Ten measures.
27 yardsticks.
Article 21(2) sets ten risk-management measures and stops there. It never says how you demonstrate them — that is left to each member state, and they have not agreed. Belgium built CyFun, Germany leans on IT-Grundschutz, France published ReCyF. This is the index of which yardstick applies where.
Reviewed . Coverage is shown as it stands, gaps included — we are filling this in state by state rather than guessing.
The yardsticks
CyFun
CyberFundamentals Framework
Centre for Cybersecurity Belgium (CCB)
4 levels · built on a published standard
DEIT-Grundschutz
IT-Grundschutz
Bundesamt für Sicherheit in der Informationstechnik (BSI)
3 levels · built on a published standard
EEE-ITS
Eesti infoturbestandard — Estonian Information Security Standard
Riigi Infosüsteemi Amet (RIA) — Information System Authority
FIKybermittari
Kybermittari — Cybermeter
Liikenne- ja viestintävirasto Traficom — National Cyber Security Centre Finland
ITACN measures
ACN security measures and implementation guidelines
Agenzia per la Cybersicurezza Nazionale (ACN)
2 levels · built on a published standard
FRReCyF
Référentiel Cyber France
Agence nationale de la sécurité des systèmes d'information (ANSSI)
2 levels · built on a published standard
CZZKB measures
Bezpečnostní opatření podle zákona o kybernetické bezpečnosti
NÚKIB — Národní úřad pro kybernetickou a informační bezpečnost
2 levels · built on a published standard
HRHR Uredba
Uredba o kibernetičkoj sigurnosti
Government of Croatia, with SOA / ZSIS as competent authority
3 levels · built on a published standard
PTQNRCS
Quadro Nacional de Referência para a Cibersegurança
CNCS — Centro Nacional de Cibersegurança
3 levels · built on a published standard
PLNSC
Narodowe Standardy Cyberbezpieczeństwa
Ministerstwo Cyfryzacji — Departament Cyberbezpieczeństwa
HUHU protective measures
Védelmi intézkedések a biztonsági osztályok szerint
Miniszterelnöki Kabinetiroda, with SZTFH as auditor registrar
2 levels · built on a published standard
NLBIO2
Baseline Informatiebeveiliging Overheid 2
Interbestuurlijke werkgroep-BIO, chaired by the Ministry of the Interior (BZK)
And the 2 you already run
Most organisations in scope did not start from nothing. These carry no geography and no national mandate — they are the frameworks an enterprise already operates, and the reason the chain below matters: what you have built once can be reused in every member state.
ISO 27001
ISO/IEC 27001 — Information security management systems
ISO and IEC · mapped at ISO/IEC 27001:2022 Annex A control level
Enterprise · no geographyNIST 800-53
NIST SP 800-53 — Security and Privacy Controls for Information Systems and Organizations
National Institute of Standards and Technology (NIST) · mapped at NIST SP 800-53 Rev. 5 control family level
None of them is compliance
Every framework on this page is a way of demonstrating the measures, not a substitute for owing them. Your obligations come from your national transposition law. ISO/IEC 27001 is the accepted alternative route in every member state we have examined.
The ten measures everything maps to
These ten points are article 21(2) of Directive (EU) 2022/2555 — the NIS2 directive itself — and they are the only thing common to all 27 member states. Article numbering, framework, registration portal and penalty calibration are all national — this is not. Every national mapping we publish hangs off these keys.
| NIS2 art. 21(2) Directive (EU) 2022/2555 | Measure | What it requires |
|---|---|---|
| (a) | Risk analysis and security policies | Policies on risk analysis and information system security. |
| (b) | Incident handling | Detection, response and recovery — feeding the article 23 reporting chain. |
| (c) | Business continuity | Backup management, disaster recovery and crisis management. |
| (d) | Supply chain security | Security in relationships with direct suppliers and service providers. |
| (e) | Security in acquisition, development and maintenance | Including vulnerability handling and disclosure. |
| (f) | Assessing the effectiveness of the measures | Policies and procedures to assess whether the measures actually work. |
| (g) | Basic cyber hygiene and cybersecurity training | Basic cyber hygiene practices and cybersecurity training. |
| (h) | Cryptography and encryption | Policies on the use of cryptography and, where appropriate, encryption. |
| (i) | Human resources security, access control and asset management | Human resources security, access control policies and asset management. |
| (j) | Multi-factor authentication and secured communications | Multi-factor authentication or continuous authentication, secured voice, video and text, and secured emergency communication systems. |
The chain, end to end
Read a row left to right and you have the whole path: the measure the directive requires, the units your national supervisor reads, then the controls of the frameworks you already run. Each column is mapped at the level that framework actually publishes — control, category, layer, domain or ISO equivalence. Two publish no stable identifiers at all, and that is recorded as a fact rather than filled in.
