Glossary
Article 21
The section of the NIS2 Directive that sets out the 10 mandatory cybersecurity risk-management measures.
Explained in depth: The 10 NIS2 security requirements
Every essential and important entity must implement measures covering risk analysis, incident handling, business continuity, supply chain security, and more — proportionate to their size and risk exposure. Article 21 also requires the measures to be documented, because a supervisory authority assesses written, approved policies and the records proving they are followed.