Skip to content

NIS2 Article 21: the 10 minimum cybersecurity measures, explained

We already covered which companies are obligated under NIS2. If your company is in scope, the next question is what exactly you have to implement — and the answer isn't vague: Art. 21(2) lists 10 closed categories of measures.

Why it's a closed list, not a suggestion

Art. 21(2) of the NIS2 Directive (EU 2022/2555) doesn't leave cybersecurity measures open to interpretation: it lists 10 mandatory risk-management categories that every essential or important entity must cover. What does vary is the level of implementation — the directive itself requires applying them "in a proportionate manner" to the entity's size, its risk exposure, and the likelihood and potential impact of an incident. It isn't an all-or-nothing checklist, but it also doesn't allow skipping any of the 10 categories.

The 10 categories in Art. 21(2)

  1. Risk analysis and information security policies — documented policies, not just informal practices.
  2. Incident handling — procedures for detecting, analyzing, and responding to security incidents.
  3. Business continuity and crisis management — recovery plans, backups, and crisis management.
  4. Supply-chain security — assessing the cybersecurity risk of direct suppliers and subcontractors.
  5. Security in system acquisition, development, and maintenance — controls built into the technical lifecycle, including vulnerability management.
  6. Policies to assess the effectiveness of measures — periodic audits and reviews of what's already in place.
  7. Basic cyber hygiene and training — awareness and training for all staff, not just the technical team.
  8. Cryptography and encryption — encryption of data at rest and in transit, where relevant.
  9. Human resources security, access control, and asset management — onboarding, offboarding, and role-change procedures, with access governed by least privilege.
  10. Multi-factor authentication and secure communications — MFA or continuous authentication, at minimum, for critical systems and remote access.

The nuance almost no one gets right: the supply chain and AI vendors

Category 4 — supply-chain security — is the one that has grown most in practical importance since AI became embedded in critical processes. An AI vendor that processes the entity's data or connects to critical systems falls directly under this obligation, just like any other technology supplier: its cybersecurity posture needs to be assessed, not just its contractual compliance.

Where it overlaps with the AI Act

If you already comply with NIS2, much of the risk-management infrastructure already exists to satisfy Art. 15 of the AI Act (cybersecurity of high-risk AI systems) — but AI-specific threats, such as data or model poisoning and adversarial examples, remain a vector that NIS2 doesn't cover on its own. The European Commission acknowledged this gap in its July 2026 Cybersecurity and AI Action Plan, which explicitly links both frameworks.

Supervision proportionate to the type of entity

How compliance is checked also depends on whether you're an essential or important entity: essential entities are subject to ex ante supervision (proactive inspections and audits by the regulator), while important entities face ex post supervision (reactive investigations following a reported incident). Either way, documenting how each of the 10 categories was applied — not just that it was applied — is what holds up under an inspection or an investigation.

The 10 measures, as a checklist

NIS2 Checklist — compliance assessment for the 10 categories in Art. 21, plus the NIS2 Security Policy already drafted for you to adapt to your entity.

View NIS2 Checklist → View NIS2 Security Policy →