Free online trainings
24
Sep
Eramba Detailed Risk & Compliance Advanced
Directive (EU) 2022/2555 - Article 21

NIS2 Article 21, measure by measure

Article 21 is the to-do list of the directive: ten security measures you must have in place. Most organisations already do six or seven of them and cannot prove it. Proving it is the work.

  • Full directive, Chapter IV or Article 21 alone
  • Free CSV download
  • Every framework included
Article 21(2)Covered in eramba
  • (a)Risk analysis and security policiesPolicies
  • (b)Incident handlingIncidents
  • (c)Business continuity and crisis managementRisk
  • (d)Supply chain securityAssessments
  • (e)Acquisition and vulnerability handlingPartial
  • (f)Assessing whether the measures workControls
  • (g)Cyber hygiene and trainingAwareness
  • (h)Cryptography and encryptionYour control
  • (i)HR security, access control, asset managementAccount reviews
  • (j)Multi-factor and continuous authenticationPartial
CoveredDocumented and tested, not performedNot eramba's job

Are you in scope?

Two questions decide it: what you do, and how big you are. The sector list is set by the directive; the size gate is the same for both tiers.

The size gate. A medium or large enterprise - 50 or more employees, or €10M or more annual turnover - operating in a listed sector is in. A five-person shop is generally out, unless the state decides you are critical anyway.

Essential entities

Proactive supervision - audits without an incident

  • Energy the utility that sends your electricity bill
  • Transport the regional bus or train line
  • Banking the high-street bank holding your savings
  • Health the clinic or lab that runs your blood tests
  • Water the municipal supply and the sewers
  • Digital infrastructure the data centre hosting your site
  • Public administration tax and social security offices

Authorities can run planned audits and on-site inspections even when nothing has gone wrong.

Important entities

Reactive supervision - audited on cause

  • Food large distributors and industrial bakeries
  • Postal and courier the service delivering your parcels
  • Waste management the trucks that come on Tuesday
  • Manufacturing medical devices, electronics, car parts
  • Chemicals fertilisers and industrial cleaning agents
  • Digital providers marketplaces and search engines
  • Research university-linked laboratories

Supervision usually follows a reasonable indication of non-compliance: a breach, or a third-party report.

Where each measure lives

The exact wording of Article 21(2), and the eramba module that carries the evidence for it. Two measures are marked partial on purpose.

  • 21(2)(a)Policies on risk analysis and information system securityStore and regularly review policies, including the ones about risk itself. Approvals and review dates are part of the record.PoliciesCovered
  • 21(2)(b)Incident handlingHandle the whole lifecycle of an incident, from detection through to the lessons learned.ExceptionsCovered
  • 21(2)(c)Business continuity, such as backup management and disaster recovery, and crisis managementBusiness risks, continuity plans, and the testing of those plans - manual or automated.RiskCovered
  • 21(2)(d)Supply chain securitySend suppliers any questionnaire you like and review the answers. Findings and risks come out the other end.Online AssessmentsCovered
  • 21(2)(e)Security in acquisition, development and maintenance, including vulnerability handlingeramba is not a vulnerability scanner. It documents and tests the controls around your vulnerability process.Internal ControlsPartial
  • 21(2)(f)Policies and procedures to assess the effectiveness of cybersecurity risk-management measuresScheduled control testing, with notifications and triggers when a treatment fails its test.Internal ControlsCovered
  • 21(2)(g)Basic cyber hygiene practices and cybersecurity trainingDistribute awareness content per department on a repeating cycle, with completion recorded per person.AwarenessCovered
  • 21(2)(h)Policies and procedures regarding the use of cryptography and encryptionThe encryption is yours. The policy that mandates it, and the control that tests it, live here.PoliciesCovered
  • 21(2)(i)Human resources security, access control policies and asset managementPull accounts from your systems and make sure accounts and roles are actually reviewed by someone.OrganisationCovered
  • 21(2)(j)Multi-factor authentication or continuous authentication solutionseramba is not an authentication service. It can test systems automatically to confirm MFA is switched on.OrganisationPartial

Article 21(4) adds that an entity finding itself non-compliant must take corrective measures without undue delay. In eramba that is a project with an owner and a deadline, linked to the requirement it closes.

Your national authority decides the detail

NIS2 entered into force in January 2023. Member states had to transpose it into national law by 17 October 2024, and did so in twenty-seven different ways - several of them late. Implementation and enforcement timelines still vary.

eramba holds the same evidence either way: policies with approvals, controls with test results, incidents with timelines, suppliers with assessments.

One directive, twenty-seven laws

Netherlands

Strict split between essential and important. Important entities face no direct oversight without cause.

Germany

The BSI is the central auditor and folds NIS2 into the existing KRITIS framework, with high-detail evidence.

Belgium

The CCB requires proactive registration and collects evidence through a portal.

France

ANSSI streamlines the process alongside DORA for finance, to avoid audit fatigue.

Implementation of NIS2 Article 21 using eramba - the full guide

Try it before you talk to anyone

Download the NIS2 package as a CSV - the full directive, Chapter IV, or Article 21 on its own - and import it into the free Community edition. Nothing to unlock, no per-framework fee.

Prove the six or seven you already do

Flat annual price. Unlimited users, unlimited frameworks, every module included. Your bill does not grow with your team.

  • 39,033 downloads last year
  • 641 enterprise users
  • 11 releases last year
  • Used for ISO, PCI and SOC 2 since 2015

Pricing

Flat annual price. Unlimited users, unlimited data, every module included. Your bill does not grow with your team.

Community

Free

Self-hosted. No user limit, no time limit.

Download

Enterprise on-premises

from 2500€/year

Runs on your infrastructure, with support and updates.

See pricing

Enterprise SaaS

from 5000€/year

Hosted and operated by eramba, in the EU.

See pricing

Contact us

A practitioner answers, not a sales sequence.