Obligations
The ten security measures every in-scope entity must adopt
Article 21 requires in-scope entities to adopt appropriate and proportionate technical, operational and organisational measures. Filter by category to explore what each one means in practice.
| # | Measure | What it means in practice | Category |
|---|---|---|---|
| 01 | Risk analysis & security policies | Establish policies on information-system security and a documented approach to analysing cyber risk. | Governance |
| 02 | Incident handling | Processes to detect, respond to and recover from security incidents. | Operational |
| 03 | Business continuity | Backup management, disaster recovery and crisis-management capabilities. | Operational |
| 04 | Supply-chain security | Address security in relationships with direct suppliers and service providers. | Supply chain |
| 05 | Secure acquisition & development | Security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure. | Technical |
| 06 | Effectiveness assessment | Policies and procedures to assess whether the cybersecurity risk-management measures are effective. | Governance |
| 07 | Cyber hygiene & training | Basic cyber-hygiene practices and regular security-awareness training for staff. | Governance |
| 08 | Cryptography & encryption | Policies on the use of cryptography and, where appropriate, encryption. | Technical |
| 09 | Access control & asset management | Human-resources security, access-control policies and asset management. | Technical |
| 10 | MFA & secure communications | The use of multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communication systems where appropriate. | Technical |
What each measure looks like in practice
The directive sets the requirement; how you meet it should be proportionate to your risk, size and exposure. Here is a pragmatic read on each of the ten.
-
Article 21(2)(a)
Risk analysis & security policies
A documented, risk-based information-security management system; management-approved policies; a living risk register.
-
Article 21(2)(b)
Incident handling
Detection, triage, response and recovery runbooks; centralised logging; a defined incident lifecycle.
-
Article 21(2)(c)
Business continuity
Tested backups, disaster-recovery plans and crisis management; defined recovery objectives (RTO/RPO).
-
Article 21(2)(d)
Supply-chain security
Supplier risk assessment, security clauses in contracts, and ongoing monitoring of critical vendors.
-
Article 21(2)(e)
Secure acquisition & development
A secure development lifecycle, coordinated vulnerability handling and disclosure, and disciplined patch management.
-
Article 21(2)(f)
Effectiveness assessment
Audits, testing and metrics that demonstrate the controls actually work.
-
Article 21(2)(g)
Cyber hygiene & training
Patching, MFA, least privilege and phishing-resistant basics; recurring awareness training.
-
Article 21(2)(h)
Cryptography & encryption
A cryptography policy; encryption of data at rest and in transit where appropriate.
-
Article 21(2)(i)
Access control & asset management
A joiner/mover/leaver process, role-based access control and a maintained asset inventory.
-
Article 21(2)(j)
MFA & secure communications
Multi-factor authentication wherever feasible; secured voice, video and text; secured emergency communications.
From requirements to a plan
See how these measures fit into a six-step path to demonstrable compliance.
See the roadmap →