NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
NIS2 Article 21 Requirements Explained
Learn

NIS2 Article 21 Requirements Explained

·Alexander Sverdlov

Article 21 of Directive (EU) 2022/2555, the NIS2 Directive, is the article that tells essential and important entities what they must actually do. Paragraph 1 requires appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the network and information systems the entity uses for its operations or to provide its services, and to prevent or minimise the impact of incidents on the recipients of those services and on other services. Paragraph 2 lists ten measures that those arrangements must include at least, based on an all-hazards approach. Paragraph 3 explains what supply chain security means. Paragraph 4 requires corrective measures without undue delay when an entity finds it does not comply. Paragraph 5 gave the Commission the power to fix the technical detail for eleven digital sectors, which it did in Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024.

Two things about the article shape every programme built on it. The list is a floor, not a ceiling: Article 21(2) says the measures "shall include at least the following". And the measures are sized by risk rather than by checklist: Article 21(1) requires them to ensure a level of security appropriate to the risks posed, taking into account the state of the art, relevant European and international standards, and the cost of implementation.

FactDetail
Legal basisArticle 21 of Directive (EU) 2022/2555, with the management body duties in Article 20, the reporting duties in Article 23 and the fine ceilings in Article 34.
Who it bindsEssential and important entities as defined in Article 3. Both tiers face the same ten measures; the difference is in supervision and enforcement.
The measuresTen, in Article 21(2), points (a) to (j), on an all-hazards approach covering network and information systems and their physical environment.
ProportionalityArticle 21(1): degree of exposure to risk, size of the entity, likelihood of incidents and their severity, including societal and economic impact.
Technical detailImplementing Regulation (EU) 2024/2690 for DNS, TLD registries, cloud, data centres, CDNs, managed and managed security service providers, marketplaces, search engines, social networks and trust service providers.
In forceMember States had to transpose by 17 October 2024 and apply their measures from 18 October 2024 (Article 41). The list of entities was due by 17 April 2025 (Article 3(3)).
The ten Article 21(2) measures of NIS2 arranged around a programme: risk analysis policies, incident handling, business continuity and crisis management, supply chain security, secure acquisition and development, and the five further points (f) to (j)

What does Article 21(1) require before the list starts?

Article 21(1) is the part most summaries skip, and it is where a supervisor starts. It requires Member States to ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures. Three adjectives, three kinds of measure. A programme that is entirely technical, or entirely policy, fails the sentence on its own terms.

The second subparagraph fixes how the measures are sized. They must ensure a level of security of network and information systems appropriate to the risks posed, taking into account the state of the art and, where applicable, relevant European and international standards, as well as the cost of implementation. When assessing proportionality, due account must be taken of the degree of the entity's exposure to risks, the entity's size, and the likelihood of occurrence of incidents and their severity, including their societal and economic impact. That last phrase is why the same measure can be adequate for one entity and inadequate for another in the same sector: a hospital's incident severity includes patients, and a payment processor's includes everyone downstream.

The five factors Article 21(1) of NIS2 uses to size the measures: degree of exposure to risk, size of the entity, likelihood of incidents, severity including societal and economic impact, and the state of the art and cost of implementation

What are the ten measures in Article 21(2)?

Article 21(2) requires the measures to be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents. It then lists what they must include at least. The wording below is the Directive's own.

PointThe measureWhat it asks of you in practice
(a)Policies on risk analysis and information system securityA written risk analysis method, a security policy the management body approved under Article 20, and a record of both being applied.
(b)Incident handlingDetection, classification, response and recovery, wired to the Article 23 clocks so a significant incident produces an early warning within 24 hours.
(c)Business continuity, such as backup management and disaster recovery, and crisis managementBackups that are tested, recovery objectives that are written down, and a crisis structure that has been exercised.
(d)Supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providersA supplier register, security requirements in contracts, and assessments that follow Article 21(3).
(e)Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosureSecure procurement and development practices, patch management, and a way for outsiders to report vulnerabilities.
(f)Policies and procedures to assess the effectiveness of cybersecurity risk-management measuresTesting that the other nine work, on a schedule, with results recorded. This is the point that makes the programme permanent.
(g)Basic cyber hygiene practices and cybersecurity trainingBaseline practices for everyone and training that can be evidenced, alongside the management body training in Article 20(2).
(h)Policies and procedures regarding the use of cryptography and, where appropriate, encryptionA cryptography policy: what is encrypted, at rest and in transit, with which algorithms and key management.
(i)Human resources security, access control policies and asset managementJoiner, mover and leaver controls, an access policy, periodic access reviews, and an asset inventory that is current.
(j)The use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriateMFA where the risk analysis says it is appropriate, and secured channels for the people who run incidents.