| NIS2 art. 21(2) Directive (EU) 2022/2555 | CyFun | IT-Grundschutz | E-ITS | Kybermittari | ACN measures | ReCyF | ZKB measures | HR Uredba | QNRCS | NSC | HU protective measures | BIO2 | ISO 27001 enterprise | NIST 800-53 enterprise |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| (a) Risk analysis | GV.OC GV.RM GV.PO ID.RA | ISMS CON ORP | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RISK PROGRAM | — | — | § 3 § 4 § 6 § 8 | — | IDENTIFICAR | RA PL PM | — | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | DE.CM DE.AE RS.MA RS.AN RS.CO RS.MI | DER OPS | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | RESPONSE SITUATION | — | — | § 14 § 21 § 22 § 23 | — | DETETAR RESPONDER | IR AU SI | — | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | PR.DS PR.IR RC.RP RC.CO | CON OPS INF IND | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | RESPONSE ARCHITECTURE | — | — | § 15 § 17 § 26 | — | RECUPERAR PROTEGER | CP PE | — | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | GV.SC ID.RA | ORP OPS | 5.19 5.20 5.21 5.22 5.23 | DEPENDENCIES | — | — | § 9 | — | IDENTIFICAR PROTEGER | SR SA | — | 5.19 5.20 5.21 5.22 5.23 | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | ID.RA PR.PS | CON APP OPS IND | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | THREAT ARCHITECTURE | — | — | § 11 § 12 § 24 § 27 | — | IDENTIFICAR PROTEGER | SA CM MA RA SI | — | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | GV.OV ID.IM | ISMS DER | 5.33 5.35 5.36 8.16 | PROGRAM RISK | — | — | § 3 § 16 | — | IDENTIFICAR | CA PM | — | 5.33 5.35 5.36 8.16 | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | PR.AT PR.PS | ORP CON | 5.37 6.3 8.7 | WORKFORCE | — | — | § 4 § 10 | — | PROTEGER | AT SI CM | — | 5.37 6.3 8.7 | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | PR.DS | CON NET | 8.24 | ARCHITECTURE | — | — | § 25 | — | PROTEGER | SC | — | 8.24 | 8.24 | SC |
| (i) HR, access, assets | GV.RR ID.AM PR.AA | ORP CON SYS APP IND | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | ACCESS ASSET WORKFORCE | — | — | § 5 § 7 § 10 § 13 § 20 | — | IDENTIFICAR PROTEGER | PS AC IA CM MP PE | — | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | PR.AA PR.IR | NET SYS APP | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | ACCESS ARCHITECTURE | — | — | § 18 § 19 | — | PROTEGER | IA AC SC | — | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
Mapped at NIST CSF 2.0 category level.
Category level, not subcategory. No official crosswalk from CyFun subcategories to article 21(2) exists; treat this as a scoping aid, not as a substitute for reading the controls at your assurance level.
Mapped at IT-Grundschutz layer level.
Layer level, not module. Module identifiers change between editions of the Kompendium, so a module-level map would go stale; scope with this, then take the module list from the edition you are working to. The IND layer is mapped to continuity, maintenance and asset control because NIS2 covers OT-heavy sectors — energy, water, manufacturing — where industrial systems carry those outcomes and general IT modules do not reach them.
Mapped at ISO/IEC 27001:2022 Annex A control level.
