Get Demo
↑

The 10 NIS2 Minimum Security Measures (Article 21) Explained

Article 21(2) of Directive (EU).

Published: September 2026 Compliance · NIS2 8–12 min read

Article 21 of Directive (EU) 2022/2555 requires essential and important entities to take appropriate and proportionate measures to manage cybersecurity risks. Article 21(2) enumerates 10 minimum measure categories — the backbone of most NIS2 programmes.

Related: NIS2 hub · Article 23 reporting · Gap assessment.

Count that matters: Article 21(2) specifies 10 minimum cybersecurity risk-management measure categories. Programmes that invent an 8- or 12-control “NIS2 framework” without mapping back to these categories create audit risk.

The 10 Article 21(2) Categories

  1. Risk analysis and information system security policies
  2. Incident handling
  3. Business continuity — backup management, disaster recovery, and crisis management
  4. Supply chain security — including relationships with direct suppliers and service providers
  5. Security in network and information systems acquisition, development and maintenance — including vulnerability handling and disclosure
  6. Policies and procedures to assess the effectiveness of cybersecurity risk-management measures
  7. Basic cyber hygiene practices and cybersecurity training
  8. Cryptography — policies and procedures on cryptography and, where appropriate, encryption
  9. Human resources security, access control policies and asset management
  10. Multi-factor / continuous authentication and secured communications (voice, video, text) and secured emergency communications, where appropriate

Appropriate and Proportionate

Measures must reflect risk exposure, entity size, likelihood and severity of incidents, and societal/economic impact. National authorities and implementing acts (where applicable to certain digital providers) may add detail — the Directive categories remain the floor.

Evidence Themes Supervisors Expect

How CyberSilo Helps

Map All 10 Categories to Living Evidence

Use CSA to track Article 21 status and ThreatHawk for monitoring proof behind incident handling and hygiene.

Frequently Asked Questions

How many Article 21 measures are there?

Ten. Article 21(2) of Directive (EU) 2022/2555 lists 10 minimum cybersecurity risk-management measure categories.

Do important entities get a shorter list?

No. The 10 categories apply to essential and important entities; proportionality and supervision intensity differ.

Is ISO 27001 enough to cover Article 21?

ISO 27001 helps a lot but does not automatically prove NIS2 compliance — map Annex A controls explicitly and close Directive-specific gaps (reporting clocks, management liability, sector rules).

NIS2 hub · Supply chain · Logging · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!