Agent · nis2-2022-2555-21
NIS2 artikel 21: Cybersecurity risk-management measures
Structural tree: the article's own paragraphs, verbatim.
CELEX 32022L2555 · 2026-08-18 · Weight 79 · minimal-risk
ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.
- What this page is
- Agent, NIS2 artikel 21
- Checked against the official source
- 2026-08-18Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does NIS2 Article 21 require, and what outcome does the rule tree give?
NIS2 Article 21 is tested here by a deterministic rule tree of 14 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32022L2555. The outcome is a machine classification, not a compliance decision.
NIS2 Article 21Checked against the publisher 2026-08-18Official text
- Paragraph 1 applies. 1. Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other service…
- Paragraph 2 applies. Taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, the measures referred to in the first subparagraph shall ensure a level of security of network and information systems appropriate to the risks posed. When assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure…
- Paragraph 3 applies. 2. The measures referred to in paragraph 1 shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the following:
A source reference, not legal advice.
Jurisdiction
The same agent, read through one country's lens.
Inputs
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)
Rule tree
If: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
1. Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other service…
Paragraph 1
If: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
Taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, the measures referred to in the first subparagraph shall ensure a level of security of network and information systems appropriate to the risks posed. When assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure…
Paragraph 2
If: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
2. The measures referred to in paragraph 1 shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the following:
Paragraph 3
If: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
(a)
Paragraph 4
If: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
policies on risk analysis and information system security;
Paragraph 5
If: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
(b)
Paragraph 6
If: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
incident handling;
Paragraph 7
If: alla(in_scope = true, punkt = 8)
Paragraph 8 applies
(c)
Paragraph 8
If: alla(in_scope = true, punkt = 9)
Paragraph 9 applies
business continuity, such as backup management and disaster recovery, and crisis management;
Paragraph 9
If: alla(in_scope = true, punkt = 10)
Paragraph 10 applies
(d)
Paragraph 10
If: alla(in_scope = true, punkt = 11)
Paragraph 11 applies
supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers;
Paragraph 11
If: alla(in_scope = true, punkt = 12)
Paragraph 12 applies
(e)
Paragraph 12
If: alla(in_scope = true, punkt = 13)
Paragraph 13 applies
security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;
Paragraph 13
If: alla(in_scope = true, punkt = 14)
Paragraph 14 applies
(f)
Paragraph 14
If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
The article text as read
- 11. Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services.
- 2Taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, the measures referred to in the first subparagraph shall ensure a level of security of network and information systems appropriate to the risks posed. When assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact.
- 32. The measures referred to in paragraph 1 shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the following:
- 4(a)
- 5policies on risk analysis and information system security;
- 6(b)
- 7incident handling;
- 8(c)
- 9business continuity, such as backup management and disaster recovery, and crisis management;
- 10(d)
- 11supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers;
- 12(e)
- 13security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;
- 14(f)
Lineage
Interface
Hashes
Artefacts
No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Citation: 32022L2555 art. 21, Cybersecurity risk-management measures. ExploreWorld Legal, https://legal.exploreworldai.com/agent/nis2-2022-2555/artikel-21 (hämtad 2026-08-18, bevis sha256:3eac4d294907bf88, bygge legal-2026-08-25).