Home NIS2 NIS2 — Article 21 ten cybersecurity risk-management measures, deep dive

NIS2 — Article 21 ten cybersecurity risk-management measures, deep dive

Last updated on Jun 03, 2026

What this article covers

NIS2 Article 21 lists ten cybersecurity risk-management measures that essential and important entities must implement. The text is short; the practice is substantial. This article walks each measure plainly and tells you what NexCyber tracks for it.

Article 21 in plain language

Essential and important entities must take "appropriate and proportionate technical, operational, and organisational measures" to manage cybersecurity risks. The measures shall include at least the following ten.

1. Policies on risk analysis and information system security

A documented risk management approach for cybersecurity, including how risks are identified, evaluated, treated, accepted, monitored, and communicated.

NexCyber tracks: written policy, owner, last review, scope statement, link to risk register.

2. Incident handling

A documented incident handling process across detection, triage, containment, eradication, recovery, and lessons learned.

NexCyber tracks: incident response policy, on-call rota, runbooks, sample post-mortems, training records.

3. Business continuity

Backup, disaster recovery, crisis management. Continuity is not only about data; it is about people, processes, suppliers, and dependencies.

NexCyber tracks: BC policy, recovery time / point objectives (RTO / RPO), test reports, lessons learned from exercises.

4. Supply chain security

Security across the supply chain, including aspects related to the security of direct suppliers and service providers.

NexCyber tracks: supplier inventory, security attestations per critical supplier, contract clauses on incident notification, SBOM coverage where applicable.

5. Security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure

Security-by-design, secure development lifecycle, vulnerability disclosure.

NexCyber tracks: SDLC policy, security testing evidence, vulnerability disclosure policy (and security.txt where exposed), patch management records.

6. Policies and procedures to assess the effectiveness of cybersecurity risk-management measures

You must measure whether your measures actually work. Metrics and assurance cycles.

NexCyber tracks: assurance plan, metrics, recent test results, internal audit reports.

7. Basic cyber hygiene and cybersecurity training

The everyday practices: password hygiene, MFA, patch discipline, phishing awareness, training.

NexCyber tracks: hygiene policy, training plan, training completion rates, phishing simulation outcomes.

8. Policies and procedures regarding the use of cryptography and, where appropriate, encryption

A decision framework for cryptography, with a key management lifecycle.

NexCyber tracks: cryptography policy, key management process, inventory of cryptographic protections in transit and at rest, post-quantum readiness considerations.

9. Human resources security, access control policies, and asset management

The people side of security: starters / movers / leavers, role-based access, asset inventory.

NexCyber tracks: HR security policy, joiner-mover-leaver playbook, RBAC matrix, asset inventory.

10. The use of multi-factor authentication or continuous authentication solutions, secured voice / video / text, and secured emergency communication systems

The high-assurance authentication and communication tier, especially for sensitive workflows and crisis communication.

NexCyber tracks: MFA enforcement scope, secure communications inventory, emergency communications playbook.

Proportionality

NIS2 is explicit on proportionality. The measures must be appropriate and proportionate to the entity's exposure, size, likelihood of incidents, and severity if incidents occur. NexCyber lets you tag obligations by proportionality rationale; auditors generally appreciate explicit, defensible proportionality reasoning.

How NexCyber composes the ten into a readiness score

Each measure carries a weight; the weight reflects regulatory expectations and your sector. The composite score is shown on the NIS2 assessment dashboard, with the breakdown per measure visible at one click.

Incident reporting — the timelines

Article 23 sets the reporting timelines on top of Article 21 measures:

  • Early warning within 24 hours of becoming aware.
  • Incident notification within 72 hours.
  • Final report within one month.
  • Intermediate updates at the request of the competent authority.

NexCyber does not file reports for you; it offers the playbook scaffold and the timer once an incident is open.

Governance angle

Article 20 of NIS2 puts cybersecurity at the management body's level: governance bodies are responsible for compliance with Article 21 measures, and members of those bodies must be trained.

NexCyber tracks: management training records, named accountability per measure, board-level review cadence.

Coordination with adjacent regulations

If you are also in scope of:

  • CRA — vulnerability handling, SBOM, and SDLC evidence overlaps with Article 21(5).
  • DORA — ICT third-party register and resilience testing overlap with Article 21(4) and Article 21(3).
  • AI Act — risk management and data governance overlap with Article 21(1), Article 21(8), and Article 21(9).

NexCyber maps a single evidence item to all applicable obligations; you upload once.

What NexCyber does NOT do

  • It does not declare you compliant. It produces a readiness picture, with proportionality reasoning surfaced.
  • It does not file authority reports. The playbook scaffolds the decision; the filing remains yours.
  • It does not perform the measures (e.g., it is not your IAM system). It records evidence about them.

Common gaps we see at first assessment

  • Policies that exist but are not signed off or scoped.
  • Supply chain security limited to a security questionnaire — no living inventory.
  • Incident handling with no exercise record.
  • MFA partially deployed without a clear exception register.
  • Cryptography policy that does not include key rotation cadence.

These are common and addressable. Plug them and the score moves.

Related articles

  • NIS2 basics — wider picture.
  • Supplier evidence basics — measure 4 detail.
  • What evidence should I prepare? — cross-regulation evidence list.

Next step

Open the NIS2 assessment in your workspace, drill into the weakest measure first, and attach the recommended evidence.