Auditen
Home / Frameworks / NIS2 / The minimum cybersecurity risk-management measures
NIS2 · Art. 21

The minimum cybersecurity risk-management measures

Article 21 requires essential and important entities to implement a proportional set of technical, operational, and organizational measures to manage cybersecurity risks. These measures must be commensurate with the entity's risk profile and aim to ensure the resilience of network and information systems.

What it means

The intent is to move away from static checklists toward a dynamic, risk-based approach to security. Organizations are not expected to implement every possible control, but rather those that specifically mitigate the risks identified in their unique operational environment.

In practice, this means cybersecurity cannot be treated as a purely IT issue; it must be integrated into organizational governance. The scope extends beyond internal systems to include the entire lifecycle of assets and the security of the external supply chain.

The directive emphasizes an "all-hazards" approach. This requires balancing preventative measures (like encryption) with detective capabilities (monitoring) and restorative capabilities (disaster recovery), ensuring that if a breach occurs, the entity can maintain essential services.

How to meet it

Evidence an auditor asks for

  • A comprehensive Risk Register documenting identified risks, their impact/likelihood, and the chosen mitigation strategies.
  • Documented policies and procedures for incident response, business continuity, and information security management.
  • Records of "tabletop" exercises or simulation tests proving that recovery plans actually work.
  • Vendor risk assessment reports and signed contracts containing specific cybersecurity obligations for third-party providers.
  • Training logs and completion certificates demonstrating that employees have undergone cyber hygiene training.

Common pitfalls

  • Treating the requirement as a one-time project rather than a continuous cycle of assessment, implementation, and review.
  • Overlooking the supply chain by assuming that large vendors are "compliant by default" without verifying their specific controls.
  • Implementing technical tools (e.g., an EDR or Firewall) without documenting the underlying policy that governs how those tools are managed and monitored.