NIS2 checkContact

Article 21(2)

The ten NIS2 measures

NIS2 describes ten areas in which organisations have to take appropriate security measures. Many organisations already have part of that in place. The questions that matter are whether the measures match the risks, whether they are carried out consistently, and whether they can be demonstrated with current information.

Reading guide

The structure of the directive

The measures below follow the letters (a) to (j) of Article 21(2). That lets you compare this overview directly against the directive, against national law such as the Dutch Cyberbeveiligingswet, against audit questions and against customer and supplier questionnaires.

Appropriate to the risk. Article 21(1) requires appropriate and proportionate measures. How they are set up therefore depends on the size of the organisation, its activities, its technical environment, the cost and the possible consequences of an incident. That is why the mapping below names a SmartCyber level per measure rather than one answer for everyone.

Demonstrably carried out. A policy document is not enough when the measure it describes is not carried out or checked. You have to be able to show what is in place, when checks were run and what was done about the exceptions. Having a backup policy is not enough; what has to be shown is a successful restore test.

The ten measures

Each measure, and how we deliver it

The letter is the directive's. The description is what the measure means for an organisation of your size. The badge names the lowest SmartCyber level that covers it.

1

Risk and security policies

A current risk assessment covering the main systems, data, threats and dependencies, with an owner, a priority and a planned measure per risk. An asset register, an overview of what you have under management, that is kept current, and security policies that match how the organisation is actually set up and actually works, aligned with ISO 27001.

Shared responsibility We draw up the assessment and the policies together with you. Your board decides which risks are acceptable and approves the policies.

Protect
2

Incident handling

Recognising, assessing, containing and reporting security incidents. Detection and response from our SOC, day and night, with SIEM and XDR underneath, rehearsed playbooks, and a response time on priority alerts set out in the SLA. For each type of incident it is recorded which actions the SOC may carry out immediately.

Think Smart Europe carries this out Our SOC handles detection, triage and the agreed response. Your organisation approves formal notifications and external communication.

Essential
3

Business continuity

Backups that cannot be altered or deleted, restore tests fixed in the calendar, and recovery objectives that were on paper before anyone needed them. For important processes we record in advance the recovery time required and the maximum data loss allowed.

Think Smart Europe carries this out We manage the agreed backups, restore tests and technical run books. The RTO and RPO, how long recovery may take and how much data you may lose in the process, are set together with you.

Essential
4

Supply chain security

Knowing which suppliers have access to systems, data or critical processes and what risks come with that: a maintained supplier register, security requirements in the contracts, and assessments with evidence behind them.

Shared responsibility We run the supplier register and the security assessments. Your organisation remains responsible for the commercial and legal arrangements with suppliers.

Advanced
5

System lifecycle

Acquiring, developing, configuring, updating and changing systems securely. Patching on an agreed rhythm, vulnerability scanning, hardened configurations and security testing that follows every system through its life. For software development we look at matters such as access rights, code management, testing and the handling of vulnerabilities found.

Think Smart Europe carries this out We run the agreed scans, updates and technical checks within the recorded remediation windows.

Protect
6

Effectiveness assessment

Assessing periodically whether the measures are carried out and have the intended effect: patch coverage, restore tests, follow-up on alerts, account management and vulnerabilities, reported on a fixed rhythm instead of one assessment gathering dust.

Think Smart Europe carries this out We collect and report the agreed data. The internal audit can be run by your organisation or by a separately appointed party.

Advanced
7

Cyber hygiene and training

Teaching staff how to recognise and report suspicious email, unusual requests and possible incidents. A structured awareness programme, phishing simulation with per-person completion records, and the training Article 20 obliges the management body itself to follow.

Think Smart Europe carries this out We run the agreed training programme and record attendance and results.

Essential
8

Cryptographic controls

Data encrypted where it sits and where it travels, certificates and keys managed across their full lifecycle, and a record of who has access, how keys are replaced and what happens when a key or a certificate expires.

We set it up; your organisation keeps ownership We set up the technical provisions for encryption and key management. Ownership and final control over the keys stay with your organisation.

Protect
9

HR security and access control

Access rights that match the role and are adjusted in time when someone changes role or leaves, with joiner, mover and leaver wired to HR, privileges reviewed against least privilege, meaning no more rights than someone needs, and administrator accounts managed separately and checked periodically.

Shared responsibility We run the technical measures and the access reviews. HR and line managers remain responsible for passing on and approving changes in time.

Advanced
10

Authentication and communications

Multi-factor authentication reduces the chance that a stolen password gives direct access. Strong sign-in wherever it matters, with conditional access on top, secured collaboration tools, and a separate communication channel for situations in which the normal email or collaboration environment cannot be relied on.

Think Smart Europe carries this out We set up and manage the agreed technical measures: strong sign-in, conditional access and the channel outside your own network (out-of-band).

Essential

The mapping to the SmartCyber levels is a first indication. During the intake we establish which measures fit the risks, the size and the technical environment of your organisation.

The same ten, as a table

How responsibilities are divided

For each measure the table states which work we carry out and which decisions or processes stay with your organisation.

