Last updated: 28 September 2026
Quick answer: NIS2 Article 21 requires essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage cybersecurity risk. It follows an all-hazards approach and lists ten minimum measures, from risk analysis and incident handling to supply chain security, cryptography and multi-factor authentication. Management bodies must approve and oversee them.
For a CISO, Article 21 is the part of NIS2 that turns into a work programme. It is short, but each of its ten measures covers a domain that most security teams already recognise from ISO 27001 or NIST CSF. The challenge is showing a regulator that those controls exist, fit your risk and actually work.
This guide walks through the NIS2 Article 21 cybersecurity risk-management measures one by one, explains what “proportionate” means, how Article 20 makes the board accountable, and how to build an evidence pack you can defend.
What are the NIS2 Article 21 cybersecurity risk-management measures?
They are the minimum security obligations that the NIS2 Directive (EU) 2022/2555 places on essential and important entities. Article 21(1) requires measures to manage the risks to the network and information systems you use to run your operations or provide your services, and to prevent or minimise the impact of incidents on recipients of those services.
Article 21(2) then says the measures must be based on an all-hazards approach and include at least ten elements, labelled (a) to (j). “All-hazards” means you consider physical events such as fire, flood or power loss, as well as cyber attacks.
Member states had to transpose NIS2 by 17 October 2024, according to the European Commission’s NIS2 page. Your exact obligations therefore come from the national law in each country where you are in scope, but those laws must implement Article 21 at a minimum. If you are unsure whether you are essential or important, our NIS2 scope decision guide walks through the tests.
The ten minimum measures explained
Each measure below is summarised in plain language, with what a supervisor is likely to expect to see.
(a) Policies on risk analysis and information system security
A documented risk assessment method and an information security policy approved by management. Expect questions on how often you reassess risk and how results drive control decisions.
(b) Incident handling
Procedures to detect, analyse, contain and recover from incidents. This links directly to the reporting duties in Article 23, so your incident process must be able to classify an incident as significant quickly.
(c) Business continuity and crisis management
Backup management, disaster recovery and crisis management. Supervisors will look for tested backups and recovery plans, not just documents.
(d) Supply chain security
Security aspects of relationships with direct suppliers and service providers. Article 21(3) adds that you must consider each supplier’s specific vulnerabilities, the overall quality of their products and cybersecurity practices, including secure development, and the results of coordinated EU supply chain risk assessments.
(e) Security in acquisition, development and maintenance
Secure procurement and development of network and information systems, including vulnerability handling and disclosure.
(f) Assessing effectiveness
Policies and procedures to assess whether your cybersecurity measures work, such as internal audits, metrics, control testing and penetration tests.
(g) Cyber hygiene and training
Basic cyber hygiene practices, such as patching, secure configuration and password rules, and cybersecurity training for staff.
(h) Cryptography and encryption
Policies on the use of cryptography and, where appropriate, encryption, including key management.
(i) Human resources security, access control and asset management
Screening and joiner, mover and leaver processes, least-privilege access, and an up-to-date asset inventory.
(j) Multi-factor authentication and secure communications
Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communication systems, where appropriate.
Common mistake: treating the list as the whole requirement. The ten items are a floor. Article 21(1) still requires measures appropriate to your risk, so a high-risk entity may need to go well beyond them.
What does “appropriate and proportionate” mean?
It means your measures should match your risk exposure, not a one-size-fits-all checklist. Article 21(1) lists the factors to weigh: the state of the art, relevant European and international standards, the cost of implementation, your size, your exposure to risk, the likelihood of incidents and their potential severity, including societal and economic impact.
In practice this gives you room to scale controls, but it also shifts the burden onto you to justify your choices. A documented risk assessment that links each decision to these factors is your best defence if a supervisor asks why a control is lighter than expected.
In practice: record the proportionality reasoning next to each control, for example “MFA enforced for all remote and privileged access; not yet for on-site kiosk accounts because of X, compensating control Y, review by Z date”.
Are there more detailed rules for some sectors?
Yes. Article 21(5) required the Commission to adopt implementing acts for certain digital providers. Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 sets detailed technical and methodological requirements for DNS service providers, TLD name registries, cloud computing and data centre service providers, content delivery networks, managed service providers, managed security service providers, online marketplaces, search engines, social networking platforms and trust service providers.
ENISA supports this with its NIS2 technical implementation guidance, published on 26 June 2025, which gives practical advice, examples of evidence and mappings to standards. Even if you are not in one of these sectors, the Implementing Regulation and ENISA’s examples are a useful benchmark for what “good” looks like.
Is Article 21 about to change?
Possibly, but not yet. On 20 January 2026 the Commission published a proposal for targeted amendments to NIS2 as part of its cybersecurity package. It would let the Commission adopt implementing acts on security measures for more types of entity, limit member states from adding extra technical requirements where such acts exist, and allow certification to reduce additional security audits. At the time of writing the proposal is still going through the EU legislative process, so the current Article 21 text and your national law continue to apply.
How does Article 20 make management accountable?
Article 20 requires management bodies of essential and important entities to approve the Article 21 measures, oversee their implementation and be capable of being held liable for infringements. Members of management bodies must also follow training so they can identify risks and assess cybersecurity practices.
For a CISO, this changes the reporting line. Your board is no longer just informed about cyber risk; it has to approve the measures and understand them. That means clear risk reporting, a documented approval of the security programme, and training records for directors.
Mapping Article 21 to the controls you already run is much faster with the right tooling. You can start your 14-day free trial of Enactia’s AI-powered GRC platform and see NIS2 cross-mapped to ISO 27001 and other frameworks.
