Directive NIS2 European Union
Article 21(2) · Directive (EU) 2022/2555

Ten measures.
27 yardsticks.

Article 21(2) sets ten risk-management measures and stops there. It never says how you demonstrate them — that is left to each member state, and they have not agreed. Belgium built CyFun, Germany leans on IT-Grundschutz, France published ReCyF. This is the index of which yardstick applies where.

Measures in the directive
10
Member states
27
Frameworks documented
8
States examined
27 / 27
States with a named framework
8 / 27
States with law detail
20 / 27

Reviewed . Coverage is shown as it stands, gaps included — we are filling this in state by state rather than guessing.

Documented frameworks

The yardsticks


And the two you already run

Most organisations in scope did not start from nothing. These two carry no geography and no national mandate — they are the frameworks an enterprise already operates, and the reason the chain below matters: what you have built once can be reused in every member state.

None of them is compliance

Every framework on this page is a way of demonstrating the measures, not a substitute for owing them. Your obligations come from your national transposition law. ISO/IEC 27001 is the accepted alternative route in every member state we have examined.

The pivot

The ten measures everything maps to


These ten points are the only thing common to all 27 member states. Article numbering, framework, registration portal and penalty calibration are all national — this is not. Every national mapping we publish hangs off these keys.

The ten risk-management measures of article 21(2) of Directive (EU) 2022/2555
Art. 21(2) Measure What it requires
(a) Risk analysis and security policies Policies on risk analysis and information system security.
(b) Incident handling Detection, response and recovery — feeding the article 23 reporting chain.
(c) Business continuity Backup management, disaster recovery and crisis management.
(d) Supply chain security Security in relationships with direct suppliers and service providers.
(e) Security in acquisition, development and maintenance Including vulnerability handling and disclosure.
(f) Assessing the effectiveness of the measures Policies and procedures to assess whether the measures actually work.
(g) Basic cyber hygiene and cybersecurity training Basic cyber hygiene practices and cybersecurity training.
(h) Cryptography and encryption Policies on the use of cryptography and, where appropriate, encryption.
(i) Human resources security, access control and asset management Human resources security, access control policies and asset management.
(j) Multi-factor authentication and secured communications Multi-factor authentication or continuous authentication, secured voice, video and text, and secured emergency communication systems.

The chain, end to end

Read a row left to right and you have the whole path: the measure the directive requires, the units your national supervisor reads, then the controls of the frameworks you already run. Each column is mapped at the level that framework actually publishes — control, category, layer, domain or ISO equivalence. Two publish no stable identifiers at all, and that is recorded as a fact rather than filled in.

The ten measures of article 21(2) mapped to each of the six documented national assessment frameworks
Art. 21(2) CyFun IT-Grundschutz E-ITS Kybermittari ACN measures ReCyF ISO 27001 enterprise NIST 800-53 enterprise
(a) Risk analysis GV.OC GV.RM GV.PO ID.RA ISMS CON ORP 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RISK PROGRAM 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RA PL PM
(b) Incident handling DE.CM DE.AE RS.MA RS.AN RS.CO RS.MI DER OPS 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 RESPONSE SITUATION 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 IR AU SI
(c) Continuity PR.DS PR.IR RC.RP RC.CO CON OPS INF IND 5.29 5.30 7.5 7.11 7.12 8.13 8.14 RESPONSE ARCHITECTURE 5.29 5.30 7.5 7.11 7.12 8.13 8.14 CP PE
(d) Supply chain GV.SC ID.RA ORP OPS 5.19 5.20 5.21 5.22 5.23 THIRD-PARTIES 5.19 5.20 5.21 5.22 5.23 SR SA
(e) Secure development ID.RA PR.PS CON APP OPS IND 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 THREAT ARCHITECTURE 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 SA CM MA RA SI
(f) Effectiveness GV.OV ID.IM ISMS DER 5.33 5.35 5.36 8.16 PROGRAM RISK 5.33 5.35 5.36 8.16 CA PM
(g) Hygiene and training PR.AT PR.PS ORP CON 5.37 6.3 8.7 WORKFORCE 5.37 6.3 8.7 AT SI CM
(h) Cryptography PR.DS CON NET 8.24 ARCHITECTURE 8.24 SC
(i) HR, access, assets GV.RR ID.AM PR.AA ORP CON SYS APP IND 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 ACCESS ASSET WORKFORCE 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 PS AC IA CM MP PE
(j) MFA and comms PR.AA PR.IR NET SYS APP 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 ACCESS ARCHITECTURE 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 IA AC SC
CyFun

Mapped at NIST CSF 2.0 category level.

Category level, not subcategory. No official crosswalk from CyFun subcategories to article 21(2) exists; treat this as a scoping aid, not as a substitute for reading the controls at your assurance level.

Full mapping →

IT-Grundschutz

Mapped at IT-Grundschutz layer level.

Layer level, not module. Module identifiers change between editions of the Kompendium, so a module-level map would go stale; scope with this, then take the module list from the edition you are working to. The IND layer is mapped to continuity, maintenance and asset control because NIS2 covers OT-heavy sectors — energy, water, manufacturing — where industrial systems carry those outcomes and general IT modules do not reach them.

Full mapping →

E-ITS

Mapped at ISO/IEC 27001:2022 Annex A control level.

This maps the ISO equivalent, not E-ITS module identifiers, which are not published as a stable public set. Where you are assessed against E-ITS itself, use this to scope and then reconcile against the standard in force.

Full mapping →

Kybermittari

Mapped at C2M2 domain level.

Domain level. The model scores capability maturity, not conformity, so it tells you where you are weak rather than whether you meet a legal obligation. It also says nothing about which MIL satisfies article 21(2) — nothing does, because the directive sets no maturity target.

