Ten measures.
27 yardsticks.
Article 21(2) sets ten risk-management measures and stops there. It never says how you demonstrate them — that is left to each member state, and they have not agreed. Belgium built CyFun, Germany leans on IT-Grundschutz, France published ReCyF. This is the index of which yardstick applies where.
Reviewed . Coverage is shown as it stands, gaps included — we are filling this in state by state rather than guessing.
The yardsticks
CyFun
CyberFundamentals Framework
Centre for Cybersecurity Belgium (CCB)
4 levels · built on a published standard
DEIT-Grundschutz
IT-Grundschutz
Bundesamt für Sicherheit in der Informationstechnik (BSI)
3 levels · built on a published standard
EEE-ITS
Eesti infoturbestandard — Estonian Information Security Standard
Riigi Infosüsteemi Amet (RIA) — Information System Authority
FIKybermittari
Kybermittari — Cybermeter
Liikenne- ja viestintävirasto Traficom — National Cyber Security Centre Finland
ITACN measures
ACN security measures and implementation guidelines
Agenzia per la Cybersicurezza Nazionale (ACN)
2 levels · built on a published standard
FRReCyF
Référentiel Cyber France
Agence nationale de la sécurité des systèmes d'information (ANSSI)
2 levels · built on a published standard
And the two you already run
Most organisations in scope did not start from nothing. These two carry no geography and no national mandate — they are the frameworks an enterprise already operates, and the reason the chain below matters: what you have built once can be reused in every member state.
ISO 27001
ISO/IEC 27001 — Information security management systems
ISO and IEC · mapped at ISO/IEC 27001:2022 Annex A control level
Enterprise · no geographyNIST 800-53
NIST SP 800-53 — Security and Privacy Controls for Information Systems and Organizations
National Institute of Standards and Technology (NIST) · mapped at NIST SP 800-53 Rev. 5 control family level
None of them is compliance
Every framework on this page is a way of demonstrating the measures, not a substitute for owing them. Your obligations come from your national transposition law. ISO/IEC 27001 is the accepted alternative route in every member state we have examined.
The ten measures everything maps to
These ten points are the only thing common to all 27 member states. Article numbering, framework, registration portal and penalty calibration are all national — this is not. Every national mapping we publish hangs off these keys.
| Art. 21(2) | Measure | What it requires |
|---|---|---|
| (a) | Risk analysis and security policies | Policies on risk analysis and information system security. |
| (b) | Incident handling | Detection, response and recovery — feeding the article 23 reporting chain. |
| (c) | Business continuity | Backup management, disaster recovery and crisis management. |
| (d) | Supply chain security | Security in relationships with direct suppliers and service providers. |
| (e) | Security in acquisition, development and maintenance | Including vulnerability handling and disclosure. |
| (f) | Assessing the effectiveness of the measures | Policies and procedures to assess whether the measures actually work. |
| (g) | Basic cyber hygiene and cybersecurity training | Basic cyber hygiene practices and cybersecurity training. |
| (h) | Cryptography and encryption | Policies on the use of cryptography and, where appropriate, encryption. |
| (i) | Human resources security, access control and asset management | Human resources security, access control policies and asset management. |
| (j) | Multi-factor authentication and secured communications | Multi-factor authentication or continuous authentication, secured voice, video and text, and secured emergency communication systems. |
The chain, end to end
Read a row left to right and you have the whole path: the measure the directive requires, the units your national supervisor reads, then the controls of the frameworks you already run. Each column is mapped at the level that framework actually publishes — control, category, layer, domain or ISO equivalence. Two publish no stable identifiers at all, and that is recorded as a fact rather than filled in.
| Art. 21(2) | CyFun | IT-Grundschutz | E-ITS | Kybermittari | ACN measures | ReCyF | ISO 27001 enterprise | NIST 800-53 enterprise |
|---|---|---|---|---|---|---|---|---|
| (a) Risk analysis | GV.OC GV.RM GV.PO ID.RA | ISMS CON ORP | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RISK PROGRAM | — | — | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | DE.CM DE.AE RS.MA RS.AN RS.CO RS.MI | DER OPS | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | RESPONSE SITUATION | — | — | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | PR.DS PR.IR RC.RP RC.CO | CON OPS INF IND | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | RESPONSE ARCHITECTURE | — | — | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | GV.SC ID.RA | ORP OPS | 5.19 5.20 5.21 5.22 5.23 | THIRD-PARTIES | — | — | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | ID.RA PR.PS | CON APP OPS IND | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | THREAT ARCHITECTURE | — | — | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | GV.OV ID.IM | ISMS DER | 5.33 5.35 5.36 8.16 | PROGRAM RISK | — | — | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | PR.AT PR.PS | ORP CON | 5.37 6.3 8.7 | WORKFORCE | — | — | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | PR.DS | CON NET | 8.24 | ARCHITECTURE | — | — | 8.24 | SC |
| (i) HR, access, assets | GV.RR ID.AM PR.AA | ORP CON SYS APP IND | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | ACCESS ASSET WORKFORCE | — | — | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | PR.AA PR.IR | NET SYS APP | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | ACCESS ARCHITECTURE | — | — | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
Mapped at NIST CSF 2.0 category level.
