Directive NIS2 European Union
Article 21(2) · Directive (EU) 2022/2555

Ten measures.
27 yardsticks.

Article 21(2) sets ten risk-management measures and stops there. It never says how you demonstrate them — that is left to each member state, and they have not agreed. Belgium built CyFun, Germany leans on IT-Grundschutz, France published ReCyF. This is the index of which yardstick applies where.

Measures in the directive
10
Member states
27
Frameworks documented
14
States examined
27 / 27
States with a named framework
14 / 27
States with law detail
27 / 27

Reviewed . Coverage is shown as it stands, gaps included — we are filling this in state by state rather than guessing.

Documented frameworks

The yardsticks


BE IE RO

CyFun

CyberFundamentals Framework

Centre for Cybersecurity Belgium (CCB)

4 levels · built on a published standard

DE

IT-Grundschutz

IT-Grundschutz

Bundesamt für Sicherheit in der Informationstechnik (BSI)

3 levels · built on a published standard

EE

E-ITS

Eesti infoturbestandard — Estonian Information Security Standard

Riigi Infosüsteemi Amet (RIA) — Information System Authority

FI

Kybermittari

Kybermittari — Cybermeter

Liikenne- ja viestintävirasto Traficom — National Cyber Security Centre Finland

IT

ACN measures

ACN security measures and implementation guidelines

Agenzia per la Cybersicurezza Nazionale (ACN)

2 levels · built on a published standard

FR

ReCyF

Référentiel Cyber France

Agence nationale de la sécurité des systèmes d'information (ANSSI)

2 levels · built on a published standard

CZ

ZKB measures

Bezpečnostní opatření podle zákona o kybernetické bezpečnosti

NÚKIB — Národní úřad pro kybernetickou a informační bezpečnost

2 levels · built on a published standard

HR

HR Uredba

Uredba o kibernetičkoj sigurnosti

Government of Croatia, with SOA / ZSIS as competent authority

3 levels · built on a published standard

PT

QNRCS

Quadro Nacional de Referência para a Cibersegurança

CNCS — Centro Nacional de Cibersegurança

3 levels · built on a published standard

PL

NSC

Narodowe Standardy Cyberbezpieczeństwa

Ministerstwo Cyfryzacji — Departament Cyberbezpieczeństwa

HU

HU protective measures

Védelmi intézkedések a biztonsági osztályok szerint

Miniszterelnöki Kabinetiroda, with SZTFH as auditor registrar

2 levels · built on a published standard

NL

BIO2

Baseline Informatiebeveiliging Overheid 2

Interbestuurlijke werkgroep-BIO, chaired by the Ministry of the Interior (BZK)

And the 2 you already run

Most organisations in scope did not start from nothing. These carry no geography and no national mandate — they are the frameworks an enterprise already operates, and the reason the chain below matters: what you have built once can be reused in every member state.

None of them is compliance

Every framework on this page is a way of demonstrating the measures, not a substitute for owing them. Your obligations come from your national transposition law. ISO/IEC 27001 is the accepted alternative route in every member state we have examined.

The pivot

The ten measures everything maps to


These ten points are article 21(2) of Directive (EU) 2022/2555 — the NIS2 directive itself — and they are the only thing common to all 27 member states. Article numbering, framework, registration portal and penalty calibration are all national — this is not. Every national mapping we publish hangs off these keys.

The ten risk-management measures of article 21(2) of Directive (EU) 2022/2555
NIS2 art. 21(2) Directive (EU) 2022/2555 Measure What it requires
(a) Risk analysis and security policies Policies on risk analysis and information system security.
(b) Incident handling Detection, response and recovery — feeding the article 23 reporting chain.
(c) Business continuity Backup management, disaster recovery and crisis management.
(d) Supply chain security Security in relationships with direct suppliers and service providers.
(e) Security in acquisition, development and maintenance Including vulnerability handling and disclosure.
(f) Assessing the effectiveness of the measures Policies and procedures to assess whether the measures actually work.
(g) Basic cyber hygiene and cybersecurity training Basic cyber hygiene practices and cybersecurity training.
(h) Cryptography and encryption Policies on the use of cryptography and, where appropriate, encryption.
(i) Human resources security, access control and asset management Human resources security, access control policies and asset management.
(j) Multi-factor authentication and secured communications Multi-factor authentication or continuous authentication, secured voice, video and text, and secured emergency communication systems.

