What policies and measures does NIS2 Article 21 require?
Article 21(2) of NIS2 lists ten minimum cybersecurity risk-management measures: risk analysis and security policies, incident handling, business continuity, supply-chain security, secure development and vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography, HR security and access control, and multi-factor authentication with secured communications.
Last updated: 2026-09-30
The ten measures of Article 21(2)
| Point | Measure |
|---|---|
| (a) | Policies on risk analysis and information system security |
| (b) | Incident handling |
| (c) | Business continuity β backup management, disaster recovery and crisis management |
| (d) | Supply-chain security, including relationships with direct suppliers and service providers |
| (e) | Security in acquisition, development and maintenance, including vulnerability handling and disclosure |
| (f) | Policies and procedures to assess the effectiveness of the measures |
| (g) | Basic cyber hygiene practices and cybersecurity training |
| (h) | Policies and procedures on cryptography and, where appropriate, encryption |
| (i) | Human resources security, access control policies and asset management |
| (j) | Multi-factor or continuous authentication, secured voice/video/text and emergency communications |
Proportionality
Article 21(1) requires measures that are appropriate and proportionate to your size, exposure to risks and the likely impact of incidents β an all-hazards approach, not a fixed control catalogue. For certain digital providers (such as DNS, cloud, data centre and managed service providers), Commission Implementing Regulation (EU) 2024/2690 specifies the technical requirements in more detail.
Related question
Does NIS2 require specific written policies?
Yes, several measures are explicitly policies and procedures β risk analysis and information system security (a), effectiveness assessment (f), cryptography (h), and access control (i) β and supervisors will expect them to be documented and approved by management.
Next steps
More answers:
For decision-support purposes only, not legal advice. Exact obligations depend on national transposition β use our free scope checker for a personalised assessment.