Category level, not subcategory. No official crosswalk from CyFun subcategories to article 21(2) exists; treat this as a scoping aid, not as a substitute for reading the controls at your assurance level.
Mapped at IT-Grundschutz layer level.
Layer level, not module. Module identifiers change between editions of the Kompendium, so a module-level map would go stale; scope with this, then take the module list from the edition you are working to. The IND layer is mapped to continuity, maintenance and asset control because NIS2 covers OT-heavy sectors — energy, water, manufacturing — where industrial systems carry those outcomes and general IT modules do not reach them.
Mapped at ISO/IEC 27001:2022 Annex A control level.
This maps the ISO equivalent, not E-ITS module identifiers, which are not published as a stable public set. Where you are assessed against E-ITS itself, use this to scope and then reconcile against the standard in force.
Mapped at C2M2 domain level.
Domain level. The model scores capability maturity, not conformity, so it tells you where you are weak rather than whether you meet a legal obligation. It also says nothing about which MIL satisfies article 21(2) — nothing does, because the directive sets no maturity target.
Mapped at ACN determination (basic / specialist set) level.
No stable public identifier set to map against, and the determinations can be revised without amending D.Lgs. 138/2024. Read the determination in force — a mapping published here would be a snapshot of a moving target.
Mapped at ReCyF security objective (important / essential grade) level.
No stable public control identifiers, and the framework sits on a law that was not promulgated as of July 2026. Treat it as the best available statement of ANSSI expectations, not as a control set to map one-to-one.
Mapped at ISO/IEC 27001:2022 Annex A control level.
Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
Mapped at NIST SP 800-53 Rev. 5 control family level.
Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
National law renumbers these
Belgium carries them at article 30 of the Law of 26 April 2024 — and adds an eleventh, a coordinated vulnerability disclosure policy. Planning against the directive's numbering alone leaves you short of a measure there. Each country page records its own numbering.
Which yardstick applies where
| Member state | Transposition | Competent authority | Assessment framework | Law detail |
|---|---|---|---|---|
| Austria | Partial or staged | Bundesamt für Cybersicherheit | None published | Recorded |
| Belgium | Transposed | Centre for Cybersecurity Belgium | CyFun | Recorded |
| Bulgaria | Partial or staged | Ministry of e-Government | None published | — |
| Cyprus | Partial or staged | Digital Security Authority | None published | — |
| Czechia | Transposed | NÚKIB | None published | — |
| Germany | Transposed | BSI | IT-Grundschutz | Recorded |
| Denmark | Transposed | Centre for Cyber Security | None published | — |
| Estonia | Transposed | Information System Authority | E-ITS | Recorded |
| Spain | Not complete | INCIBE / CCN | None published | Recorded |
| Finland | Transposed | Traficom | Kybermittari | — |
| France | Not complete | ANSSI | ReCyF | Recorded |
| Greece | Transposed | National Cybersecurity Authority | None published | Recorded |
| Croatia | Transposed | SOA / ZSIS | None published | — |
| Hungary | Transposed | SZTFH | None published | — |
| Ireland | Not complete | NCSC Ireland | CyFun | — |
| Italy | Transposed | ACN | ACN measures | Recorded |
| Lithuania | Transposed | NKSC | None published | — |
| Luxembourg | Not complete | ILR / HCPN | None published | — |
| Latvia | Transposed | National Cybersecurity Centre | None published | — |
| Malta | Partial or staged | Malta Digital Innovation Auth. | None published | — |
| Netherlands | Partial or staged | RDI | None published | Recorded |
| Poland | Transposed | Ministry of Digital Affairs | None published | Recorded |
| Portugal | Transposed | CNCS | None published | Recorded |
| Romania | Transposed | DNSC | CyFun | — |
| Sweden | Transposed | MSB | None published | Recorded |
| Slovenia | Transposed | URSIV | None published | — |
| Slovakia | Transposed | NBU | None published | — |
On a narrow screen the competent authority and law columns are hidden. Both are on each member state's page — tap a country name.
« None published » means we examined that state and found no national assessment framework for private entities in scope — the reason is on its page, and it is usually that the obligations sit directly in the law or in an authority decree. It does not mean the state has nothing to say. « Not examined yet » would mean we have not looked; there are none left.