The chain, end to end

Read a row left to right and you have the whole path: the measure the directive requires, the units your national supervisor reads, then the controls of the frameworks you already run. Each column is mapped at the level that framework actually publishes — control, category, layer, domain or ISO equivalence. Two publish no stable identifiers at all, and that is recorded as a fact rather than filled in.

The ten measures of article 21(2) mapped to each of the 14 documented frameworks: 12 national assessment frameworks and 2 enterprise frameworks
NIS2 art. 21(2) Directive (EU) 2022/2555 CyFun IT-Grundschutz E-ITS Kybermittari ACN measures ReCyF ZKB measures HR Uredba QNRCS NSC HU protective measures BIO2 ISO 27001 enterprise NIST 800-53 enterprise
(a) Risk analysis GV.OC GV.RM GV.PO ID.RA ISMS CON ORP 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RISK PROGRAM § 3 § 4 § 6 § 8 IDENTIFICAR RA PL PM 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RA PL PM
(b) Incident handling DE.CM DE.AE RS.MA RS.AN RS.CO RS.MI DER OPS 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 RESPONSE SITUATION § 14 § 21 § 22 § 23 DETETAR RESPONDER IR AU SI 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 IR AU SI
(c) Continuity PR.DS PR.IR RC.RP RC.CO CON OPS INF IND 5.29 5.30 7.5 7.11 7.12 8.13 8.14 RESPONSE ARCHITECTURE § 15 § 17 § 26 RECUPERAR PROTEGER CP PE 5.29 5.30 7.5 7.11 7.12 8.13 8.14 5.29 5.30 7.5 7.11 7.12 8.13 8.14 CP PE
(d) Supply chain GV.SC ID.RA ORP OPS 5.19 5.20 5.21 5.22 5.23 DEPENDENCIES § 9 IDENTIFICAR PROTEGER SR SA 5.19 5.20 5.21 5.22 5.23 5.19 5.20 5.21 5.22 5.23 SR SA
(e) Secure development ID.RA PR.PS CON APP OPS IND 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 THREAT ARCHITECTURE § 11 § 12 § 24 § 27 IDENTIFICAR PROTEGER SA CM MA RA SI 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 SA CM MA RA SI
(f) Effectiveness GV.OV ID.IM ISMS DER 5.33 5.35 5.36 8.16 PROGRAM RISK § 3 § 16 IDENTIFICAR CA PM 5.33 5.35 5.36 8.16 5.33 5.35 5.36 8.16 CA PM
(g) Hygiene and training PR.AT PR.PS ORP CON 5.37 6.3 8.7 WORKFORCE § 4 § 10 PROTEGER AT SI CM 5.37 6.3 8.7 5.37 6.3 8.7 AT SI CM
(h) Cryptography PR.DS CON NET 8.24 ARCHITECTURE § 25 PROTEGER SC 8.24 8.24 SC
(i) HR, access, assets GV.RR ID.AM PR.AA ORP CON SYS APP IND 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 ACCESS ASSET WORKFORCE § 5 § 7 § 10 § 13 § 20 IDENTIFICAR PROTEGER PS AC IA CM MP PE 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 PS AC IA CM MP PE
(j) MFA and comms PR.AA PR.IR NET SYS APP 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 ACCESS ARCHITECTURE § 18 § 19 PROTEGER IA AC SC 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 IA AC SC
CyFun

Mapped at NIST CSF 2.0 category level.

