The ten NIS2 security measures
#MeasureWhat it means in practiceCategory
01Risk analysis & security policiesEstablish policies on information-system security and a documented approach to analysing cyber risk.Governance
02Incident handlingProcesses to detect, respond to and recover from security incidents.Operational
03Business continuityBackup management, disaster recovery and crisis-management capabilities.Operational
04Supply-chain securityAddress security in relationships with direct suppliers and service providers.Supply chain
05Secure acquisition & developmentSecurity in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure.Technical
06Effectiveness assessmentPolicies and procedures to assess whether the cybersecurity risk-management measures are effective.Governance
07Cyber hygiene & trainingBasic cyber-hygiene practices and regular security-awareness training for staff.Governance
08Cryptography & encryptionPolicies on the use of cryptography and, where appropriate, encryption.Technical
09Access control & asset managementHuman-resources security, access-control policies and asset management.Technical
10MFA & secure communicationsThe use of multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communication systems where appropriate.Technical

What each measure looks like in practice

The directive sets the requirement; how you meet it should be proportionate to your risk, size and exposure. Here is a pragmatic read on each of the ten.

  1. Article 21(2)(a)

    Risk analysis & security policies

    A documented, risk-based information-security management system; management-approved policies; a living risk register.

  2. Article 21(2)(b)

    Incident handling

    Detection, triage, response and recovery runbooks; centralised logging; a defined incident lifecycle.

  3. Article 21(2)(c)

    Business continuity

    Tested backups, disaster-recovery plans and crisis management; defined recovery objectives (RTO/RPO).

  4. Article 21(2)(d)

    Supply-chain security

    Supplier risk assessment, security clauses in contracts, and ongoing monitoring of critical vendors.

  5. Article 21(2)(e)

    Secure acquisition & development

    A secure development lifecycle, coordinated vulnerability handling and disclosure, and disciplined patch management.

  6. Article 21(2)(f)

    Effectiveness assessment

    Audits, testing and metrics that demonstrate the controls actually work.

  7. Article 21(2)(g)

    Cyber hygiene & training

    Patching, MFA, least privilege and phishing-resistant basics; recurring awareness training.

  8. Article 21(2)(h)

    Cryptography & encryption

    A cryptography policy; encryption of data at rest and in transit where appropriate.

  9. Article 21(2)(i)

    Access control & asset management

    A joiner/mover/leaver process, role-based access control and a maintained asset inventory.

  10. Article 21(2)(j)

    MFA & secure communications

    Multi-factor authentication wherever feasible; secured voice, video and text; secured emergency communications.

From requirements to a plan

See how these measures fit into a six-step path to demonstrable compliance.

See the roadmap →