← Course outline
Aavistus Training · nis2 · NIS.04

Cybersecurity risk-management measures

What you'll learn

The all-hazards baseline every in-scope entity must implement: the ten minimum measures of Article 21(2) — from risk analysis and incident handling to MFA, encryption and supply-chain security — and the proportionality principle governing them.

Regulation — cited to the current EU text

The proportionality principle

Article 21(1) requires essential and important entities to implement appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of their network and information systems 32022L2555 Article 21@2022-12-27. The required level of security must take into account the state of the art and, where applicable, relevant European and international standards, as well as the cost of implementation 32022L2555 Article 21@2022-12-27. When assessing the proportionality of the measures, due account must be taken of the degree of the entity's exposure to risks, its size, the likelihood of incidents occurring and their severity, including societal and economic impact 32022L2555 Article 21@2022-12-27. The objective is a level of security appropriate to the actual risks — not a single compliance ceiling applied uniformly to every in-scope entity.

The all-hazards approach

The measures required by Article 21(1) must be based on "an all-hazards approach" that aims to protect network and information systems and the physical environment of those systems from incidents 32022L2555 Article 21@2022-12-27. This is a deliberate design choice: entities may not scope their risk programmes narrowly around cyber-only threat vectors while leaving physical or environmental attack surfaces unaddressed.

The ten minimum measures

Article 21(2) establishes a floor of ten measure categories that in-scope entities must implement at minimum 32022L2555 Article 21@2022-12-27:

(a) Risk analysis and information system security policies — Documented policies governing how risks are identified and how information systems are secured.

(b) Incident handling — Formal procedures for detecting, responding to and recovering from incidents.

(c) Business continuity — Explicitly encompasses backup management, disaster recovery and crisis management. The regulation treats operational resilience as a distinct obligation, not a derivative of incident response 32022L2555 Article 21@2022-12-27.

(d) Supply chain security — Entities must address security in their relationships with direct suppliers and service providers. When determining appropriate measures, entities must consider vulnerabilities specific to each direct supplier or service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including secure development procedures 32022L2555 Article 21@2022-12-27. Entities are additionally required to take into account results of coordinated security risk assessments of critical supply chains conducted at EU level under Article 22(1) 32022L2555 Article 21@2022-12-27.

(e) Security in acquisition, development and maintenance — Covers the full lifecycle of network and information systems, including vulnerability handling and disclosure 32022L2555 Article 21@2022-12-27.

(f) Effectiveness assessment — Entities must maintain policies and procedures to evaluate whether their cybersecurity risk-management measures are actually working, not merely in place on paper 32022L2555 Article 21@2022-12-27.

(g) Cyber hygiene and training — Basic cyber hygiene practices and cybersecurity training are mandatory minimum measures 32022L2555 Article 21@2022-12-27. Their inclusion in Article 21(2) confirms that foundational controls are not assumed; they must be affirmatively implemented.

(h) Cryptography and encryption — Entities must have policies and procedures governing the use of cryptography and, where appropriate, encryption 32022L2555 Article 21@2022-12-27. The proportionality qualifier attaches to encryption specifically; the obligation to maintain a cryptography policy is unconditional.

(i) Human resources security, access control and asset management — These three sub-domains are grouped as a single mandatory measure category, reflecting their interdependence in managing insider risk and access governance 32022L2555 Article 21@2022-12-27.

(j) Multi-factor authentication and secured communications — Entities must deploy multi-factor authentication or continuous authentication solutions, and secured voice, video, text and emergency communication systems within the entity, where appropriate 32022L2555 Article 21@2022-12-27.

Non-compliance: a continuing remediation obligation

The regulation does not treat non-compliance as a static condition to be reported and tolerated. Where an entity finds it does not comply with the Article 21(2) measures, it must take all necessary, appropriate and proportionate corrective measures without undue delay 32022L2555 Article 21@2022-12-27. This creates a self-assessment and remediation loop that is itself a compliance requirement.

Implementing acts

The Commission shall adopt implementing acts setting out technical and methodological requirements for the Article 21(2) measures, with a first tranche covering DNS service providers, cloud computing service providers, managed service providers, trust service providers and several other entity types by 17 October 2024 32022L2555 Article 21@2022-12-27. Technical and methodological requirements, as well as sectoral requirements, for other essential and important entities may follow in subsequent implementing acts 32022L2555 Article 21@2022-12-27. Those acts are to follow European and international standards as well as relevant technical specifications to the extent possible, developed in coordination with the Cooperation Group and ENISA 32022L2555 Article 21@2022-12-27.

Your operations manual

This block connects to your organisation's own information-security policies (ISMS). In the full product it shows, cited to your policy set, how YOUR organisation implements the obligation above — private to your organisation. (Demo placeholder.)

Real-world context — illustrative only

The following cases are labeled illustrative context only and carry no regulatory authority; they are provided to ground the legal requirements in observable incidents.

Coca-Cola dairy unit ransomware attack CASE-1 — A ransomware incident disrupted production capacity at a Coca-Cola dairy unit, with the company subsequently restoring most operations. This directly illustrates Article 21(2)(b) and (c): the speed and completeness of recovery depends on the maturity of incident handling procedures, backup availability and disaster recovery planning established before the event. Production downtime translates directly into the societal and economic impact that the proportionality assessment under Article 21(1) is designed to factor in for food-sector operators.

Italian ransomware landscape H1 2026 CASE-2 — Analysis of the Italian ransomware environment in H1 2026 documents the scale and distribution of ransomware targeting across sectors. This contextualises the Article 21(2) floor as a minimum baseline against an active and sustained threat pattern, not a precautionary measure against low-probability events. Risk analysis under measure (a), effective incident handling under (b), and MFA deployment under (j) all bear directly on ransomware exposure, which remains the dominant incident category in the European operational environment.

Thialf ice stadium attack CASE-3 — Dutch ice stadium Thialf was targeted by a criminal group demanding ransom and threatening to publish exfiltrated data on the dark web. Forensic investigation conducted by internal and external professionals established that data and operational processes had not been affected. This outcome illustrates the operational difference between an entity that has invested in containment, detection and forensic response capacity and one that has not. It also demonstrates the Article 21(2)(b) and (f) dynamic: effective incident handling followed by a credible post-incident assessment enabled Thialf to make a public statement grounded in evidence rather than assumption — a practical consequence of having the required response procedures in place.

Check your understanding

1. When assessing the proportionality of cybersecurity measures under Article 21(1), which factor must be taken into account?

2. What does the all-hazards approach mandated by Article 21(1) require entities to protect?

3. Article 21(2)(c) on business continuity explicitly encompasses which three elements?

4. Under Article 21(2)(h), how does the regulation distinguish the obligations on cryptography policy and encryption?

5. When an entity discovers it does not comply with the Article 21(2) measures, what does the regulation require it to do?