Category level, not subcategory. No official crosswalk from CyFun subcategories to article 21(2) exists; treat this as a scoping aid, not as a substitute for reading the controls at your assurance level.

Full mapping →

IT-Grundschutz

Mapped at IT-Grundschutz layer level.

Layer level, not module. Module identifiers change between editions of the Kompendium, so a module-level map would go stale; scope with this, then take the module list from the edition you are working to. The IND layer is mapped to continuity, maintenance and asset control because NIS2 covers OT-heavy sectors — energy, water, manufacturing — where industrial systems carry those outcomes and general IT modules do not reach them.

Full mapping →

E-ITS

Mapped at ISO/IEC 27001:2022 Annex A control level.

This maps the ISO equivalent rather than E-ITS itself, because RIA publishes no crosswalk of its own to article 21(2). The E-ITS measures do have stable public identifiers — ORP.1.M1 and the like — and the catalogue below carries every one of them.

Full mapping →

Kybermittari

Mapped at Kybermittari domain level.

Domain level. The model scores capability maturity, not conformity, so it tells you where you are weak rather than whether you meet a legal obligation. It also says nothing about which MIL satisfies article 21(2) — nothing does, because the directive sets no maturity target. CRITICAL is not placed against a measure here: it is Traficom's own addition, and putting it under a letter would be our invention rather than their model.

Full mapping →

ACN measures

Mapped at ACN determination (basic / specialist set) level.

No stable public identifier set to map against, and the determinations can be revised without amending D.Lgs. 138/2024. Read the determination in force — a mapping published here would be a snapshot of a moving target.

Full mapping →

ReCyF

Mapped at ReCyF security objective (important / essential grade) level.

No stable public control identifiers, and the framework sits on a law that was not promulgated as of July 2026. Treat it as the best available statement of ANSSI expectations, not as a control set to map one-to-one.

Full mapping →

ZKB measures

Mapped at decree paragraph (§) level.

The headings are unambiguous but the § themselves are detailed: a § match tells you which paragraph to read, not that its requirements are met. The lower-obligations regime has its own decree (410/2025 Sb.) with a lighter set — this mapping is of the higher regime.

Full mapping →

HR Uredba

Mapped at Annex II measure, per level level.

Not recorded yet at measure level. Secondary sources report thirteen measures in Annex II; we have not confirmed that against the official annex, so we do not publish the count as fact. The levels above are confirmed.

Full mapping →

QNRCS

Mapped at QNRCS function level.

Function level is the coarsest mapping in this hub. A function covers many measures at three capability levels each, so a function match locates the area to read and nothing more. The measure count is not recorded yet.

Full mapping →

NSC

Mapped at NIST SP 800-53 Rev. 5 control family level.

Family level, inherited from the NIST mapping. And the NSC are recommendations: a family match locates your evidence, it does not discharge the Polish statute.

Full mapping →

HU protective measures

Mapped at protective measure category (Appendix 2) level.

Not recorded yet at category level. The category names reported so far — programme management, access control, awareness and training, logging, supply chain risk management — read like the NIST SP 800-53 family set, and nineteen is a suggestive count. We are not publishing that as a mapping: an equivalence inferred from five names out of nineteen would be a guess wearing a citation.

Full mapping →

BIO2

Mapped at ISO/IEC 27002:2022 control level.

The ISO controls map; the overheidsmaatregelen do not, because their identifiers and their number are not transcribed here yet. That gap matters: they are exactly the part specific to the Dutch government, and the part the Cbw makes legally binding.

Full mapping →

ISO 27001 · enterprise

Mapped at ISO/IEC 27001:2022 Annex A control level.

Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.

Full mapping →

NIST 800-53 · enterprise

Mapped at NIST SP 800-53 Rev. 5 control family level.

Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Full mapping →

National law renumbers these

Belgium carries them at article 30 of the Law of 26 April 2024 — and adds an eleventh, a coordinated vulnerability disclosure policy. Planning against the directive's numbering alone leaves you short of a measure there. Each country page records its own numbering.

Catalogues

Which of them names its measures, one by one


A mapping says which of the ten measures a framework serves. A catalogue says which requirement, at which assurance level, scored how. They are not the same work, and the frameworks are far from equal on the second: 3 of 14 publish no citable identifier at all, and 2 attach a maturity scale. We hold 6 of them requirement by requirement so far.

Every requirement
6 / 14
Unit level only
5 / 14
Nothing to cite
3 / 14
Not verified yet
0 / 14

And how much of it there is

These counts are not interchangeable. Each framework names its own unit — an Anforderung is not a requirement is not a practice — so a longer bar means a finer breakdown, not a heavier obligation. What it does tell you is the shape of the reading ahead: IT-Grundschutz holds 2 124 units where CyFun holds 218.

For each documented framework: whether its owner publishes citable identifiers, how deep this site holds the detail, the unit it is held at, whether the framework attaches a maturity scale, and how many assurance levels it has
Framework Owner publishes ids What we hold Held at Maturity scale Levels
CyFun Yes Every requirement 218 requirements Yes 4
IT-Grundschutz Yes Every requirement 2124 Anforderungs Not recorded yet 3
E-ITS Yes Every requirement 1802 measures Not recorded yet
Kybermittari Yes Every requirement 325 practices Yes
ACN measures No stable public ids Nothing to cite ACN determination (basic / specialist set) Not recorded yet 2
ReCyF No stable public ids Nothing to cite ReCyF security objective (important / essential grade) Not recorded yet 2
ZKB measures Yes Every requirement 442 provisions Not recorded yet 2
HR Uredba No stable public ids Nothing to cite Annex II measure, per level Not recorded yet 3
QNRCS Yes Unit level only QNRCS function Not recorded yet 3
NSC Yes Unit level only NIST SP 800-53 Rev. 5 control family via NIST 800-53 Not recorded yet
HU protective measures Yes Unit level only protective measure category (Appendix 2) Not recorded yet 2
BIO2 Yes Unit level only ISO/IEC 27002:2022 control via ISO 27001 Not recorded yet
ISO 27001 enterprise Yes Unit level only ISO/IEC 27001:2022 Annex A control Not recorded yet
NIST 800-53 enterprise Yes Every requirement 1196 controls Not recorded yet 3

Two columns, two different facts

Owner publishes ids is about the framework: whether anyone can cite one of its requirements by a stable identifier. What we hold is about this site, and it is the honest half. Every requirement means we carry each one with its assurance level, its key-measure status and what its owner relates it to. Unit level only means we cite the layer, domain or category the framework publishes at, and the detail underneath is still to transcribe — that is our queue, not a gap in the framework.

State by state

Which yardstick applies where


For each of the 27 EU member states: transposition status, competent authority, national assessment framework and whether national law detail is recorded here
Member state Transposition Competent authority Assessment framework Law detail
Austria Bundesamt für Cybersicherheit None published Recorded
Belgium Transposed Centre for Cybersecurity Belgium CyFun Recorded
Bulgaria Transposed Ministry of e-Government None published Recorded
Cyprus Transposed Digital Security Authority None published Recorded
Czechia Transposed NÚKIB ZKB measures Recorded
Germany Transposed BSI IT-Grundschutz Recorded
Denmark Transposed Styrelsen for Samfundssikkerhed None published Recorded
Estonia Transposed Information System Authority E-ITS Recorded
Spain Not complete INCIBE / CCN None published Recorded
Finland Transposed Traficom Kybermittari Recorded
France Not complete ANSSI ReCyF Recorded
Greece Transposed National Cybersecurity Authority None published Recorded
Croatia Transposed SOA / ZSIS HR Uredba Recorded
Hungary Transposed SZTFH HU protective measures Recorded
Ireland Not complete NCSC Ireland CyFun
Italy Transposed ACN ACN measures Recorded
Lithuania Transposed NKSC None published Recorded
Luxembourg Transposed ILR / HCPN None published Recorded
Latvia Transposed National Cybersecurity Centre None published Recorded
Malta Transposed Critical Infrastructure Protection Dept. None published Recorded
Netherlands Transposed RDI BIO2 Recorded
Poland Transposed Ministry of Digital Affairs NSC Recorded
Portugal Transposed CNCS QNRCS Recorded
Romania Transposed DNSC CyFun Recorded
Sweden Transposed NCSC at FRA (Försvarets radioanstalt) None published Recorded
Slovenia Transposed URSIV None published Recorded
Slovakia Transposed NBU None published Recorded

