Skip to content

OrganizationPractitioner

Tool: NIS2 Article 21 self-assessment

For: finance, risk and compliance · executives and CIOsPrerequisites: Basic notions of the NIS2 directive.

Reading mode

Article 21 of the NIS2 directive lists ten cybersecurity risk-management measures. The question an auditor will ask is not “does the measure exist?” but “can you prove it?”. This tool separates the two, and suggests for each measure the evidence observability can produce.

MeasureEvidence telemetry can provideStatus
aPolicies on risk analysis and information system securityasset inventory kept up to date by automatic discovery, dated review
bIncident handlingalerts, timestamped timelines, tickets linked to traces and logs
cBusiness continuity, backup management, disaster recovery, crisis managementbackup success, timed restore tests, logged exercises
dSupply chain securitymeasured availability and errors of supplier services, logged supplier access
eSecurity in acquisition, development and maintenance, including vulnerability handling and disclosuretracked deployed versions, software bill of materials (SBOM), measured patch delays
fAssessing the effectiveness of risk-management measuressecurity indicators tracked over time, archived reviews
gBasic cyber hygiene and cybersecurity trainingpatch and configuration status, training rate tracked
hCryptography and encryptioncertificate inventory and expiry, logged key rotation
iHuman resources security, access control, asset managementaccess logs, privileged account review, leavers processed
jMulti-factor or continuous authentication, secured and emergency communicationsshare of access with MFA, authentication logs, emergency channel tests

Result

  • Demonstrable
  • In place, no evidence
  • Partial
  • Missing

Action plan, by priority

Reference: Article 21(2), points (a) to (j), of Directive (EU) 2022/2555. This tool helps prepare the discussion with the CISO and legal; it is not legal advice, and how it applies to your organization depends on your classification and on the national transposition law. Nothing is sent: your answers stay in this browser.

  1. The starting situation is Helinord’s in June 2025, from the journal in the CIO path: three partial measures, seven missing. The action plan starts with the missing ones.
  2. Set incident handling (b) to “In place, no evidence”: it drops to priority 3, but stays in the plan. A process nobody can demonstrate does not count in front of an auditor.
  3. Declare a measure not applicable: it leaves the denominator, and the tool reminds you that the justification must be written down.
  4. Aim for eight out of ten, like Helinord a year later: the remaining two often depend on suppliers and go through a contractual plan.

A measure without evidence is a paper measure. Every line of the table should be backed by a metric, a log or a dashboard that demonstrates it is effective over time. This tool is not legal advice: your organization’s classification and the national rules should be checked with your lawyer. This matters all the more since the French transposition law has not yet been enacted as of October 2, 2026.

Going further: the compliance lesson of the CIO path, a signed log is not an auditable log and the evidence matrix of the GenAI method.