This maps the ISO equivalent rather than E-ITS itself, because RIA publishes no crosswalk of its own to article 21(2). The E-ITS measures do have stable public identifiers — ORP.1.M1 and the like — and the catalogue below carries every one of them.
Mapped at Kybermittari domain level.
Domain level. The model scores capability maturity, not conformity, so it tells you where you are weak rather than whether you meet a legal obligation. It also says nothing about which MIL satisfies article 21(2) — nothing does, because the directive sets no maturity target. CRITICAL is not placed against a measure here: it is Traficom's own addition, and putting it under a letter would be our invention rather than their model.
Mapped at ACN determination (basic / specialist set) level.
No stable public identifier set to map against, and the determinations can be revised without amending D.Lgs. 138/2024. Read the determination in force — a mapping published here would be a snapshot of a moving target.
Mapped at ReCyF security objective (important / essential grade) level.
No stable public control identifiers, and the framework sits on a law that was not promulgated as of July 2026. Treat it as the best available statement of ANSSI expectations, not as a control set to map one-to-one.
Mapped at decree paragraph (§) level.
The headings are unambiguous but the § themselves are detailed: a § match tells you which paragraph to read, not that its requirements are met. The lower-obligations regime has its own decree (410/2025 Sb.) with a lighter set — this mapping is of the higher regime.
Mapped at Annex II measure, per level level.
Not recorded yet at measure level. Secondary sources report thirteen measures in Annex II; we have not confirmed that against the official annex, so we do not publish the count as fact. The levels above are confirmed.
Mapped at QNRCS function level.
Function level is the coarsest mapping in this hub. A function covers many measures at three capability levels each, so a function match locates the area to read and nothing more. The measure count is not recorded yet.
Mapped at NIST SP 800-53 Rev. 5 control family level.
Family level, inherited from the NIST mapping. And the NSC are recommendations: a family match locates your evidence, it does not discharge the Polish statute.
Mapped at protective measure category (Appendix 2) level.
Not recorded yet at category level. The category names reported so far — programme management, access control, awareness and training, logging, supply chain risk management — read like the NIST SP 800-53 family set, and nineteen is a suggestive count. We are not publishing that as a mapping: an equivalence inferred from five names out of nineteen would be a guess wearing a citation.
Mapped at ISO/IEC 27002:2022 control level.
The ISO controls map; the overheidsmaatregelen do not, because their identifiers and their number are not transcribed here yet. That gap matters: they are exactly the part specific to the Dutch government, and the part the Cbw makes legally binding.
Mapped at ISO/IEC 27001:2022 Annex A control level.
Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
Mapped at NIST SP 800-53 Rev. 5 control family level.
Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
National law renumbers these
Belgium carries them at article 30 of the Law of 26 April 2024 — and adds an eleventh, a coordinated vulnerability disclosure policy. Planning against the directive's numbering alone leaves you short of a measure there. Each country page records its own numbering.
Which of them names its measures, one by one
A mapping says which of the ten measures a framework serves. A catalogue says which requirement, at which assurance level, scored how. They are not the same work, and the frameworks are far from equal on the second: 3 of 14 publish no citable identifier at all, and 2 attach a maturity scale. We hold 6 of them requirement by requirement so far.
And how much of it there is
These counts are not interchangeable. Each framework names its own unit — an Anforderung is not a requirement is not a practice — so a longer bar means a finer breakdown, not a heavier obligation. What it does tell you is the shape of the reading ahead: IT-Grundschutz holds 2 124 units where CyFun holds 218.
