — and the internal escalation that lets you meet the 24-hour clock of article 23.

What an auditor will ask for

  • An incident response plan with defined roles
  • A severity classification matrix
  • Post-incident review records
Art. 21(2)(c)

Business continuity and crisis management


« business continuity, such as backup management and disaster recovery, and crisis management »

Backups you have actually restored from, a recovery plan with tested RTO and RPO, and a crisis structure that convenes.

What an auditor will ask for

  • Business impact analysis with RTO/RPO per service
  • Restore test records, not just backup logs
  • Crisis management plan and exercise reports
Art. 21(2)(d)

Supply chain security


« supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers »

The obligation most entities are least prepared for. It covers your DIRECT suppliers, and you must consider their overall quality of practices.

What an auditor will ask for

  • ICT supplier register with criticality tiering
  • Security requirements in contracts
  • Supplier assessment results and follow-up actions
Art. 21(2)(e)

Security in acquisition, development and maintenance


« security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure »

Secure development and change practices, plus a way to receive and act on vulnerability reports.

What an auditor will ask for

  • Secure development standard
  • Vulnerability management process with SLAs by severity
  • A coordinated vulnerability disclosure policy
Art. 21(2)(f)

Assessing effectiveness


« policies and procedures to assess the effectiveness of cybersecurity risk-management measures »

Evidence that you check whether the measures work, not merely that they exist. This is the measure auditors use to test the others.

What an auditor will ask for

  • Internal audit or control-testing plan
  • Test results with findings and remediation
  • Management review minutes
Art. 21(2)(g)

Cyber hygiene and training


« basic cyber hygiene practices and cybersecurity training »

Baseline practices for everyone, plus role-appropriate training. Note that article 20 separately obliges management bodies to follow training.

What an auditor will ask for

  • Awareness programme with completion rates
  • Role-specific training records
  • Phishing simulation results and trend
Art. 21(2)(h)

Cryptography


« policies and procedures regarding the use of cryptography and, where appropriate, encryption »

A policy stating what must be encrypted, with which algorithms, and how keys are managed through their lifecycle.

What an auditor will ask for

  • Cryptography policy with approved algorithms
  • Key management procedure
  • Encryption coverage inventory
Art. 21(2)(i)

HR security, access control and asset management


« human resources security, access control policies and asset management »

Knowing what you have, who can reach it, and removing that access when people move or leave.

What an auditor will ask for

  • Asset inventory with owners and classification
  • Access control policy and periodic access reviews
  • Joiner / mover / leaver records
Art. 21(2)(j)

Multi-factor authentication and secured communications


« the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate »

MFA is named explicitly in the directive. So are secured communications and an emergency channel that still works when your primary systems do not.

What an auditor will ask for

  • MFA coverage report, especially for remote and privileged access
  • Secured communications standard
  • A tested out-of-band emergency channel

Cover all ten at once


All five assessment toolkits: risk analysis, incident handling, continuity, supply chain, and access control with MFA.

  • All 5 assessment toolkits (Excel + PDF each)
  • Consolidated maturity dashboard across all article 21 measures
  • Single gap-analysis view with prioritised remediation plan
  • Lifetime updates as national transpositions evolve
249 € excl. VAT

Value if bought separately: 395 €

Cart 0