NIS2 guide
The ten NIS2 risk-management measures
Article 21 is the core of NIS2. It requires appropriate and proportionate measures to manage cyber risks and names ten areas every entity must cover. This page explains each area with practical examples and shows what an authority will want to see as evidence.
Last updated: October 2026 · Legal basis: Directive (EU) 2022/2555 (NIS2); details depend on national law
The principle: appropriate and proportionate
Article 21(1) requires essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems they use for their operations or services, and to prevent or minimise the impact of incidents. The measures must take into account the state of the art, relevant European and international standards and the cost of implementation.
Proportionality is assessed against the entity’s exposure to risk, its size, and the likelihood and severity of incidents, including their societal and economic impact. A 60-person manufacturer does not need the same security operations as a national electricity grid operator. It does need to cover all ten areas and be able to explain why its measures fit its risk.
The directive follows an all-hazards approach: the measures protect systems and their physical environment, not only against cyberattacks but also against events such as theft, fire, flood or power failure.
The ten minimum measures of Article 21(2)
| Point | Measure | Typical evidence |
|---|---|---|
| (a) | Policies on risk analysis and information system security | Approved security policy, documented risk assessment updated at least yearly |
| (b) | Incident handling | Incident process with roles, logging and alerting, records of past incidents |
| (c) | Business continuity, such as backup management and disaster recovery, and crisis management | Backup concept, restore test reports, contingency plan, crisis team list |
| (d) | Supply chain security, including relationships with direct suppliers and service providers | Supplier register, security clauses in contracts, supplier assessments |
| (e) | Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure | Patch deadlines and records, vulnerability scans, security requirements in procurement |
| (f) | Policies and procedures to assess the effectiveness of the measures | Internal audit plan and reports, metrics, tracked findings |
| (g) | Basic cyber hygiene practices and cybersecurity training | Training plan, attendance records, acceptable use policy |
| (h) | Policies and procedures on cryptography and, where appropriate, encryption | Cryptography policy, device encryption reports, key management rules |
| (i) | Human resources security, access control policies and asset management | Joiner, mover and leaver process, access reviews, asset inventory |
| (j) | Multi-factor or continuous authentication, secured voice, video and text communications and secured emergency communication systems, where appropriate | MFA coverage report, emergency communication plan and test |
The list is a minimum. National laws may add requirements, and some authorities have published their own frameworks or baseline measures. Our country versions describe these where they exist.
Implementing Regulation (EU) 2024/2690 for digital providers
For certain digital providers, the Commission has set out the technical and methodological requirements in detail. Implementing Regulation (EU) 2024/2690 applies to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online marketplaces, online search engines and social networking platforms, and trust service providers (Art. 1).
Its annex breaks the ten areas of Article 21(2) down into specific requirements, from the security policy and risk management policy to incident handling, business continuity and supply chain security. Where a requirement is not appropriate, not applicable or not feasible for an entity, the entity must document its reasons (Art. 2 of the regulation). The regulation also defines when an incident is significant for these providers (Art. 3 to 14).
For all other sectors, the regulation is not binding, but it is a useful benchmark. Some national authorities refer to it directly, and auditors often use it as a reference for what a mature implementation looks like.
Supply chain: the measure that reaches suppliers
Point (d) obliges entities to consider the vulnerabilities specific to each direct supplier and service provider, the overall quality of their products and cybersecurity practices, including their secure development procedures (Art. 21(3)). This is how NIS2 reaches companies that are not in scope themselves. Their customers ask for security clauses, questionnaires or certificates.
If you are a supplier, expect these requests and prepare a standard answer pack: your security policy, an overview of your measures, any certificates and a contact for security incidents. If you are in scope, start with a register of your critical suppliers and a short set of contract clauses covering incident notification, minimum measures and audit rights.
ISO/IEC 27001 and other frameworks
There is no NIS2 certificate. Article 21 does not prescribe a standard, but it refers to European and international standards. An information security management system based on ISO/IEC 27001 covers most of the ten areas and gives you a structure for evidence. It does not cover registration, the reporting deadlines of Article 23 or the specific duties of the management body under Article 20. Those you have to add.
Member States may require entities to use certified ICT products, services or processes under European cybersecurity certification schemes (Art. 24). Check your national law for such requirements.
Where to start
Begin with the measures that reduce the most risk for the least effort: multi-factor authentication for remote access, email and administrator accounts, tested offline backups, a patch process with deadlines, and an incident process with a reporting chain. Then build the policy framework and the risk assessment around them. Point (f) requires you to check effectiveness, so plan internal reviews from the start.
The NIS2 scoring asks two to three questions for each of the ten areas and shows where your gaps are. The checklist contains the same questions for a workshop with your team. Tools such as Sightadel help to track measures and evidence in one place.
Frequently asked questions
Do all ten measures apply to small important entities?
Yes. All ten areas apply to essential and important entities alike. Proportionality decides how far each measure goes, not whether it applies (Art. 21(1)).
Is ISO 27001 certification enough for NIS2?
It covers most of the measures in Article 21, but not registration, the reporting deadlines of Article 23 or the management duties of Article 20. There is no official NIS2 certificate.
Who has to apply Implementing Regulation 2024/2690?
DNS service providers, TLD name registries, cloud, data centre and CDN providers, managed (security) service providers, online marketplaces, search engines, social networks and trust service providers (Art. 1 of the regulation).
What does supply chain security mean for my suppliers?
You assess the security of direct suppliers and service providers and agree requirements with them (Art. 21(2)(d) and (3)). Suppliers that are not in scope receive these requirements through contracts.