nis²insights.com

In force since 17 Oct 2024·Day 565·

Reference · Article 21Last revised 05 May 2026

The 21 measures, explained simply.

Article 21 of Directive (EU) 2022/2555 lists ten categories of cybersecurity risk-management measures. We have unpacked them into 21 concrete checkpoints, grouped by what your team actually has to deliver.

§ 01

Governance

  1. M.01Information security policies — approved at board level
  2. M.02Roles, responsibilities & accountability formally documented
  3. M.03Director training on cybersecurity risk
  4. M.04Annual independent review of the security programme

§ 02

Risk management

  1. M.05Risk analysis methodology and live risk register
  2. M.06Asset inventory: information systems and data
  3. M.07Business continuity & crisis management plans
  4. M.08Backups: tested restore procedures

§ 03

Technical measures

  1. M.09Multi-factor authentication on all critical access
  2. M.10Cryptography and encryption policy
  3. M.11Network segmentation and zero-trust principles
  4. M.12Vulnerability management and patching cadence
  5. M.13Endpoint detection and response
  6. M.14Secure software development lifecycle

§ 04

Supply chain

  1. M.15Supplier security assessments
  2. M.16Contractual security clauses for critical vendors
  3. M.17Continuous monitoring of third-party exposure

§ 05

Incident handling

  1. M.18Detection, classification and escalation playbooks
  2. M.1924h early warning to CSIRT
  3. M.2072h incident notification with severity assessment
  4. M.21Final report within one month
Boardroom mid-discussion — the moment a board agrees to commission the assessmentAction · Run the checklist

§ Action

Ready to put numbers on this?

Take the 21-point assessment. Score in two minutes. Walk away with a prioritised action plan ready to share with your board.