The NIS 2 Directive | Article 21



Article 21, Cybersecurity risk-management measures


1. Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services.

Taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, the measures referred to in the first subparagraph shall ensure a level of security of network and information systems appropriate to the risks posed. When assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact.


2. The measures referred to in paragraph 1 shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the following:


(a) policies on risk analysis and information system security;


(b) incident handling;


(c) business continuity, such as backup management and disaster recovery, and crisis management;


(d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers;


(e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;


(f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures;


(g) basic cyber hygiene practices and cybersecurity training;


(h) policies and procedures regarding the use of cryptography and, where appropriate, encryption;


(i) human resources security, access control policies and asset management;


(j) the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate.


3. Member States shall ensure that, when considering which measures referred to in paragraph 2, point (d), of this Article are appropriate, entities take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures. Member States shall also ensure that, when considering which measures referred to in that point are appropriate, entities are required to take into account the results of the coordinated security risk assessments of critical supply chains carried out in accordance with Article 22(1).


4. Member States shall ensure that an entity that finds that it does not comply with the measures provided for in paragraph 2 takes, without undue delay, all necessary, appropriate and proportionate corrective measures.


5. By 17 October 2024, the Commission shall adopt implementing acts laying down the technical and the methodological requirements of the measures referred to in paragraph 2 with regard to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online market places, of online search engines and of social networking services platforms, and trust service providers.

The Commission may adopt implementing acts laying down the technical and the methodological requirements, as well as sectoral requirements, as necessary, of the measures referred to in paragraph 2 with regard to essential and important entities other than those referred to in the first subparagraph of this paragraph.

When preparing the implementing acts referred to in the first and second subparagraphs of this paragraph, the Commission shall, to the extent possible, follow European and international standards, as well as relevant technical specifications. The Commission shall exchange advice and cooperate with the Cooperation Group and ENISA on the draft implementing acts in accordance with Article 14(4), point (e).

Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 39(2).



Understanding Article 21 of the NIS 2 Directive | Analysis

Article 21 of NIS 2 defines what organisations must do to manage cybersecurity risks before an incident occurs, transforming cybersecurity from a predominantly technical discipline into a matter of corporate governance, enterprise risk management and legal accountability.

Article 21 adopts a principles based approach. It requires organisations to implement appropriate and proportionate technical, operational and organisational measures to manage cybersecurity risks affecting their network and information systems. This drafting reflects a deliberate legislative choice. The European law recognised that cybersecurity is characterised by rapid technological evolution and constantly changing threat landscapes. A prescriptive approach would inevitably become obsolete. Instead, the Directive establishes enduring legal principles, and allows flexibility in determining how those principles should be implemented.

The result is a legal framework that shifts regulatory attention towards governance. Organisations must demonstrate that cybersecurity risks are systematically identified, assessed, managed, monitored and continuously reviewed within an enterprise wide governance framework.

Article 21 is a legal standard of care. It establishes a standard of organisational diligence. It does not establish a catalogue of technical requirements.

An organisation remains compliant despite suffering a sophisticated cyberattack, provided that it can demonstrate that appropriate governance processes, risk assessments and security measures had been implemented prior to the incident.

An organisation may possess advanced technological capabilities, and fail to satisfy Article 21, if those technologies are not supported by effective governance, documented decision making, periodic review, and appropriate organisational oversight.

The technical measures implemented by an organisation are not the legal obligation themselves. They are the evidence demonstrating whether the legal obligation has been fulfilled.

A very significant legal principle followed in Article 21 is proportionality. NIS 2 deliberately avoids imposing identical cybersecurity obligations on every regulated entity. Organisations are required to implement measures that are appropriate in light of their particular circumstances. When determining what constitutes appropriate and proportionate measures, Article 21 requires consideration of multiple factors, including the state of the art, the costs of implementation, the size of the organisation, the likelihood of incidents, the severity of potential consequences, and the degree of exposure to cybersecurity risks.

The proportionality principle recognises that cybersecurity risks differ substantially between sectors, organisations, and operational environments. A multinational operator of critical infrastructure cannot reasonably be expected to adopt identical security arrangements to those required in a medium sized regional service provider.

