HomeRequirements
Obligation map
Understand the obligations.
A structured view of key Directive provisions, with implementation questions and evidence to consider. Apply the national framework to your organisation.
Article 21
Cybersecurity risk management
Build proportionate measures around risk analysis, policies, incident handling, continuity, supply chain and other areas listed in Article 21.
↗Article 23Incident reporting
Prepare to assess significant incidents and make staged notifications through the relevant national route.
↗Article 20Management accountability
Management bodies have a role in approving and overseeing cybersecurity risk-management measures and receiving relevant training.
↗Article 21Supply-chain security
Consider security-related aspects of relationships with direct suppliers and service providers within the risk-management measures.
↗