How do Article 21 measures map to ISO 27001?
Most Article 21 measures map closely to ISO/IEC 27001:2022 clauses and Annex A controls. The table below is an indicative mapping to help you reuse an existing ISMS. It is not an official correspondence, so check the Implementing Regulation and ENISA’s mapping where they apply to you.
| Article 21(2) | Measure | Indicative ISO 27001:2022 reference | Typical evidence |
|---|---|---|---|
| (a) | Risk analysis and security policies | Clauses 5.2, 6.1.2, 6.1.3; A.5.1 | Risk methodology, risk register, approved policy |
| (b) | Incident handling | A.5.24 to A.5.28 | Incident procedure, logs, post-incident reviews |
| (c) | Business continuity, backup, crisis management | A.5.29, A.5.30, A.8.13, A.8.14 | BCP, DR tests, backup restore reports |
| (d) | Supply chain security | A.5.19 to A.5.23 | Supplier inventory, assessments, contract clauses |
| (e) | Secure acquisition, development, vulnerability handling | A.8.8, A.8.25 to A.8.29 | Secure SDLC, vulnerability management records |
| (f) | Effectiveness assessment | Clauses 9.1 to 9.3; A.5.35 | KPIs, internal audit reports, management review |
| (g) | Cyber hygiene and training | A.6.3, A.8.9, A.8.19 | Training records, hardening baselines, patch reports |
| (h) | Cryptography and encryption | A.8.24 | Crypto policy, key management procedure |
| (i) | HR security, access control, asset management | A.5.9 to A.5.18; A.6.1 to A.6.6 | Asset inventory, access reviews, leaver checklists |
| (j) | MFA and secure communications | A.5.14, A.8.5 | MFA coverage report, secure comms configuration |
If you already hold ISO 27001 certification, see our guide on NIS2 to ISO 27001:2022 mapping and the ISO 27001 framework page for how to reuse your ISMS evidence.
What happens if you do not comply?
Supervisors can order corrective action and impose fines. Article 21(4) requires an entity that finds it does not comply to take all necessary, appropriate and proportionate corrective measures without undue delay.
Under Article 34, member states must provide for maximum fines of at least EUR 10 million or 2% of total worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4% for important entities, whichever is higher. Essential entities also face proactive supervision, while important entities are generally supervised after the fact, for example following an incident or evidence of non-compliance.
How do you build an Article 21 evidence pack?
Build it around the ten measures, with one owner and one set of evidence per measure. Use this checklist as a starting point.
- Confirm scope. Record which national laws apply and whether you are essential or important in each.
- Run a gap assessment. Assess each of the ten measures against your current controls, using a structured compliance assessment.
- Update the risk register. Link each risk to the measure and control that treats it, using an enterprise risk management process.
- Approve policies. Get management body approval for the security policy set and record it.
- Tackle suppliers. Inventory critical ICT suppliers, assess them and update contracts, ideally in a vendor and third-party risk management workflow.
- Test. Run incident, backup restore and continuity tests, and keep the reports.
- Train the board. Deliver and record management body training under Article 20(2).
- Measure and review. Report effectiveness metrics to management at least annually.
Key takeaways
- NIS2 Article 21 sets ten minimum measures, (a) to (j), under an all-hazards approach.
- Measures must be appropriate and proportionate, and you must be able to justify your choices.
- Implementing Regulation (EU) 2024/2690 adds detailed rules for digital infrastructure and digital providers.
- Article 20 makes management bodies approve, oversee and train on cybersecurity measures.
- An existing ISO 27001 ISMS covers much of Article 21, but gaps usually remain in supply chain and board governance.
Frequently asked questions
Who must comply with NIS2 Article 21?
Essential and important entities as defined in NIS2 and in each member state’s transposing law. This generally covers medium and large organisations in the sectors listed in Annexes I and II, plus some entities regardless of size, such as certain digital infrastructure providers. Check the national law in each country where you operate.
Is ISO 27001 certification enough for NIS2 Article 21?
Not automatically. ISO 27001 covers most Article 21 domains, but NIS2 adds specific expectations on supply chain security, management body approval and training, and incident reporting. National laws or Implementing Regulation (EU) 2024/2690 may add detailed requirements. Treat certification as strong evidence, then close the remaining gaps.
Does NIS2 require multi-factor authentication?
Article 21(2)(j) requires the use of multi-factor or continuous authentication solutions, secured communications and secured emergency communication systems where appropriate. The words “where appropriate” allow a risk-based approach, but you should document where MFA is not used and what compensating controls apply.
Are management bodies personally liable under NIS2?
Article 20 requires that management bodies approve the Article 21 measures, oversee their implementation and can be held liable for infringements. The detail of liability depends on national law. Board members must also follow cybersecurity training so they can understand and challenge the measures they approve.
What are the fines for breaching Article 21?
Member states must allow maximum fines of at least EUR 10 million or 2% of worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4% for important entities, whichever is higher. National laws can set higher maximums, and supervisors can also use binding instructions and other corrective measures.
Conclusion: turn Article 21 into a managed programme
NIS2 Article 21 is short, but it touches every part of a security programme. Treat the ten measures as the structure of your programme, justify proportionality in writing, reuse ISO 27001 evidence where you can, and bring your board into approval and oversight early. That is what a supervisor will look for.
To see how cross-framework mapping can reduce NIS2 effort, contact us or book a demo or start your 14-day free trial.
This article is for general information and is not legal advice.