Proportionality provides supervisory authorities with the flexibility necessary to assess compliance on a case-by-case basis. Regulatory assessment becomes an exercise in evaluating governance quality, not measuring compliance against technical checklists.

This flexible approach significantly increases the importance of documentation. Organisations must demonstrate how and what decisions have been made, but also why those decisions were considered appropriate.

Article 21 of NIS 2 identifies ten categories of risk management measures. These categories are not isolated compliance obligations. They are components of a governance framework. Compliance cannot be demonstrated by showing that individual controls exist. Supervisory authorities examine whether those controls operate coherently as part of an integrated risk management framework.

A very important element of Article 21 is the all hazards approach. Historically, cybersecurity legislation focused primarily on malicious cyberattacks. Article 21 adopts a considerably broader perspective.

NIS 2 recognises that operational disruption may result from malicious actors, insider threats, software vulnerabilities, supply chain failures, cloud outages, human error, physical sabotage, geopolitical instability, infrastructure failures or complex combinations of these factors. This broad conception of cybersecurity reflects the operational realities faced by organisations responsible for essential and important services.

Hybrid attacks never occur in isolation. A cyber intrusion or a ransomware attack may coincide with a supply chain disruption, and disinformation campaigns to undermine public confidence. Article 21 regulates organisational resilience, not simply information security.

This is an important conceptual evolution. Cybersecurity governance increasingly overlaps with enterprise risk management, operational resilience, business continuity, crisis management and strategic decision making.

Supply chain security is one of the most significant obligations under Article 21. The Directive requires organisations to take account of cybersecurity risks arising from suppliers, service providers and the broader supply chain. This obligation extends beyond traditional vendor management, and requires organisations to consider the overall quality of suppliers' cybersecurity practices, vulnerabilities associated with third parties, and the security of products and services incorporated into their own operations. This is a substantial expansion of organisational responsibility.

Historically, cybersecurity programs concentrated primarily on protecting internally managed systems. Article 21 recognises that organisational resilience increasingly depends on external relationships. Cybersecurity governance can no longer be limited by organisational boundaries. This development has practical implications for procurement, outsourcing, contractual risk allocation, due diligence processes, and ongoing supplier monitoring.

Article 21 cannot be understood without Article 20, which assigns responsibility for approving and overseeing cybersecurity risk-management measures. Together, Articles 20 and 21 establish a comprehensive governance model. Article 21 defines the substance of cybersecurity risk management. Article 20 identifies the individuals responsible for ensuring that those measures are properly implemented and supervised.

Boards are expected to understand the organisation's cybersecurity risk landscape, review management reporting, evaluate strategic decisions, allocate appropriate resources, and ensure that cybersecurity considerations are integrated into broader governance processes. This is an important evolution in European corporate governance. Cybersecurity increasingly occupies a position comparable to financial reporting, internal controls, operational resilience and regulatory compliance.

Article 21 should be interpreted in the context of the European Union's broader resilience agenda. NIS 2 requirements complement a growing body of legislation addressing digital resilience, operational continuity, supply chain security and critical infrastructure protection. Together with instruments such as the Digital Operational Resilience Act for financial entities, the Cyber Resilience Act, the AI Act, and the Critical Entities Resilience framework, Article 21 contributes to an increasingly integrated legal architecture governing organisational resilience.


From Article 21 to Commission Implementing Regulation (EU) 2024/2690

Article 21(5) of the NIS 2 Directive expressly empowered the European Commission to adopt implementing acts specifying the technical and methodological requirements for the cybersecurity risk management measures required by Article 21. The result was Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024.

In simple terms, Article 21 establishes the legal obligation. Commission Implementing Regulation (EU) 2024/2690 specifies how certain digital entities are expected to implement the obligation in practice.



Note: This is the final text of the NIS 2 Directive. The full name is "Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)".


Articles, Directive (EU) 2022/2555 (NIS 2 Directive):

https://www.nis-2-directive.com/NIS_2_Directive_Articles.html