INDEPENDENT NIS2 RESOURCEGovernance · Resilience · ImplementationEU framework / national application
HomeRequirementsCybersecurity risk management
Article 21 / Requirement

Cybersecurity risk management

Build proportionate measures around risk analysis, policies, incident handling, continuity, supply chain and other areas listed in Article 21.

What this means in practice

Translate the provision into accountable decisions and documented processes. The exact application depends on the entity, the relevant national law and any applicable sector-specific rules.

Implementation questions

  1. Define the systems and services in scope
  2. Record risk decisions and accountable owners
  3. Review measures against Article 21 and national requirements

Evidence to organise

RecordWhat to check
Approved risk methodologyOwner, currency, approval and follow-up actions
Control inventory and policy ownersOwner, currency, approval and follow-up actions
Review and exception recordsOwner, currency, approval and follow-up actions
These are planning prompts, not an exhaustive legal checklist or proof of compliance.

Official sources and context

Use these alongside the applicable national legislation and authority guidance. This page is general information and may not reflect every national measure or later amendment.