Organization
Tool: NIS2 Article 21 self-assessment
For: finance, risk and compliance · executives and CIOsPrerequisites: Basic notions of the NIS2 directive.
Article 21 of the NIS2 directive lists ten cybersecurity risk-management measures. The question an auditor will ask is not “does the measure exist?” but “can you prove it?”. This tool separates the two, and suggests for each measure the evidence observability can produce.
| Measure | Evidence telemetry can provide | Status |
|---|---|---|
| aPolicies on risk analysis and information system security | asset inventory kept up to date by automatic discovery, dated review | |
| bIncident handling | alerts, timestamped timelines, tickets linked to traces and logs | |
| cBusiness continuity, backup management, disaster recovery, crisis management | backup success, timed restore tests, logged exercises | |
| dSupply chain security | measured availability and errors of supplier services, logged supplier access | |
| eSecurity in acquisition, development and maintenance, including vulnerability handling and disclosure | tracked deployed versions, software bill of materials (SBOM), measured patch delays | |
| fAssessing the effectiveness of risk-management measures | security indicators tracked over time, archived reviews | |
| gBasic cyber hygiene and cybersecurity training | patch and configuration status, training rate tracked | |
| hCryptography and encryption | certificate inventory and expiry, logged key rotation | |
| iHuman resources security, access control, asset management | access logs, privileged account review, leavers processed | |
| jMulti-factor or continuous authentication, secured and emergency communications | share of access with MFA, authentication logs, emergency channel tests |
Result
- Demonstrable
- In place, no evidence
- Partial
- Missing
Action plan, by priority
Reference: Article 21(2), points (a) to (j), of Directive (EU) 2022/2555. This tool helps prepare the discussion with the CISO and legal; it is not legal advice, and how it applies to your organization depends on your classification and on the national transposition law. Nothing is sent: your answers stay in this browser.
Things to try
Section titled “Things to try”- The starting situation is Helinord’s in June 2025, from the journal in the CIO path: three partial measures, seven missing. The action plan starts with the missing ones.
- Set incident handling (b) to “In place, no evidence”: it drops to priority 3, but stays in the plan. A process nobody can demonstrate does not count in front of an auditor.
- Declare a measure not applicable: it leaves the denominator, and the tool reminds you that the justification must be written down.
- Aim for eight out of ten, like Helinord a year later: the remaining two often depend on suppliers and go through a contractual plan.
The rule to remember
Section titled “The rule to remember”A measure without evidence is a paper measure. Every line of the table should be backed by a metric, a log or a dashboard that demonstrates it is effective over time. This tool is not legal advice: your organization’s classification and the national rules should be checked with your lawyer. This matters all the more since the French transposition law has not yet been enacted as of October 2, 2026.
Going further: the compliance lesson of the CIO path, a signed log is not an auditable log and the evidence matrix of the GenAI method.