NIS2 risk management measures: How to meet Article 21 requirements
Cyber security risk management used to mean updating an Excel tracking sheet once or twice a year, taking a few screenshots of your cloud setup, and emailing back and forth with external auditors.
Under the NIS2 Directive, that approach is no longer viable.
The Directive mandates proactive, risk-proportionate cyber security measures, backed by strict management oversight and rapid incident reporting. When auditors or national authorities evaluate your compliance posture, static documentation from six months ago won’t pass muster. They require verifiable, continuous evidence.
This shift requires cyber security to become an ongoing governance and risk management activity rather than a compliance exercise performed once or twice a year. Organizations need visibility into evolving risks, clear accountability for managing them, and processes that ensure cyber security measures remain effective over time.
In this guide, we’ll examine NIS2 risk management measures outlined in Article 21 and discuss how organizations can implement them as part of a practical and sustainable cyber security program.
- Understanding NIS2 risk management measures
- Key risk management measures required under NIS2
- Risk analysis and security policies
- Incident handling
- Business continuity and crisis management
- Supply chain security
- Security in system acquisition, development, and maintenance
- Assessing the effectiveness of cyber security measures
- Cyber hygiene and security awareness
- Cryptography and encryption
- Human resources security, access control, and asset management
- Multi-factor authentication and secure communications
- Key risk management measures required under NIS2
- Building a risk management program that supports NIS2 compliance
- How CyberArrow supports NIS2 compliance
- FAQs
Understanding NIS2 risk management measures
NIS2 Article 21 requires organizations to implement appropriate and proportionate technical, operational, and organizational measures to manage cyber security risks and minimize the impact of incidents.
The exact measures will vary depending on the organization’s size, industry, operational environment, and risk profile. However, the objective remains the same: establish a cyber security risk management framework that protects critical services and supports operational resilience.
Key risk management measures required under NIS2
Article 21 identifies several areas that organizations should address when building a cyber security risk management program. Rather than treating these measures as separate compliance activities, organizations should integrate them into a coordinated risk management framework.
Risk analysis and security policies
Identify the systems, assets, services, and data that support your operations. Assess the threats and vulnerabilities that could affect them, evaluate potential business impacts, and document the results in a risk register.
Risk assessments should feed directly into your security policies and procedures. These policies should define how risks are identified, assessed, treated, monitored, and reviewed, as well as the responsibilities of different teams involved in managing cyber security risks.
Incident handling
Organizations should establish documented processes for detecting, reporting, assessing, responding to, and recovering from cyber security incidents.
Define escalation paths, assign responsibilities, and ensure teams know how incidents will be investigated and communicated. Test response procedures periodically to confirm that they can be executed effectively during an actual incident.
Maintain records of incidents, actions taken, and lessons learned. This information can support future improvements and help demonstrate compliance during audits and regulatory reviews.
Business continuity and crisis management
Organizations should prepare for scenarios where cyber incidents disrupt critical services or operations. Identify critical business processes, establish backup and recovery procedures, define recovery objectives, and document crisis management responsibilities.
Test business continuity and disaster recovery plans regularly to validate recovery capabilities and identify gaps before a disruption occurs.
Supply chain security
NIS2 specifically requires organizations to consider security risks associated with suppliers and service providers. Maintain an inventory of third parties that provide technology services, process data, or support critical operations. Assess supplier risks before onboarding and review them periodically thereafter.
Incorporate security requirements, incident notification obligations, and other relevant controls into vendor compliance agreements where appropriate.
Security in system acquisition, development, and maintenance
When acquiring new technologies, developing applications, or making significant system changes, evaluate security requirements before deployment. Establish processes for vulnerability management, security testing, patch management, and vulnerability disclosure to help reduce the risk of introducing exploitable weaknesses into production environments.
Assessing the effectiveness of cyber security measures
Organizations should periodically review whether their cyber security controls continue to operate effectively and address identified risks. This may involve vulnerability assessments, penetration testing, security reviews, internal audits, control assessments, and monitoring activities.
The objective is to identify weaknesses, verify that controls are functioning as intended, and address gaps before they contribute to an incident.
Cyber hygiene and security awareness
Provide training that helps personnel recognize phishing attempts, social engineering tactics, unsafe data handling practices, and other common threats. Reinforce cyber hygiene practices such as strong password management, secure device usage, software updates, and prompt reporting of suspicious activity regularly.
Cryptography and encryption
Organizations should establish policies governing the use of cryptography and encryption to protect sensitive information. This includes determining when encryption should be applied, how cryptographic keys will be managed, and how sensitive data will be protected during storage and transmission.