Read together, the list runs from governance to technology and back. Points (a) and (f) bracket it: the first requires the analysis that decides what is proportionate, and the sixth requires proof that the result works. Everything in between is what a certified management system already contains, which is why our guide to NIS2 against ISO 27001 maps most of Article 21 onto Annex A and then lists the four gaps certification leaves open.

What does Article 21(3) add on supply chain security?

Point (d) is the measure entities most often under-specify, so Article 21(3) spells it out. When considering which supply chain measures are appropriate, entities must take into account the vulnerabilities specific to each direct supplier and service provider, and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures. They must also take into account the results of the coordinated security risk assessments of critical supply chains carried out under Article 22(1).

Two consequences follow for the budget and the calendar. The duty is per supplier, so it scales with the supplier count, and it is about the supplier's practices rather than a signed questionnaire. And it recurs, because practices change and the Article 22 assessments are published over time. Our guide to what NIS2 compliance costs treats supply chain as its own budget line for exactly this reason.

NIS2 Article 21 by the numbers: ten minimum measures in Article 21(2), a 24 hour early warning under Article 23(4)(a), a fine ceiling of EUR 10 million or 2 percent of worldwide turnover for essential entities under Article 34(4), and national measures applying from 18 October 2024 under Article 41(1)

What does Article 21(4) require when you find a gap?

Article 21(4) requires an entity that finds it does not comply with the measures in paragraph 2 to take, without undue delay, all necessary, appropriate and proportionate corrective measures. It is a short paragraph with a long reach. It means a gap assessment is not a neutral exercise: the moment you know a measure is missing, the duty to fix it starts running. It also means a supervisor reading your risk register can ask when each open item was found and what happened next. A programme that records findings without dated corrective actions has documented its own infringement.

What does Implementing Regulation (EU) 2024/2690 add?

Article 21(5) required the Commission to adopt, by 17 October 2024, implementing acts laying down the technical and methodological requirements of the ten measures for DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online marketplaces, online search engines and social networking platforms, and trust service providers. The Commission did so on that date in Implementing Regulation (EU) 2024/2690.

For those entities, Article 2(1) of the Regulation makes the Annex the definition of the ten measures. The Annex has thirteen sections, each tied back to a point of Article 21(2): a policy on the security of network and information systems, a risk management policy, incident handling, business continuity and crisis management, supply chain security, secure acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, human resources security, access control, asset management, and environmental and physical security. Article 2(2) preserves proportionality but attaches a paper trail to it: where the Annex says a requirement applies "where appropriate", "where applicable" or "to the extent feasible" and the entity decides it does not apply, the entity must document its reasoning in a comprehensible manner.

The Regulation also settles what counts as a significant incident for those sectors. Article 3 lists the general criteria, including direct financial loss exceeding EUR 500 000 or 5 percent of annual turnover, whichever is lower, and Article 4 treats incidents that recur at least twice within six months with the same apparent root cause as one significant incident when together they meet that loss criterion. Articles 5 to 14 add sector-specific thresholds. Entities outside the eleven sectors are not bound by the Annex, but the Commission may adopt further implementing acts for them under the second subparagraph of Article 21(5), and many supervisors read the Annex as the clearest available statement of what "appropriate" means.

Three layers of text behind NIS2 Article 21: the ten measures in the Directive that bind every entity, the thirteen Annex sections of Implementing Regulation (EU) 2024/2690 that bind the digital sectors, and the 27 national transpositions that add their own detail

How do Articles 20 and 23 connect to Article 21?

Article 21 does not stand alone. Article 20(1) requires the management bodies of essential and important entities to approve the cybersecurity risk-management measures taken to comply with Article 21, to oversee their implementation, and makes them liable for infringements of that Article by the entity. Article 20(2) requires the members of those bodies to follow training so that they can identify risks and assess risk-management practices, and encourages entities to offer similar training to employees regularly. The approval is a dated act and a supervisor will ask to see it.

Article 23 is the other half of point (b). Article 23(4) requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours with an initial assessment of severity and impact, an intermediate report on request, and a final report not later than one month after the notification. Trust service providers must file the notification itself within 24 hours. Incident handling under Article 21(2)(b) is what makes those deadlines achievable, and our comparison of incident reporting deadlines by regulation places the NIS2 clocks beside the GDPR, DORA, AI Act and CRA ones.

How is Article 21 enforced?

Article 34(4) requires Member States to make infringements of Article 21 or 23 by essential entities subject to administrative fines with a maximum of at least EUR 10 000 000 or at least 2 percent of total worldwide annual turnover of the undertaking the entity belongs to, whichever is higher. Article 34(5) sets the corresponding figures for important entities at EUR 7 000 000 or 1.4 percent. Those are floors for the national maximum, so a transposition may go higher.

