Agent · nis2-2022-2555-21
NIS2 artikel 21: Cybersecurity risk-management measures
Strukturelt tre: artikkelens egne punkter, ordrett.
CELEX 32022L2555 · 2026-08-18 · Vekt 79 · minimal-risk
ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.
- Hva siden er
- Agent, NIS2 artikel 21
- Lest mot offisiell kilde
- 2026-08-18Fersk
- Ansvarlig utgiver
- ExploreWorld Legal, redaksjonenAnsvarsposisjon
Kort svar
What does NIS2 Article 21 require, and what outcome does the rule tree give?
NIS2 Article 21 is tested here by a deterministic rule tree of 14 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32022L2555. The outcome is a machine classification, not a compliance decision.
NIS2 Article 21Lest mot utgiveren 2026-08-18Offisiell tekst
- Paragraph 1 applies. 1. Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other service…
- Paragraph 2 applies. Taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, the measures referred to in the first subparagraph shall ensure a level of security of network and information systems appropriate to the risks posed. When assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure…
- Paragraph 3 applies. 2. The measures referred to in paragraph 1 shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the following:
En kildehenvisning, ikke juridisk rådgivning.
Jurisdiksjon
Samme agent, lest med ett lands øyne.
Inndata
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)
Regeltre
Hvis: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
1. Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other service…
Punkt 1
Hvis: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
Taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, the measures referred to in the first subparagraph shall ensure a level of security of network and information systems appropriate to the risks posed. When assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure…
Punkt 2
Hvis: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
2. The measures referred to in paragraph 1 shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the following:
Punkt 3
Hvis: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
(a)
Punkt 4
Hvis: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
policies on risk analysis and information system security;
Punkt 5
Hvis: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
(b)
Punkt 6
Hvis: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
incident handling;
Punkt 7
Hvis: alla(in_scope = true, punkt = 8)
Paragraph 8 applies
(c)
Punkt 8
Hvis: alla(in_scope = true, punkt = 9)
Paragraph 9 applies
business continuity, such as backup management and disaster recovery, and crisis management;
Punkt 9
Hvis: alla(in_scope = true, punkt = 10)
Paragraph 10 applies
(d)
Punkt 10
Hvis: alla(in_scope = true, punkt = 11)
Paragraph 11 applies
supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers;
Punkt 11
Hvis: alla(in_scope = true, punkt = 12)
Paragraph 12 applies
(e)
Punkt 12
Hvis: alla(in_scope = true, punkt = 13)
Paragraph 13 applies
security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;
Punkt 13
Hvis: alla(in_scope = true, punkt = 14)
Paragraph 14 applies
(f)
Punkt 14
Hvis ingen regel treffer: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
Artikkelteksten som ble lest
- 11. Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services.
- 2Taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, the measures referred to in the first subparagraph shall ensure a level of security of network and information systems appropriate to the risks posed. When assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact.
- 32. The measures referred to in paragraph 1 shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the following:
- 4(a)
- 5policies on risk analysis and information system security;
- 6(b)
- 7incident handling;
- 8(c)
- 9business continuity, such as backup management and disaster recovery, and crisis management;
- 10(d)
- 11supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers;
- 12(e)
- 13security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;
- 14(f)
Opphav
Grensesnitt
Hasher
Artefakter
Ingen rådgivning. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Sitering: 32022L2555 art. 21, Cybersecurity risk-management measures. ExploreWorld Legal, https://legal.exploreworldai.com/agent/nis2-2022-2555/artikel-21 (hämtad 2026-08-18, bevis sha256:3eac4d294907bf88, bygge legal-2026-08-25).