- IT-Grundschutz 2 124 Anforderung
- E-ITS 1 802 measure
- NIST 800-53 1 196 control
- ZKB measures 442 provision
- Kybermittari 325 practice
- CyFun 218 requirement
| Framework | Owner publishes ids | What we hold | Held at | Maturity scale | Levels |
|---|---|---|---|---|---|
| CyFun | Yes | Every requirement | 218 requirements | Yes | 4 |
| IT-Grundschutz | Yes | Every requirement | 2124 Anforderungs | Not recorded yet | 3 |
| E-ITS | Yes | Every requirement | 1802 measures | Not recorded yet | — |
| Kybermittari | Yes | Every requirement | 325 practices | Yes | — |
| ACN measures | No stable public ids | Nothing to cite | ACN determination (basic / specialist set) | Not recorded yet | 2 |
| ReCyF | No stable public ids | Nothing to cite | ReCyF security objective (important / essential grade) | Not recorded yet | 2 |
| ZKB measures | Yes | Every requirement | 442 provisions | Not recorded yet | 2 |
| HR Uredba | No stable public ids | Nothing to cite | Annex II measure, per level | Not recorded yet | 3 |
| QNRCS | Yes | Unit level only | QNRCS function | Not recorded yet | 3 |
| NSC | Yes | Unit level only | NIST SP 800-53 Rev. 5 control family via NIST 800-53 | Not recorded yet | — |
| HU protective measures | Yes | Unit level only | protective measure category (Appendix 2) | Not recorded yet | 2 |
| BIO2 | Yes | Unit level only | ISO/IEC 27002:2022 control via ISO 27001 | Not recorded yet | — |
| ISO 27001 enterprise | Yes | Unit level only | ISO/IEC 27001:2022 Annex A control | Not recorded yet | — |
| NIST 800-53 enterprise | Yes | Every requirement | 1196 controls | Not recorded yet | 3 |
Two columns, two different facts
Owner publishes ids is about the framework: whether anyone can cite one of its requirements by a stable identifier. What we hold is about this site, and it is the honest half. Every requirement means we carry each one with its assurance level, its key-measure status and what its owner relates it to. Unit level only means we cite the layer, domain or category the framework publishes at, and the detail underneath is still to transcribe — that is our queue, not a gap in the framework.
Which yardstick applies where
| Member state | Transposition | Competent authority | Assessment framework | Law detail |
|---|---|---|---|---|
| Austria | Bundesamt für Cybersicherheit | None published | Recorded | |
| Belgium | Transposed | Centre for Cybersecurity Belgium | CyFun | Recorded |
| Bulgaria | Transposed | Ministry of e-Government | None published | Recorded |
| Cyprus | Transposed | Digital Security Authority | None published | Recorded |
| Czechia | Transposed | NÚKIB | ZKB measures | Recorded |
| Germany | Transposed | BSI | IT-Grundschutz | Recorded |
| Denmark | Transposed | Styrelsen for Samfundssikkerhed | None published | Recorded |
| Estonia | Transposed | Information System Authority | E-ITS | Recorded |
| Spain | Not complete | INCIBE / CCN | None published | Recorded |
| Finland | Transposed | Traficom | Kybermittari | Recorded |
| France | Not complete | ANSSI | ReCyF | Recorded |
| Greece | Transposed | National Cybersecurity Authority | None published | Recorded |
| Croatia | Transposed | SOA / ZSIS | HR Uredba | Recorded |
| Hungary | Transposed | SZTFH | HU protective measures | Recorded |
| Ireland | Not complete | NCSC Ireland | CyFun | — |
| Italy | Transposed | ACN | ACN measures | Recorded |
| Lithuania | Transposed | NKSC | None published | Recorded |
| Luxembourg | Transposed | ILR / HCPN | None published | Recorded |
| Latvia | Transposed | National Cybersecurity Centre | None published | Recorded |
| Malta | Transposed | Critical Infrastructure Protection Dept. | None published | Recorded |
| Netherlands | Transposed | RDI | BIO2 | Recorded |
| Poland | Transposed | Ministry of Digital Affairs | NSC | Recorded |
| Portugal | Transposed | CNCS | QNRCS | Recorded |
| Romania | Transposed | DNSC | CyFun | Recorded |
| Sweden | Transposed | NCSC at FRA (Försvarets radioanstalt) | None published | Recorded |
| Slovenia | Transposed | URSIV | None published | Recorded |
| Slovakia | Transposed | NBU | None published | Recorded |
On a narrow screen the competent authority and law columns are hidden. Both are on each member state's page — tap a country name.
« None published » means we examined that state and found no national assessment framework for private entities in scope — the reason is on its page, and it is usually that the obligations sit directly in the law or in an authority decree. It does not mean the state has nothing to say. « Not examined yet » would mean we have not looked; there are none left.