# The Ten NIS2 Measures of Article 21(2), Explained

NIS2 Article 21(2) lists ten risk management measures every affected entity must implement. What each one means, how they map to German law, and where to start.

Source: https://zyberum.com/insights/nis2-measures-article-21 · Updated: 2026-10-07

NIS2 does not leave the security measures open. **Article 21(2) of the NIS2 Directive** names ten areas that every essential and important entity must cover, and German law transposes them one to one in **section 30 of the BSIG**. The measures have to be appropriate to your risk, size and exposure, so a 60-person manufacturer does not run a bank's programme, but no entity in scope can skip one of the ten areas. This article explains each one in plain terms and says where to put your effort first.

## The ten areas

Article 21(2) lists them as follows. The wording below is a practical reading, not a quote.

1. **Risk analysis and information system security policies.** A documented way to find, assess and treat risks, and the policies that follow from it. This is the foundation the other nine build on.
2. **Incident handling.** Detect, respond to and recover from security incidents, with clear roles. This connects directly to the reporting deadlines (24 hours, 72 hours, one month).
3. **Business continuity.** Backup management, disaster recovery and crisis management, so you can keep operating or come back fast. Backups that have never been restored do not count.
4. **Supply chain security.** The security of relationships with your suppliers and service providers, including their secure development practices. Your risk includes their risk.
5. **Security in acquisition, development and maintenance.** Secure development and procurement, including vulnerability handling and disclosure. For anyone building software or devices, this is where a vulnerability process lives.
6. **Effectiveness assessment.** Policies and procedures to judge whether the measures actually work. This is the clause that asks for testing and evidence, not just documents.
7. **Cyber hygiene and training.** Basic practices and security awareness for staff, including management. The everyday habits that stop the common attacks.
8. **Cryptography.** Policies on the use of cryptography and, where appropriate, encryption. Encrypt what matters, and manage the keys.
9. **Human resources security, access control and asset management.** Who may access what, on which systems, and an inventory of the assets to protect.
10. **Multi-factor authentication, secured communications and emergency communication.** Strong authentication, secured voice, video and text, and a way to communicate when the normal systems are down.

## Where this bites in practice

Three of the ten cause the most difficulty in the first projects we see.

- **Effectiveness assessment (6).** Many organisations have policies but no evidence they work. This is where a penetration test earns its place: it shows quickly where the controls fail and produces the evidence NIS2 asks for. Testing and advising is exactly what we do; we are not an auditor or certification body.
- **Supply chain security (4).** Treating suppliers as out of scope is the common mistake. NIS2 makes their weaknesses your problem, so you need to know how your critical suppliers develop and secure what they sell you.
- **Incident handling (2) and the reporting clock.** The measures are only real if someone notices the incident. Without monitoring and a clear escalation path, the 24-hour deadline is unreachable.

## How deep do the measures have to go?

Proportionate to risk and size. The law expects you to be able to **explain your choices**: why a given measure is enough for your risk, or why a stronger one was not needed. That is very different from copying a maximal policy set you cannot sustain. Short and true beats long and copied. Management has to approve the measures and oversee them, and it can be held liable, so the reasoning needs to be written down.

## A sensible order

1. **Risk analysis (1)** first, because it decides how far the rest goes.
2. **Incident handling and detection (2)** next, so you can meet the reporting duty and limit damage.
3. **Backups, access control and MFA (3, 9, 10)**, the measures that stop the most real-world attacks.
4. **Vulnerability handling and secure development (5)** if you build products.
5. **Effectiveness testing (6)** to prove the above work, and **supply chain (4)** and **training (7)** in parallel.
6. **Cryptography (8)** woven through, not bolted on.

Zyberum helps with the scope check, the gap analysis against these ten areas, the implementation and the testing that produces the effectiveness evidence. See [NIS2 compliance](/nis2) or book a [free NIS2 check](/contact?meeting=consult&interest=nis2).

## FAQ

**Are the ten NIS2 measures mandatory for everyone in scope?**

Yes. Article 21(2) of the NIS2 Directive lists ten areas that every essential and important entity must address. The measures must be appropriate to the entity's risk and size, so the depth differs, but none of the ten areas can simply be skipped.

**How does Article 21 relate to German law?**

Article 21 of the directive is transposed into German law in section 30 of the BSIG. The German law lists the same ten areas. If you operate in Germany you implement them under the BSIG; the directive is the source behind it.

**Does an ISO 27001 ISMS cover the ten measures?**

Largely, but not automatically. An existing ISMS covers much of the ground, especially risk management, access control and cryptography. The NIS2-specific parts, in particular incident reporting deadlines and supply chain security, usually need explicit work on top.

## Sources

- [Directive (EU) 2022/2555 (NIS2), Article 21](https://eur-lex.europa.eu/eli/dir/2022/2555/oj)
- [BSIG § 30 (Risikomanagementmaßnahmen), gesetze-im-internet.de](https://www.gesetze-im-internet.de/bsig_2025/__30.html)
- [BSI: NIS-2 und das NIS2-Umsetzungsgesetz](https://www.bsi.bund.de/DE/Das-BSI/Auftrag/Gesetze-und-Verordnungen/NIS-2/nis-2_node.html)

## Related

- [NIS2 in Germany: Who Is Affected and What to Do Now](https://zyberum.com/insights/nis2-what-to-do-now)
- [NIS2](https://zyberum.com/glossary/nis2)
- [Incident Response](https://zyberum.com/glossary/incident-response)
- [Vulnerability Management: A Process That Works in Practice](https://zyberum.com/insights/vulnerability-management-process)
- [NIS2 without the paper mountain.](https://zyberum.com/nis2)
- [Does NIS2 apply to your company?](https://zyberum.com/nis2-check)

---
Zyberum GmbH. Canonical page: https://zyberum.com/insights/nis2-measures-article-21
