Blogs | 6clicks

The ten NIS2 Article 21 measures, and who owns the evidence for each

Written by 6clicks Editorial | Aug 17, 2026

TL;DR

  • Article 21(2) sets ten minimum cybersecurity risk management measures. They are identical for essential and important entities.
  • Article 20 makes the management body personally accountable for approving and overseeing them.
  • Each measure needs a traceable owner and a defensible evidence trail, not just a policy.
  • Most measures map onto a mature ISO 27001 ISMS. The hard one is 21(2)(f), proving the controls work on an ongoing basis.
  • Incident reporting runs to statutory clocks: early warning within 24 hours, notification within 72 hours, final report within one month.

 

NIS2 Article 21(2) requires in-scope entities to implement ten minimum cybersecurity risk-management measures. They cover risk policies, incident handling, business continuity, supply chain security, secure development, testing effectiveness, cyber hygiene and training, cryptography, HR security and access control, and multi-factor authentication. The obligations are identical for essential and important entities. Article 20 makes management personally accountable for approving and overseeing them.

What does Article 21 of NIS2 require?

Article 21(1) requires appropriate and proportionate technical, operational, and organisational measures to manage risk to network and information systems. Article 21(2) then lists ten minimum measures every in-scope entity must implement, based on an all-hazards approach.

 

Two points that change how you should read the list:

 

  • The ten measures are a floor, not a ceiling. Proportionality is assessed against your exposure, size, and the societal impact of disruption.
  • The list is identical for essential and important entities. Classification changes supervision and penalty ceilings, not the security obligations.

Who is accountable for NIS2 compliance?

Article 20 places the duty on management bodies. They must approve the risk management measures, oversee implementation, and can be held personally liable for failures. Management must also complete training, and entities must offer similar training to staff.

 

This is why evidence ownership matters more under NIS2 than under previous frameworks. A named person has to sign off on measures they did not personally perform, which means each measure needs a traceable owner and a defensible evidence trail.

 

The ten measures, with evidence owner for each:

 

# Article Measure What evidence looks like Typical owner
1 21(2)(a) Risk analysis and information system security policies Approved policy set, current risk register, board approval records CISO or risk lead
2 21(2)(b) Incident handling Incident register, response playbooks, post-incident reviews, 24/72-hour reporting records SecOps and incident response
3 21(2)(c) Business continuity, backup management, disaster recovery, crisis management Tested BCP and DR plans, restore test results, crisis comms plan Business continuity lead
4 21(2)(d) Supply chain security, including direct supplier and service provider relationships Supplier register, tiered risk assessments, security clauses, assessment records Procurement and vendor risk
5 21(2)(e) Security in acquisition, development and maintenance, including vulnerability handling and disclosure Secure SDLC evidence, vulnerability management records, disclosure policy, patch timelines Engineering and product security
6 21(2)(f) Policies and procedures to assess the effectiveness of risk-management measures Control testing results, internal audit reports, effectiveness metrics over time Internal audit or assurance
7 21(2)(g) Basic cyber hygiene practices and cybersecurity training Training completion records including management, phishing simulation results, hygiene baselines People team with security
8 21(2)(h) Policies on the use of cryptography and, where appropriate, encryption Cryptographic standard, key management procedures, encryption coverage evidence Security architecture
9 21(2)(i) Human resources security, access control policies and asset management Screening records, joiner-mover-leaver evidence, access reviews, asset inventory IT operations and people team
10 21(2)(j) Multi-factor or continuous authentication, secured voice, video and text communications, secured emergency communications MFA coverage reporting, exception register, secured comms configuration IT operations

 

Owners are indicative. The directive does not assign roles. What it does require is that someone can produce the evidence and that management can show they oversaw it.

Which measure causes the most trouble?

Article 21(2)(f). The other nine ask whether you have a control. This one asks whether you can prove it works, on an ongoing basis.

 

Most organisations can produce a policy for each of the other nine within a week. Producing twelve months of evidence that the controls operated as intended is a different exercise, and it is the one that turns NIS2 from a documentation task into an operational one.

Does NIS2 replace ISO 27001?

No. NIS2 is a legal obligation, ISO 27001 is a certifiable standard. However, there is a substantial overlap: most Article 21 measures map to existing Annex A controls, so an organisation with a mature ISMS has an advantage.

 

The gaps are usually reporting timelines, supply chain depth, and management accountability, none of which ISO 27001 covers in the same form.

Frequently asked questions

 

 

How 6clicks helps

Nine of the ten Article 21 measures are a documentation exercise. Article 21(2)(f) is not. It asks whether your measures work, on an ongoing basis, and Article 20 puts a named person on the hook for saying so.

That is an evidence problem, and evidence problems do not get solved by another policy repository.

 

What NIS2 asks for What this means operationally How 6clicks handles it
Ten minimum measures under Article 21(2) A control set mapped to the directive, not a generic library NIS2 content in the 6clicks Content Library, auto-mapped to Article 21 measures by Hailey
Evidence that measures are effective, not just present Continuous control testing with retained history Automated control testing and evidence collection through no-code integrations with your systems
Supply chain risk under 21(2)(d) Tiered supplier assessments, at scale, with responses tracked Vendor risk assessments issued, tracked, and scored in one register
Management oversight under Article 20 Board-level reporting a director can defend Board or executive reporting views can be configured within the dashboard
Multiple Member States, multiple national rules One control set answering several transpositions at once Multi-framework mapping, so a control tested once satisfies obligations across NIS2, ISO 27001, and others
Incident reporting inside 24 and 72 hours Evidence retrievable at speed, not assembled under pressure Centralized incident and evidence registers, with custom forms aligned to NIS2 reporting templates

Why this matters more in the EU than elsewhere

Most organisations facing NIS2 already have an ISMS. The gap is not controls, it is proof. Article 21(2)(f) turns compliance from an annual artefact into an operating requirement, and that is where spreadsheet-and-SharePoint approaches stop scaling.

See how the ten Article 21 measures map to ISO 27001 controls you may already have. Book a 30-minute NIS2 evidence session with our team.