Skip to content
atlas

NIS2 minimum requirements

Also known as: NIS2 Article 21 measures, cybersecurity risk-management measures

The baseline list of security measures every organisation under NIS2 must have in place.

Draft - this entry has not been reviewed yet.

Formal

The ten areas of measures in NIS2 Article 21(2) - among them risk analysis, incident handling, business continuity, supply-chain security, training, encryption and multi-factor authentication - to be applied in proportion to the entity's size and exposure to risk.

In plain English

Like the equipment every car must have before it may use the road - lights, brakes, seat belts - however big or small the car.

In practice

The IT operations manager at a Danish freight company holds each point on the list against what the firm already does and finds that backups exist but have never been restored in a test.

Why it matters

A broad duty to “manage cyber risk” is easy to claim and hard to check; the list gives the authority concrete points to inspect, and a missing one can bring orders or fines.

Technical deep dive

Article 21(1) sets the general duty: appropriate and proportionate technical, operational and organisational measures to manage risks to the network and information systems used for operations or for providing services, and to prevent or minimise the impact of incidents. Measures must take account of the state of the art, relevant European and international standards and the cost of implementation, and proportionality is judged by the entity's exposure to risk, its size and the likelihood and severity of incidents, including their societal and economic impact. Article 21(2) then requires an "all-hazards" approach, covering physical events such as fire, flooding and power loss as well as attacks, and lists ten areas, points (a) to (j), that the measures must at least include.

The list is organisational as much as technical: (a) policies on risk analysis and information system security; (b) incident handling; (c) business continuity, including backup management, disaster recovery and crisis management; (d) supply chain security; (e) security in acquisition, development and maintenance, including vulnerability handling and disclosure; (f) policies and procedures to assess the effectiveness of the measures; (g) basic cyber hygiene and training; (h) cryptography and, where appropriate, encryption; (i) human resources security, access control and asset management; and (j) multi-factor or continuous authentication, secured voice, video and text communications and secured emergency communications, where appropriate. Article 21(3) adds that supply-chain measures must consider each direct supplier's specific vulnerabilities, product quality and secure development practices, and Article 21(4) requires non-compliance to be corrected without undue delay.

For DNS, TLD, cloud, data centre, CDN, managed and managed security service providers, online marketplaces, search engines, social networks and trust service providers, Commission Implementing Regulation (EU) 2024/2690 turns the ten areas into detailed technical and methodological requirements in its annex. For all other entities the national transposition, in Denmark § 6 of the NIS2 Act, carries the list almost word for word, and the detail is left to guidance and recognised standards.

In practice the ten areas map closely onto ISO/IEC 27002:2022: incident management to controls 5.24-5.28, continuity to 5.29-5.30 and backup to 8.13, suppliers to 5.19-5.22, secure development and vulnerabilities to 8.8 and 8.25-8.28, effectiveness to 5.35 and ISO 27001 clause 9, awareness to 6.3, cryptography to 8.24, access control to 5.15-5.18 and authentication to 8.5. Two misreadings recur. "Minimum" does not mean light, since each area must be addressed and a scaled-down response has to be justified by risk and size; and "where appropriate" in points (h) and (j) is not an opt-out; in practice it means being able to show, with a documented risk rationale, why a measure such as MFA is not used on a given system.

Relationships

Sources & further reading

Standards & official texts

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.