Run the assessment
The ten measure areas of Article 21(2)
- Risk analysis and information system security policies
- Incident handling — detect, respond, and report under Art. 23
- Business continuity — backup management and disaster recovery
- Supply chain security — including direct suppliers and service providers
- Security in network and information systems — acquisition, development, maintenance and vulnerabilities handling
- Policies and procedures to assess effectiveness of cybersecurity measures
- Basic cyber hygiene practices and cybersecurity training
- Policies regarding the use of cryptography and encryption where appropriate
- Human resources security, access control policies and asset management
- Use of multi-factor authentication or continuous authentication solutions, secured voice/video/text communications and secured emergency communication systems
Honest limitation: this is a structured self-check based on the directive text. National implementing laws add registration duties and sector specifics. Confirm against your national law — this is not legal advice.
Before you start
Read the guide first: What Is a NIS2 Gap Assessment? — a plain-language explanation of what the ten Article 21 measure areas mean for your agency, with grade descriptions and next steps.
Not sure whether your company is in scope of NIS2 at all? Take the free scope self-assessment first (12 questions).
Related free tools: NIS2 Incident Report Generator · Security Headers Checker · Cookie Consent Checker
The plain-language guide: NIS2 for Small Agencies: What Changes. Full offline checklist with templates: NIS2 Compliance Kit e-book ($9.99 on Amazon).