The fine is not the sharpest tool. Article 32(4) gives competent authorities powers over essential entities that include binding instructions with deadlines, orders to bring the measures into line with Article 21 in a specified manner and period, orders to implement audit recommendations, a designated monitoring officer, and orders to make aspects of an infringement public. Article 32(5) adds, where those measures fail, the power to have a certification or authorisation temporarily suspended and to have the chief executive or legal representative temporarily prohibited from exercising managerial functions. Our guides to NIS2 fines and penalties and to what to expect from a NIS2 audit cover the graduated powers and how they are used.

What Article 21 readiness looks like on a board: Article 21(2) measures with current evidence, direct suppliers assessed under Article 21(3), days since the last effectiveness test under Article 21(2)(f), and whether the Article 20 management body approval is on file

What the other results get wrong

The first error is presenting the ten points as ten controls. Each point is a category. Point (i) alone contains human resources security, access control and asset management, and the implementing regulation splits it across three Annex sections. A gap assessment with ten rows is not a gap assessment.

The second is skipping paragraph 1. Pages that start at the list treat every measure as mandatory in the same form for everyone, which is not what the Directive says. The measures are appropriate and proportionate, sized by exposure, size, likelihood and severity, and the cost of implementation is a legitimate input. The flip side is that the reasoning has to exist: an entity that scales a measure down needs the risk analysis under point (a) that justifies it, and for the digital sectors Article 2(2) of the implementing regulation requires that reasoning to be documented.

The third is forgetting point (f). Several results describe NIS2 as a project that ends at implementation. Article 21(2)(f) requires policies and procedures to assess the effectiveness of the measures, which means testing on a cycle, forever. Our guide to how long NIS2 compliance takes separates the build phases from the evidence work that never closes.

Where do you stand?

Fill this in from your own records. A blank row is a finding waiting for a supervisor to make it.

QuestionYour answerArticle
Which of the ten measures can you evidence today, rather than describe?Art. 21(2)(a) to (j)
Where is the risk analysis that justifies the size of each measure?Art. 21(1) and 21(2)(a)
When did the management body approve the measures, and where is the record?Art. 20(1)
Which direct suppliers have been assessed for their practices, and when?Art. 21(3)
When was effectiveness last tested, and what did the test find?Art. 21(2)(f)
For each open gap, what corrective action was taken and on what date?Art. 21(4)
Can you produce an early warning within 24 hours, out of hours?Art. 23(4)(a)

If several rows are blank, start with scope and then with evidence. Our guide to what NIS2 is and who must comply settles whether you are essential or important, our free NIS2 compliance checklist scores the ten measures in a spreadsheet, and a free compliance check tells you which rows you can evidence today. Our NIS2 compliance software carries the ten measures as tracked controls with an owner and evidence, runs the Article 23 clocks, and keeps the Article 20 approval beside the measures it approved. Entities that also fall under DORA should read how DORA and NIS2 differ before building two programmes.

The bottom line on NIS2 Article 21: ten measures, one all-hazards approach, tested for effectiveness

Frequently asked questions

Do important entities have fewer Article 21 obligations than essential ones?

No. Article 21 applies to essential and important entities alike, and the ten measures are the same. The tiers differ in supervision, which is proactive for essential entities, and in the fine ceilings in Article 34(4) and (5).

Is multi-factor authentication mandatory under NIS2?

Point (j) requires the use of multi-factor authentication or continuous authentication solutions "where appropriate". Appropriateness is decided by the risk analysis under point (a) and the proportionality test in Article 21(1). For the eleven digital sectors, the Annex to Implementing Regulation (EU) 2024/2690 sets the detail, and a decision not to apply a "where appropriate" requirement must be documented under its Article 2(2).

Does ISO 27001 certification satisfy Article 21?

It covers most of the measures, but not the reporting clocks in Article 23, the management body approval and training in Article 20, or national registration. Article 21(1) also refers to relevant European and international standards as an input to what is appropriate, which supports using a certified system as the evidence base.

Does the implementing regulation apply to my hospital or energy company?

Not directly. Implementing Regulation (EU) 2024/2690 binds the eleven digital sectors named in Article 21(5). For other sectors the Directive and the national transposition apply, and the Commission may adopt further implementing acts under the second subparagraph of Article 21(5).

What is the deadline for complying with Article 21?

Article 41 required Member States to apply their transposing measures from 18 October 2024. The obligations bind entities from the date fixed in national law, which in some Member States came later because transposition was late. There is no separate grace period in the Directive for the Article 21 measures.

Primary sources

Article references above are taken from Articles 3, 20, 21, 23, 32, 34 and 41 of Directive (EU) 2022/2555 and from Articles 1 to 5 and the Annex of Commission Implementing Regulation (EU) 2024/2690. NIS2 is a directive, so the binding text is your national transposition, which may set higher fine ceilings, different registration duties and its own deadlines. Confirm the current national text before relying on a specific provision.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING