NIS2
The 10 NIS2 Article 21 Requirements
Article 21 of Directive (EU) 2022/2555 is the operational heart of NIS2. It requires every essential and important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to its network and information systems — and it names ten measures that those arrangements must, as a minimum, be based on.
| Measure | What it covers |
|---|---|
| (a) Risk analysis and information system security policies | A documented, repeatable method for identifying and assessing risks to your network and information systems, and a set of approved security policies built on the results. This is the foundation the other nine measures are justified against. |
| (b) Incident handling | Defined procedures for detecting, triaging, containing, resolving and recording incidents, with named roles, escalation paths and the internal timers that let you meet the 24-hour and 72-hour reporting deadlines. |
| (c) Business continuity and crisis management | Backup management, disaster recovery arrangements and a crisis management plan, including recovery time and recovery point objectives — and evidence that restores are actually tested, not just scheduled. |
| (d) Supply chain security | Security assessment of direct suppliers and service providers, taking account of their specific vulnerabilities and overall security practice, plus security requirements written into contracts and monitored over the relationship. |
| (e) Security in acquisition, development and maintenance | Security built into how you buy, build and maintain systems: secure development practices, change management, patch management and structured vulnerability handling and disclosure. |
| (f) Assessment of effectiveness | Policies and procedures for judging whether your risk-management measures actually work — internal audits, control testing, technical assessments and management review, with findings tracked to closure. |
| (g) Cyber hygiene and security training | Basic hygiene practices such as patching, least privilege, network segmentation and password practice, combined with regular awareness training for staff and role-specific training for those with security duties. |
| (h) Cryptography and encryption | A policy on the use of cryptography, covering encryption in transit and at rest, approved algorithms and key management — applied where the risk assessment shows it is warranted. |
| (i) HR security, access control and asset management | Screening and duties for personnel across joiner, mover and leaver processes, formal access control based on need-to-know, and a maintained inventory of the assets that support your services. |
| (j) Multi-factor authentication and secure communications | Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communication systems for use when normal channels are unavailable. |
The measures follow an all-hazards approach: they must protect systems against incidents of every origin, from ransomware and supplier compromise to fire, flood and power loss. They apply in full to every essential entity and important entity named by Article 21.
Just as importantly, they must be documented, not merely implemented. A supervisory authority cannot inspect an intention. When it asks how you handle supplier risk or how access rights are reviewed, the answer has to be a dated, approved, version- controlled document plus the records that prove it is followed — meeting minutes, training logs, test reports, review sign-offs. Organisations with genuinely good technical practice still fail NIS2 audits when nothing is written down.
Skip the blank page
The NIS2 Starter Kit gives you editable policy templates for these measures out of the box — risk management, incident handling, continuity, supply chain and access control, all mapped to the Article 21 lettering so you can show an auditor exactly what covers what.
See the NIS2 Starter Kit