The ten NIS2 security measures, in plain words
Article 21 in plain terms — what each of the ten measures means, and the difference between claiming a control and proving it.
The short version: the Law of 5 May 2026 requires ten cybersecurity measures of every entity it covers — essential and important alike. They come from Article 21 of the NIS2 Directive, and they are the checklist the ILR will hold you to. Here is what each one means in plain terms, and what "done" actually looks like.
None of the ten is exotic. What trips companies up is not understanding them — it is proving them. A control you have written into a policy but never tested is not the same thing, to a regulator or an insurer, as one you can evidence.
The ten measures, in plain words
- Risk analysis and security policies. A written view of the risks your business actually faces, and security rules that follow from it — not a template downloaded and signed.
- Incident handling. A plan for detecting, managing and recording incidents, so that when something happens you respond rather than improvise.
- Business continuity. Backups that are actually tested, disaster recovery, and a way to keep operating through a crisis.
- Supply chain security. Managing the security of the suppliers and service providers who touch your systems — and the contract terms that hold them to it.
- Secure acquisition and development. Security built into the systems you buy, build and maintain, including how you handle and disclose vulnerabilities.
- Testing effectiveness. A way to check that your measures actually work — not just that they exist on paper.
- Cyber hygiene and training. The basics done consistently, and real training for your staff.
- Cryptography. Encryption used where it matters, under a policy that says where and how.
- Human resources, access control and asset management. Control over who can access what, what happens when people join or leave, and knowing what assets you actually have.
- Multi-factor authentication and secure communications. Two-step login where it counts, and secured voice, video and text communications, including for emergencies.
The same ten apply to essential and important entities. What differs is supervision, not the requirements: essential entities are checked proactively, important entities after an incident or a complaint. So "we are only important" does not reduce the list — it only changes when someone looks.
Proportionality: all ten apply, but not to the same depth
Article 21 asks for measures that are appropriate and proportionate to your risk, size and exposure. A 60-person logistics firm is not held to the same depth as a national grid operator. But proportionality scales how far you take each measure — it does not let you skip one. All ten have to be present; the sophistication is what flexes.
Where companies actually fall short
In practice the gaps cluster in the same few places, and they are rarely the exotic ones:
- Multi-factor authentication deployed for most accounts but not all — and the ones missing it are often the privileged ones.
- Backups that exist but have never been restored, so nobody knows if they work.
- No supplier security clauses, because IT contracts were signed before anyone thought about the supply chain.
- No way to test effectiveness — measures are asserted, never checked.
These are not expensive to fix. What they need is someone to find them honestly, which is the part an internal team or the provider who built the setup cannot do for itself.
Claimed is not proven. Every one of the ten can be scored two ways: how developed it is, and how you know — you said so, we read the document, or we tested it and saw the result. A file full of "claimed" controls satisfies nobody who matters. When you assess yourself against Article 21, insist on the second number.
How we help
Our Compliance Audit measures you against all ten, tests what can be tested, and labels the rest honestly — so your file shows a regulator, an insurer or a client which controls rest on evidence and which rest on somebody's word. You end up with a risk assessment, a security policy, an action plan and an incident procedure written for your company, and a clear list of what to fix, in what order.
Not sure whether the law applies to you in the first place? That is a separate, quicker question — and one we answer in writing before any of this.