Align controls with the organization’s risk profile and the sensitivity of the information being processed.
Human resources security, access control, and asset management
Access to systems and information should be granted based on business needs and reviewed regularly. Organizations should maintain inventories of assets, define access control policies, review user permissions periodically, and establish procedures for onboarding, role changes, and employee departures.
Multi-factor authentication and secure communications
Where appropriate, implement multi-factor authentication (MFA) or continuous authentication mechanisms to strengthen access security.
NIS2 also encourages the use of secure communication methods, particularly when transmitting sensitive information or coordinating response activities during incidents. Integrate authentication controls and secure communications into the broader security architecture and review as technologies and risks evolve.
Building a risk management program that supports NIS2 compliance
Implementing the NIS2 risk management measures described in Article 21 requires more than individual security controls. Organizations need governance processes that ensure risks are identified, managed, monitored, and reviewed consistently across the business.
1. Establish governance and accountability
Assign clear ownership for cyber security risks and define responsibilities across security, IT, risk management, compliance, and business teams.
Management should receive regular updates on cyber security risks, control effectiveness, incident trends, and remediation activities. Establishing accountability helps ensure cyber security risks receive appropriate attention and oversight.
2. Define risk ownership and treatment processes
Every identified risk should have a designated owner responsible for evaluating and addressing it. Define how risks will be assessed, accepted, mitigated, transferred, or avoided. Consistent risk treatment processes help organizations make informed decisions and allocate resources effectively.
3. Integrate cyber security risk into enterprise risk management
Don’t manage cyber security risks in isolation. Integrate cyber security risk into enterprise risk management to provide leadership with a broader understanding of how cyber threats may affect operations, compliance, finances, and strategic objectives.
This approach also helps organizations prioritize cyber security investments based on business impact rather than technical concerns alone.
4. Moving from periodic reviews to continuous oversight
Many of the risk management measures described in Article 21 have traditionally been managed through periodic reviews. Risk assessments may be performed annually, access reviews completed every quarter, and vendor assessments conducted only during onboarding.
As environments become more complex, these point-in-time activities may not provide sufficient visibility into emerging risks.
| NIS2 requirement | Traditional approach | Continuous approach |
| Access management | Periodic user access reviews | Ongoing monitoring of privileged accounts, role changes, and MFA enforcement. |
| Incident handling | Manual collection of logs during investigations | Continuous logging, monitoring, and audit trail management. |
| Supply chain security | Annual vendor assessments | Continuous monitoring of vendor risks, certifications, and remediation activities. |
A more continuous approach helps organizations identify issues earlier, maintain stronger oversight, and demonstrate that risk management measures remain effective over time.
5. Maintain evidence for audits and assessments
Organizations should document risk assessments, policy reviews, incident investigations, supplier assessments, testing activities, and corrective actions.
Maintaining evidence in a structured and accessible manner makes it easier to demonstrate compliance and reduces the effort required during audits, assessments, and regulatory reviews.
How CyberArrow supports NIS2 compliance
You don’t need to rebuild your security architecture from scratch to implement NIS2 risk management measures. CyberArrow GRC helps organizations support these requirements by enabling teams to:
- Conduct and document risk assessments.
- Maintain centralized risk registers and treatment plans.
- Monitor remediation activities and track corrective actions.
- Manage policies and control frameworks from a single platform.
- Perform third-party and supplier risk assessments.
- Collect and maintain evidence for audits and regulatory reviews.
- Monitor compliance activities through real-time dashboards and reporting.
See how an environmental regulatory organization in Berlin achieved NIS2 compliance with CyberArrow GRC.
Schedule a free demo today to see how CyberArrow handles continuous control monitoring for Article 21.
See what our clients have to say about CyberArrow GRC:
FAQs
What are NIS2 risk management measures?
NIS2 risk management measures are the technical, operational, and organizational controls organizations implement to manage cyber security risks and reduce the impact of incidents. These measures are outlined in Article 21 of the Directive.
What does Article 21 of NIS2 require?
Article 21 requires organizations to implement appropriate and proportionate cyber security risk management measures covering areas such as risk assessments, incident handling, business continuity, supply chain security, security testing, access controls, and cyber security training.
Are risk assessments mandatory under NIS2?
Yes. Risk analysis is one of the core measures identified in Article 21 and forms the foundation of an organization’s cyber security risk management program.
Does NIS2 require supply chain risk management?
Yes. Organizations must assess and manage cyber security risks associated with suppliers and service providers, particularly those that support critical business functions.
