EU regulatory register · NIS2
Article 21Cybersecurity risk-management measures
CELEX 32022L2555 · Read on 2026-08-18 · Chapter IV
Official text
Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.
1. Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services.
Taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, the measures referred to in the first subparagraph shall ensure a level of security of network and information systems appropriate to the risks posed. When assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact.
2. The measures referred to in paragraph 1 shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the following:
(a)
policies on risk analysis and information system security;
(b)
incident handling;
(c)
business continuity, such as backup management and disaster recovery, and crisis management;
(d)
supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers;
(e)
security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;
(f)
The article continues in the official text.
Other articles in this chapter
Related articles
Articles in other acts connected to this one, with the reason written against the text. The map is a route between acts, not an assessment.
- Intersects with · mutualDORA · 6
A financial entity reads risk management in the sector act that takes precedence, and the general article only so far as it is not covered there.
CELEX 32022R2554 · 2026-08-18
- Analogous to · mutualGDPR · 32
Both articles require security measures proportionate to the risk, one for personal data and one for network and information systems.
CELEX 32016R0679 · 2026-08-18
The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.
Verifiable trust signals
- Six fixed blocks, one source per line
- No sentence written by a language model
- Engine version and read date on every answer
- No customer data, no documents, no advice
- Model card and audit published under the EU AI Act