NIS2

The 10 NIS2 Article 21 Requirements

Article 21 of Directive (EU) 2022/2555 is the operational heart of NIS2. It requires every essential and important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to its network and information systems — and it names ten measures that those arrangements must, as a minimum, be based on.

MeasureWhat it covers
(a) Risk analysis and information system security policiesA documented, repeatable method for identifying and assessing risks to your network and information systems, and a set of approved security policies built on the results. This is the foundation the other nine measures are justified against.
(b) Incident handlingDefined procedures for detecting, triaging, containing, resolving and recording incidents, with named roles, escalation paths and the internal timers that let you meet the 24-hour and 72-hour reporting deadlines.
(c) Business continuity and crisis managementBackup management, disaster recovery arrangements and a crisis management plan, including recovery time and recovery point objectives — and evidence that restores are actually tested, not just scheduled.
(d) Supply chain securitySecurity assessment of direct suppliers and service providers, taking account of their specific vulnerabilities and overall security practice, plus security requirements written into contracts and monitored over the relationship.
(e) Security in acquisition, development and maintenanceSecurity built into how you buy, build and maintain systems: secure development practices, change management, patch management and structured vulnerability handling and disclosure.
(f) Assessment of effectivenessPolicies and procedures for judging whether your risk-management measures actually work — internal audits, control testing, technical assessments and management review, with findings tracked to closure.
(g) Cyber hygiene and security trainingBasic hygiene practices such as patching, least privilege, network segmentation and password practice, combined with regular awareness training for staff and role-specific training for those with security duties.
(h) Cryptography and encryptionA policy on the use of cryptography, covering encryption in transit and at rest, approved algorithms and key management — applied where the risk assessment shows it is warranted.
(i) HR security, access control and asset managementScreening and duties for personnel across joiner, mover and leaver processes, formal access control based on need-to-know, and a maintained inventory of the assets that support your services.
(j) Multi-factor authentication and secure communicationsMulti-factor or continuous authentication, secured voice, video and text communications, and secured emergency communication systems for use when normal channels are unavailable.

The measures follow an all-hazards approach: they must protect systems against incidents of every origin, from ransomware and supplier compromise to fire, flood and power loss. They apply in full to every essential entity and important entity named by Article 21.

Just as importantly, they must be documented, not merely implemented. A supervisory authority cannot inspect an intention. When it asks how you handle supplier risk or how access rights are reviewed, the answer has to be a dated, approved, version- controlled document plus the records that prove it is followed — meeting minutes, training logs, test reports, review sign-offs. Organisations with genuinely good technical practice still fail NIS2 audits when nothing is written down.

Skip the blank page

The NIS2 Starter Kit gives you editable policy templates for these measures out of the box — risk management, incident handling, continuity, supply chain and access control, all mapped to the Article 21 lettering so you can show an auditor exactly what covers what.

See the NIS2 Starter Kit

Related reading

Frequently asked questions