LexClawFrameworks & Standards
FrameworksNIS2 Measures
risk managementv2022Published

NIS2 Minimum Security Measures

NIS2 Measures

NIS2 Article 21 establishes 10 minimum cybersecurity risk management measures that essential and important entities must implement. ENISA provides guidance on implementation.

Issuing Body
European Union Agency for Cybersecurity (ENISA)
Version
2022
Published
2022-12-27
Controls
13
Mapped Laws
29
Control IDTitleDomainMaturity
NIS2-Art.21(2)(a)
Policies on Risk Analysis and Information System Security
Essential and important entities shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems. Policies on risk analysis and information system security are required.
managed
NIS2-Art.21(2)(b)
Incident Handling
Measures for incident handling including prevention, detection and response to incidents. Entities must have documented incident response procedures and test them regularly.
managed
NIS2-Art.21(2)(c)
Business Continuity
Business continuity measures such as backup management and disaster recovery, and crisis management. Entities must ensure continuity of operations during and after significant incidents.
managed
NIS2-Art.21(2)(d)
Supply Chain Security
Security in supply chain including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers. Entities must assess and manage supply chain cybersecurity risks.
managed
NIS2-Art.21(2)(e)
Security in Network and Information Systems Acquisition
Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure. Secure development practices and vulnerability management are required.
managed
NIS2-Art.21(2)(f)
Policies and Procedures for Cryptography
Policies and procedures to assess the effectiveness of cybersecurity risk-management measures, including the use of cryptography and, where appropriate, encryption.
managed
NIS2-Art.21(2)(g)
Human Resources Security
Human resources security, access control policies and asset management. Entities must implement appropriate personnel security measures and manage access rights.
managed
NIS2-Art.21(2)(h)
Multi-Factor Authentication
The use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate.
managed
NIS2-Art.23(1)
Notification of Significant Incidents
Member States shall ensure that essential and important entities notify, without undue delay, the CSIRT or, where applicable, the competent authority of any incident having a significant impact on the provision of their services. Entities shall submit an early warning within 24 hours.
managed
NIS2-Art.23(4)
Notification Timeline
Entities shall submit an early warning (within 24 hours), an incident notification (within 72 hours), and a final report (within 1 month) for significant incidents.
managed
NIS2-Art.20
Governance
Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities, oversee its implementation and can be held liable for infringements. Management bodies must undergo cybersecurity training.
managed
NIS2-Art.24
Use of European Cybersecurity Certification Schemes
Member States shall, in order to demonstrate compliance with certain requirements set out in Article 21, require essential and important entities to use particular ICT products, ICT services and ICT processes that are certified under European cybersecurity certification schemes.
defined
NIS2-Art.26
Jurisdiction and Registration
Essential and important entities shall be deemed to fall under the jurisdiction of the Member State in which they are established. Entities providing services in the EU but not established in the EU must designate a representative.
defined