NIS2 Requirements: The 10 Measures
The heart of the NIS2 Directive (EU 2022/2555) is Article 21: ten technical and organisational minimum measures that every affected entity must implement in line with the state of the art. Added to these are the personal liability of management under Art. 20 and the staggered reporting obligation within 24 and 72 hours under Art. 23. We explain each requirement in practical terms and guide you to demonstrable compliance.
What NIS2 Requires of You
Obligations, liability, deadlines and who is affected at a glance
10 Minimum Measures
Art. 21 (2) of EU Directive 2022/2555 defines ten mandatory risk management measures — from the risk concept to multi-factor authentication. They apply to every affected entity.
Management Liability
Art. 20 NIS2 obliges management bodies to approve and oversee the measures and to be trained themselves. In the event of breaches, management is personally liable — under the German NIS2UmsuCG without any limitation of liability.
Reporting Obligation 24 / 72 h
Significant security incidents must be reported in stages: an early warning within 24 hours, a full report within 72 hours and a final report after one month at the latest (Art. 23 NIS2).
Who Is Affected?
Affected are medium-sized and large entities (from 50 employees or EUR 10 million in turnover) across 18 sectors — divided into essential and important entities. In Germany, around 29,000 companies (BSI).
Fines & Sanctions
Breaches can incur fines of up to EUR 10 million or 2 % of worldwide annual turnover for essential entities and up to EUR 7 million or 1.4 % for important entities (Art. 34 NIS2).
Registration & Proof Obligation
Affected entities must register with the BSI and be able to demonstrate the effectiveness of their measures. Essential entities are subject to proactive supervision, important ones to incident-based supervision.
The 10 Minimum Measures under Art. 21 NIS2
Every requirement of EU Directive 2022/2555 explained individually
1. Risk Analysis & Security Concepts
Concepts for risk analysis and for the security of information systems (Art. 21 (2) lit. a). The basis is a documented, regularly updated risk management process, ideally aligned with ISO/IEC 27001 or BSI IT-Grundschutz.
2. Handling of Security Incidents
Incident handling (lit. b): processes for detecting, analysing, containing and remediating incidents — including the reporting process to the BSI with a 24-hour early warning and a 72-hour report under Art. 23.
3. Business Continuity
Backup management, recovery after emergencies and crisis management (lit. c). Business continuity and disaster recovery plans with defined RTO/RPO targets and regular recovery tests.
4. Supply Chain Security
Supply chain security (lit. d): securing relationships with suppliers and service providers, assessing their security practices and contractual security requirements right down the IT service chain.
5. Secure Procurement & Vulnerabilities
Security in the acquisition, development and maintenance of IT systems including vulnerability management and vulnerability disclosure (lit. e) — secure development, patch management and defined reporting channels for vulnerabilities.
6. & 7. Effectiveness, Cyber Hygiene & Training
Concepts for assessing the effectiveness of the measures (lit. f) as well as basic cyber hygiene and cybersecurity training (lit. g) — measurable KPIs, audits, awareness training and mandatory management training.
8. & 9. Cryptography, Access & Personnel
Concepts for cryptography and encryption (lit. h) as well as personnel security, access control based on least privilege and asset management (lit. i) — from data encryption to a complete asset inventory.
10. MFA & Secured Communication
Use of multi-factor authentication, continuous authentication as well as secured voice, video, text and emergency communication (lit. j) — the standard for all privileged and remote access.
Ready for the next step?
Let's discuss in a free initial consultation how we can move your business forward.