Glossary · NIS2

Article 21

The section of the NIS2 Directive that sets out the 10 mandatory cybersecurity risk-management measures.

Explained in depth: The 10 NIS2 security requirements

Article 21 requires essential and important entities to take "appropriate and proportionate" technical, operational, and organisational measures across ten areas: (a) risk analysis and information system security policies; (b) incident handling; (c) business continuity, backup management, and crisis management; (d) supply chain security; (e) security in network and information systems acquisition, development, and maintenance, including vulnerability handling; (f) policies to assess the effectiveness of the measures; (g) basic cyber hygiene practices and cybersecurity training; (h) cryptography and, where appropriate, encryption; (i) human resources security, access control policies, and asset management; (j) multi-factor authentication, secured communications, and secured emergency communication systems where appropriate. The measures follow an all-hazards approach: they must protect against cyber attacks as well as physical incidents such as power failures or fires that affect network and information systems.

Why it matters

Article 21 is the operational core of NIS2. Every compliance programme, gap analysis, and audit maps back to these ten measures. They apply equally to essential and important entities.

Used in

See also

← All glossary terms