On a narrow screen the competent authority and law columns are hidden. Both are on each member state's page — tap a country name.

« None published » means we examined that state and found no national assessment framework for private entities in scope — the reason is on its page, and it is usually that the obligations sit directly in the law or in an authority decree. It does not mean the state has nothing to say. « Not examined yet » would mean we have not looked; there are none left.

Common questions

Does a CyFun label make us NIS2 compliant?
No, and this is the most expensive misunderstanding about the framework. Ireland's NCSC states it plainly: CyFun "does not prove that an entity is compliant with their NIS2 obligations but can provide a structured assessment framework to demonstrate cybersecurity maturity." Your obligations are owed under your national transposition law. CyFun is the instrument most regulators in Belgium, Ireland and Romania expect you to use to demonstrate that you have met them — evidence, not exemption.
Is CyFun only for Belgium?
Not any more. Belgium, Ireland and Romania are joint owners of the scheme, and Ireland has adopted CyberFundamentals as its national assessment and certification scheme. If your group has entities in more than one of those states, you can run one assessment programme rather than three — which is close to the only economy of scale NIS2 offers.
How many controls are there at each level?
Basic adds 34 controls. Important adds 99 on top of Basic, for 133. Essential adds 85 further advanced controls, bringing the cumulative total to about 218 — published figures for that top level vary between 217 and 218 depending on the source, so treat the additions rather than the total as the stable number. A fourth tier, Small, sits below Basic as an entry point for micro-organisations and is not an assurance level in the same sense.
What is the difference between CyFun 2.0 and CyFun 2025?
They are the same thing. The Centre for Cybersecurity Belgium published version 2 of the framework on 24 October 2025 and brands it CyFun 2025. If a document refers to "CyFun 2.0", it means this edition. The substantive change is alignment with NIST Cybersecurity Framework 2.0, which adds a sixth function, GOVERN, alongside expanded supply chain and operational technology coverage.
Can we use ISO 27001 instead?
Yes. ISO/IEC 27001 is the accepted alternative route, and entities in scope in Belgium are expected to work to either CyberFundamentals or ISO 27001. The practical trade-off: ISO 27001 is internationally recognised and certifiable anywhere, while CyFun is free to use, mapped to the national supervisor's expectations, and considerably lighter at its lower levels. Organisations already certified to ISO 27001 rarely have reason to switch.
Is passing an assessment a yes-or-no result?
No. Each control is scored for maturity out of five, and the level is awarded on documented maturity thresholds: at least 2.5 out of 5 for Basic and 3.5 out of 5 for Essential. That means an organisation can implement every control and still fall short if it cannot evidence how consistently they operate. In practice the documentation is what decides the outcome.
How does CyFun relate to article 21 of the directive?
Article 21(2) of the directive sets out ten risk-management measures as an outcome to achieve. CyFun is one way of structuring and evidencing them, organised by NIST CSF function rather than by the article's ten points, so the mapping is thematic rather than one-to-one. Note also that national law renumbers: Belgium carries these measures at article 30 of the Law of 26 April 2024 — and adds an eleventh, a coordinated vulnerability disclosure policy.
Cart 0