NIS2
NIS2 Directive (EU 2022/2555)
The EU directive raising the baseline for cybersecurity risk management and incident reporting across critical sectors. Article 21 sets the minimum security measures; Article 23 sets incident reporting timelines.
Who it applies to
Medium and large organizations operating in critical sectors across the EU — energy, transport, health, banking, digital infrastructure, public administration, water, waste and more — classified as 'essential' or 'important' entities.
Article 21 — Risk-management measures
- Art. 21(2)(a) Risk analysis and information system security policies16 mapped
Establish policies on risk analysis and information system security as a foundation of the security programme.
- Art. 21(2)(b) Incident handling10 mapped
Implement processes to prevent, detect, analyse and respond to security incidents.
- Art. 21(2)(h) Cryptography and encryption13 mapped
Adopt policies and procedures on the use of cryptography and, where appropriate, encryption.
- Art. 21(2)(i) Access control and asset management14 mapped
Apply human-resources security, access control policies and asset management.