NIS2 Directive, Cybersecurity Risk-Management Measures
Directive (EU) 2022/2555, Art. 21
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 18 October 2024.
A sector security regimes rule binding public and private bodies.
As of 8 September 2026.
What it requires
- This duty reaches your service where you qualify as a medium-sized enterprise or larger under the EU size-cap rule (Commission Recommendation 2003/361/EC) and you operate an online marketplace, online search engine or social networking services platform under Annex II, or where you are a public administration entity of central or regional government under Annex I.
- Take technical, operational and organisational measures appropriate to the risk your network and information systems face, covering at minimum a risk analysis and information-system-security policy, incident handling, business continuity and crisis management, supply chain security, and security in the acquisition, development and maintenance of your systems.
- Maintain basic cyber hygiene practices and cybersecurity training, policies on cryptography and encryption where appropriate, human resources security and access control, and multi-factor authentication or continuous authentication solutions where appropriate.
- Have your management body approve these measures, oversee their implementation, and complete cybersecurity training.
- If you are not established in the Union but offer a covered service within it, designate a representative established in a Member State where you offer the service.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
Article 34(4): where a Member State's transposing law is infringed as to Article 21 (or Article 23), an essential entity is subject to an administrative fine of a maximum of at least EUR 10,000,000 or at least 2 percent of total worldwide annual turnover, whichever is higher. Article 34(5) sets a lower tier for an important entity, a maximum of at least EUR 7,000,000 or at least 1.4 percent of turnover, whichever is higher; that lower tier is also recorded on this instrument because Article 34 draws no separate figure for Article 21 alone. This is a directive: the figures are the floor each Member State's own transposing law must set as its statutory maximum, not a cap the Union applies directly, and a given Member State's actual ceiling may be set higher.
- Rule
- Higher of
- As of
- 8 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The competent authority designated or established by each EU Member State under Article 8 of the Directive, coordinated at Union level through the NIS Cooperation Group and the CSIRTs network.
Settledness
- As of
- 8 September 2026
- Guidance link
- https://www.enisa.europa.eu/sites/default/files/2025-06/ENISA_Technical_implementation_guidance_on_cybersecurity_risk_management_measures_version_1.0.pdf
- Guidance body
- European Union Agency for Cybersecurity (ENISA), Technical Implementation Guidance on Commission Implementing Regulation (EU) 2024/2690, developed with the NIS Cooperation Group and the European Commission
- Open questions
- Does the medium-enterprise size threshold under Article 2(1) test a social networking platform, online marketplace or search engine on a standalone basis, or does the partner-enterprise and linked-enterprise aggregation built into Commission Recommendation 2003/361/EC pull in the turnover and headcount of its wider corporate group?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 21 requires each Member State to ensure that essential and important entities, defined by the Annex I and Annex II sector lists together with a medium-enterprise size threshold set under Article 2, take appropriate and proportionate technical, operational and organisational measures to manage the cybersecurity risks to the network and information systems they use, based on an all-hazards approach covering at least risk analysis and information system security, incident handling, business continuity, supply chain security, security in system acquisition and maintenance, the effectiveness of the measures, basic cyber hygiene and training, cryptography, human resources security and access control, and multi-factor or continuous authentication.
Annex II names online marketplaces, online search engines and social networking services platforms among the digital providers this duty reaches once they cross the medium-enterprise size threshold, and Annex I separately reaches public administration entities of central and regional government.
An entity not established in the Union that offers such a service within it must designate a representative in a Member State where it offers the service, and falls under that Member State's jurisdiction for this duty.
When LexLint raises it
operates_social_platform