Article 21 is the article of Directive (EU) 2022/2555 that says what an essential or important entity has to do, and it does it in one list. Paragraph 1 sets the standard: "appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems", to a level "appropriate to the risks posed", taking into account "the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation", with proportionality judged by exposure, size, likelihood and severity. Paragraph 2 then says the measures "shall be based on an all-hazards approach" and "shall include at least" ten things. This article is those ten as a checklist, with the two documents that give each one its detail.
Where the detail comes from
For the digital providers, cloud, data centre, CDN, managed service, managed security service, marketplace, search engine, social networking, DNS, TLD and trust services, the detail is not national. Article 21(5) told the Commission to adopt "the technical and the methodological requirements" of the ten measures for them by 17 October 2024, and Implementing Regulation (EU) 2024/2690 did, in an Annex of 13 sections, each headed with the point of Article 21(2) it implements. The Regulation's recital 3 says the sections "are based on European and international standards, such as ISO/IEC 27001, ISO/IEC 27002 and ETSI EN 319401". For every other entity the member state's act carries the detail, and most states have written it from the same standards.
So the checklist has three columns beside the point: the Directive's own words, the sections of the Regulation that detail it, and the ISO 27001 clauses and Annex A controls that produce the evidence. The mapping is ours, not ENISA's, and the mapping page carries it section by section with what each section asks.
The ten points
| Point | The measure, as Article 21(2) words it | Regulation sections | ISO 27001 |
|---|---|---|---|
| (a) | Policies on risk analysis and information system security | 1, 2 | 5.1, 5.2, 6.1.2, 6.1.3, 8.2, 8.3, A.5.1, A.5.2, A.5.4, A.5.7, A.5.35, A.5.36 |
| (b) | Incident handling | 3 | A.5.5, A.5.24, A.5.25, A.5.26, A.5.27, A.5.28, A.6.8, A.8.17 |
| (c) | Business continuity, such as backup management and disaster recovery, and crisis management | 4 | A.5.29, A.5.30, A.8.13, A.8.14 |
| (d) | Supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers | 5 | A.5.19, A.5.20, A.5.21, A.5.22, A.5.23 |
| (e) | Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure | 6 | A.8.8, A.8.20, A.8.21, A.8.22, A.8.25, A.8.26, A.8.27, A.8.28, A.8.29, A.8.31, A.8.32 |
| (f) | Policies and procedures to assess the effectiveness of cybersecurity risk-management measures | 7 | 9.1, 9.2, 9.3, 10.1, 10.2 |
| (g) | Basic cyber hygiene practices and cybersecurity training | 8 | 7.2, 7.3, A.6.3, A.8.7, A.8.19 |
| (h) | Policies and procedures regarding the use of cryptography and, where appropriate, encryption | 9 | A.5.33, A.8.24 |
| (i) | Human resources security, access control policies and asset management | 10 | A.5.3, A.6.1, A.6.2, A.6.4, A.6.5, A.6.6 |
| (j) | The use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate | 11, 12, 13 | A.5.9, A.5.10, A.5.11, A.5.12, A.5.13, A.5.14, A.5.15, A.5.16, A.5.17, A.5.18, A.7.1, A.7.2, A.7.3, A.7.4, A.7.5, A.7.8, A.7.10, A.7.11, A.7.12, A.7.14, A.8.2, A.8.3, A.8.5, A.8.10, A.8.18 |
Sections 11 to 13 of the Regulation cite point (j) in their headings although point (i) is the one that names access control and asset management; the table records the Annex as published.
The two places an ISMS stops
Eight of the ten points are produced in full by a conforming ISO 27001 management system, and the table shows which clause or control produces each. Two are not.
Point (b), incident handling, is met by the ISO 27001 incident process for everything except the statutory clock: the Directive's Article 23 asks for an early warning, a notification and a final report on fixed deadlines, to a CSIRT or competent authority, and for a significance test, and for the digital providers the Regulation's Articles 3 to 14 make that test mechanical. An ISMS has an incident register; it does not have a rule that a cloud service unavailable for more than half an hour is a notifiable incident, or a filer with an EU Login. The clocks and the thresholds are their own article.
Point (g), cyber hygiene and training, is met for staff and missed for the board. Article 20(2) requires "the members of the management bodies of essential and important entities" themselves "to follow training", and Article 20(1) makes those bodies approve the measures, oversee their implementation and be liable for infringements. ISO 27001 asks for leadership commitment and for competence; it does not put the directors in the training register or attach liability to their signature. The evidence a supervisor asks for here is a training record with the board's names on it and a minute of the approval.
How to use the table
For each point, the question is not whether a policy exists but whether the records the right-hand column names exist and are current: the risk assessment and treatment plan and the Statement of Applicability for (a); the incident register, the contact with the authority and the synchronised clocks for (b); the tested continuity plan and the backups for (c); the supplier register with the security clauses and the reviews for (d); the secure development procedure and the vulnerability handling and disclosure process for (e); the internal audit, the management review and the measurements for (f); the training records and the hygiene baseline for (g); the cryptography policy and the key management for (h); the screening, the joiner-mover-leaver process and the asset inventory for (i); and the authentication policy, the access controls and the physical controls for (j). Article 21(4) is the rule for what the table turns up: an entity "that finds that it does not comply with the measures provided for in paragraph 2 takes, without undue delay, all necessary, appropriate and proportionate corrective measures".
Whether the Directive reaches you at all, and as which kind of entity, is the scope determination; which state's act carries the detail, if you are not a digital provider, is on the register page. StandardOS keeps the records in the right-hand column as living records, mapped to the sections, so the checklist is a view of the system rather than a document to maintain beside it.
Sources
- Directive (EU) 2022/2555 (NIS2), Article 20(1) and (2), Article 21(1) to (5), Article 23(4), read on EUR-Lex in six languages.
- Commission Implementing Regulation (EU) 2024/2690, recital 3, Article 1, Articles 3 to 14, Annex, sections 1 to 13.
- ISO/IEC 27001:2022, clauses 4 to 10 and Annex A, for the references in the table.
This is not legal advice, and the mapping to ISO 27001 is StandardOS's reading of the two texts, checkable against both.