Full mapping →

ACN measures

Mapped at ACN determination (basic / specialist set) level.

No stable public identifier set to map against, and the determinations can be revised without amending D.Lgs. 138/2024. Read the determination in force — a mapping published here would be a snapshot of a moving target.

Full mapping →

ReCyF

Mapped at ReCyF security objective (important / essential grade) level.

No stable public control identifiers, and the framework sits on a law that was not promulgated as of July 2026. Treat it as the best available statement of ANSSI expectations, not as a control set to map one-to-one.

Full mapping →

ISO 27001 · enterprise

Mapped at ISO/IEC 27001:2022 Annex A control level.

Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.

Full mapping →

NIST 800-53 · enterprise

Mapped at NIST SP 800-53 Rev. 5 control family level.

Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Full mapping →

National law renumbers these

Belgium carries them at article 30 of the Law of 26 April 2024 — and adds an eleventh, a coordinated vulnerability disclosure policy. Planning against the directive's numbering alone leaves you short of a measure there. Each country page records its own numbering.

State by state

Which yardstick applies where


For each of the 27 EU member states: transposition status, competent authority, national assessment framework and whether national law detail is recorded here
Member state Transposition Competent authority Assessment framework Law detail
Austria Partial or staged Bundesamt für Cybersicherheit None published Recorded
Belgium Transposed Centre for Cybersecurity Belgium CyFun Recorded
Bulgaria Partial or staged Ministry of e-Government None published
Cyprus Partial or staged Digital Security Authority None published
Czechia Transposed NÚKIB None published
Germany Transposed BSI IT-Grundschutz Recorded
Denmark Transposed Centre for Cyber Security None published
Estonia Transposed Information System Authority E-ITS Recorded
Spain Not complete INCIBE / CCN None published Recorded
Finland Transposed Traficom Kybermittari
France Not complete ANSSI ReCyF Recorded
Greece Transposed National Cybersecurity Authority None published Recorded
Croatia Transposed SOA / ZSIS None published
Hungary Transposed SZTFH None published
Ireland Not complete NCSC Ireland CyFun
Italy Transposed ACN ACN measures Recorded
Lithuania Transposed NKSC None published
Luxembourg Not complete ILR / HCPN None published
Latvia Transposed National Cybersecurity Centre None published
Malta Partial or staged Malta Digital Innovation Auth. None published
Netherlands Partial or staged RDI None published Recorded
Poland Transposed Ministry of Digital Affairs None published Recorded
Portugal Transposed CNCS None published Recorded
Romania Transposed DNSC CyFun
Sweden Transposed MSB None published Recorded
Slovenia Transposed URSIV None published
Slovakia Transposed NBU None published

On a narrow screen the competent authority and law columns are hidden. Both are on each member state's page — tap a country name.

« None published » means we examined that state and found no national assessment framework for private entities in scope — the reason is on its page, and it is usually that the obligations sit directly in the law or in an authority decree. It does not mean the state has nothing to say. « Not examined yet » would mean we have not looked; there are none left.

Common questions

Does a CyFun label make us NIS2 compliant?
No, and this is the most expensive misunderstanding about the framework. Ireland's NCSC states it plainly: CyFun "does not prove that an entity is compliant with their NIS2 obligations but can provide a structured assessment framework to demonstrate cybersecurity maturity." Your obligations are owed under your national transposition law. CyFun is the instrument most regulators in Belgium, Ireland and Romania expect you to use to demonstrate that you have met them — evidence, not exemption.
Is CyFun only for Belgium?
Not any more. Belgium, Ireland and Romania are joint owners of the scheme, and Ireland has adopted CyberFundamentals as its national assessment and certification scheme. If your group has entities in more than one of those states, you can run one assessment programme rather than three — which is close to the only economy of scale NIS2 offers.
How many controls are there at each level?
Basic adds 34 controls. Important adds 99 on top of Basic, for 133. Essential adds 85 further advanced controls, bringing the cumulative total to about 218 — published figures for that top level vary between 217 and 218 depending on the source, so treat the additions rather than the total as the stable number. A fourth tier, Small, sits below Basic as an entry point for micro-organisations and is not an assurance level in the same sense.
What is the difference between CyFun 2.0 and CyFun 2025?
They are the same thing. The Centre for Cybersecurity Belgium published version 2 of the framework on 24 October 2025 and brands it CyFun 2025. If a document refers to "CyFun 2.0", it means this edition. The substantive change is alignment with NIST Cybersecurity Framework 2.0, which adds a sixth function, GOVERN, alongside expanded supply chain and operational technology coverage.
Can we use ISO 27001 instead?
Yes. ISO/IEC 27001 is the accepted alternative route, and entities in scope in Belgium are expected to work to either CyberFundamentals or ISO 27001. The practical trade-off: ISO 27001 is internationally recognised and certifiable anywhere, while CyFun is free to use, mapped to the national supervisor's expectations, and considerably lighter at its lower levels. Organisations already certified to ISO 27001 rarely have reason to switch.
Is passing an assessment a yes-or-no result?
No. Each control is scored for maturity out of five, and the level is awarded on documented maturity thresholds: at least 2.5 out of 5 for Basic and 3.5 out of 5 for Essential. That means an organisation can implement every control and still fall short if it cannot evidence how consistently they operate. In practice the documentation is what decides the outcome.
How does CyFun relate to article 21 of the directive?
Article 21(2) of the directive sets out ten risk-management measures as an outcome to achieve. CyFun is one way of structuring and evidencing them, organised by NIST CSF function rather than by the article's ten points, so the mapping is thematic rather than one-to-one. Note also that national law renumbers: Belgium carries these measures at article 30 of the Law of 26 April 2024 — and adds an eleventh, a coordinated vulnerability disclosure policy.
Cart 0