Art. 21(2)(a) Risk Analysis & Security Policy Toolkit
Assess and evidence your risk-analysis methodology and information system security policies, as required by article 21(2)(a).
- Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
- Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
- Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
- Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
- Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
- NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
- Regenerated from our data hub, so it carries the same review date as the site and cannot drift from it
Art. 21(2)(b) · Art. 23 Incident Handling Toolkit
Build the incident handling capability article 21(2)(b) requires, wired to the 24h / 72h / one-month reporting chain of article 23.
- Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
- Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
- Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
- Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
- Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
- NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
- Regenerated from our data hub, so it carries the same review date as the site and cannot drift from it
Art. 21(2)(c) Business Continuity & Crisis Management Toolkit
Backup management, disaster recovery and crisis management, the three components named in article 21(2)(c).
- Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
- Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
- Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
- Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
- Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
- NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
- Regenerated from our data hub, so it carries the same review date as the site and cannot drift from it
Art. 21(2)(d) · Art. 21(3) Supply Chain Security Toolkit
Supplier risk assessment and contractual security requirements — the obligation most entities are least prepared for.
- Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
- Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
- Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
- Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
- Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
- NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
- Regenerated from our data hub, so it carries the same review date as the site and cannot drift from it
Art. 21(2)(i) · 21(2)(j) Access Control, MFA & Asset Management Toolkit
Human resources security, access control policies, asset management and the multi-factor authentication requirement of article 21(2)(j).
- Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
- Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
- Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
- Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
- Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
- NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
- Regenerated from our data hub, so it carries the same review date as the site and cannot drift from it
Best value Complete Assessment Toolkit Bundle
All five assessment toolkits: risk analysis, incident handling, continuity, supply chain, and access control with MFA.
- All five article 21 assessment toolkits, each delivered as its own download
- Contents summary (Markdown) listing every component
- Every component generated from the same data hub on the same review date, so the per-country tables agree with each other and with the site