The NIS2 Article 21(2) measures, what Think Smart Europe delivers, and who carries it out
MeasureWhat we deliver for itWho operates itFrom SmartCyber
a) Risk and security policies A current risk assessment covering the main systems, data, threats and dependencies, with an owner, a priority and a planned measure per risk. An asset register, an overview of what you have under management, that is kept current, and security policies that match how the organisation is actually set up and actually works, aligned with ISO 27001. Shared responsibility
We draw up the assessment and the policies together with you. Your board decides which risks are acceptable and approves the policies.
Protect
b) Incident handling Recognising, assessing, containing and reporting security incidents. Detection and response from our SOC, day and night, with SIEM and XDR underneath, rehearsed playbooks, and a response time on priority alerts set out in the SLA. For each type of incident it is recorded which actions the SOC may carry out immediately. Think Smart Europe carries this out
Our SOC handles detection, triage and the agreed response. Your organisation approves formal notifications and external communication.
Essential
c) Business continuity Backups that cannot be altered or deleted, restore tests fixed in the calendar, and recovery objectives that were on paper before anyone needed them. For important processes we record in advance the recovery time required and the maximum data loss allowed. Think Smart Europe carries this out
We manage the agreed backups, restore tests and technical run books. The RTO and RPO, how long recovery may take and how much data you may lose in the process, are set together with you.
Essential
d) Supply chain security Knowing which suppliers have access to systems, data or critical processes and what risks come with that: a maintained supplier register, security requirements in the contracts, and assessments with evidence behind them. Shared responsibility
We run the supplier register and the security assessments. Your organisation remains responsible for the commercial and legal arrangements with suppliers.
Advanced
e) System lifecycle Acquiring, developing, configuring, updating and changing systems securely. Patching on an agreed rhythm, vulnerability scanning, hardened configurations and security testing that follows every system through its life. For software development we look at matters such as access rights, code management, testing and the handling of vulnerabilities found. Think Smart Europe carries this out
We run the agreed scans, updates and technical checks within the recorded remediation windows.
Protect
f) Effectiveness assessment Assessing periodically whether the measures are carried out and have the intended effect: patch coverage, restore tests, follow-up on alerts, account management and vulnerabilities, reported on a fixed rhythm instead of one assessment gathering dust. Think Smart Europe carries this out
We collect and report the agreed data. The internal audit can be run by your organisation or by a separately appointed party.
Advanced
g) Cyber hygiene and training Teaching staff how to recognise and report suspicious email, unusual requests and possible incidents. A structured awareness programme, phishing simulation with per-person completion records, and the training Article 20 obliges the management body itself to follow. Think Smart Europe carries this out
We run the agreed training programme and record attendance and results.
Essential
h) Cryptographic controls Data encrypted where it sits and where it travels, certificates and keys managed across their full lifecycle, and a record of who has access, how keys are replaced and what happens when a key or a certificate expires. We set it up; your organisation keeps ownership
We set up the technical provisions for encryption and key management. Ownership and final control over the keys stay with your organisation.
Protect
i) HR security and access control Access rights that match the role and are adjusted in time when someone changes role or leaves, with joiner, mover and leaver wired to HR, privileges reviewed against least privilege, meaning no more rights than someone needs, and administrator accounts managed separately and checked periodically. Shared responsibility
We run the technical measures and the access reviews. HR and line managers remain responsible for passing on and approving changes in time.
Advanced
j) Authentication and communications Multi-factor authentication reduces the chance that a stolen password gives direct access. Strong sign-in wherever it matters, with conditional access on top, secured collaboration tools, and a separate communication channel for situations in which the normal email or collaboration environment cannot be relied on. Think Smart Europe carries this out
We set up and manage the agreed technical measures: strong sign-in, conditional access and the channel outside your own network (out-of-band).
Essential

The lettering follows Article 21(2) of the NIS2 directive. The Dutch Cyberbeveiligingswet copies the same ten measures into article 21(3)(a) to (j) with the same letters, so either reference works. The final division of tasks is recorded per organisation in the agreement and the service description.

Where it goes wrong in practice

We carry it out and prove it

In assessments we regularly find that measures do exist, but that nobody can show when they were last carried out or checked.

What we typically find
  • A backup policy, and no record of a tested restore
  • Multi-factor authentication on email, but not on remote access or admin accounts
  • An asset list in a spreadsheet that was accurate eighteen months ago
  • Supplier contracts with no security clause and no assessment on file
  • Awareness training completed once, with no record of who and when
  • An incident procedure that has never been run as an exercise

None of these is negligence. They are the normal state of a busy IT department that was never asked for evidence before.

What closing the gap looks like
  • Restores tested on a schedule, with the result on file
  • Conditional access covering every route in, reviewed quarterly
  • An asset inventory that updates itself from the tooling that manages the assets
  • A supplier register, standard security clauses, and assessments in date order
  • Awareness and phishing simulation with per-person completion records
  • A tabletop exercise a year, and the report from it

We solve this by scheduling the checks as recurring work and recording the results. The reporting you need then comes out of the day-to-day service instead of a project just before an audit.

How we work through them

Our approach in five steps

Every client follows the same route, from scoping to an operation that keeps the evidence current. At any moment you can point at the step you are in and at what it produces.

01

Scope

Per legal entity and per country we establish which legislation applies and which systems and processes fall inside the assessment.

02

Assess

We hold the existing measures and the available evidence against the ten areas of the directive and against national law, such as the Cyberbeveiligingswet in the Netherlands, CyberFundamentals in Belgium or ReCyF in France.

03

Plan

You receive a remediation plan with priorities, responsibilities, costs and decision points, drawn up so the board can formally adopt it, because Article 20 requires exactly that approval.

04

Implement

Our own engineers in Amsterdam and Sofia put the missing technical and organisational measures in place. Nothing is passed to a third party, and nothing lands on your team as homework.

05

Operate and monitor

The SOC and our management teams run the agreed checks, handle alerts and keep the reporting and the evidence current. The board receives its quarterly report.

Which measures are in place, and which are still missing?

In a call with our CISO we go through which measures are already in place, what evidence is available, and which points need attention first.

Cyber Incident