The Licence is live: See what it includes

Guides · Regulation · 9 min read

What NIS2 Article 21 actually asks of a 50-person company

The ten cybersecurity risk-management measures of NIS2 Article 21(2), what each one means for a company of 50 to 250 people with no risk officer, the 24/72-hour reporting clock, and what management is personally on the hook for.

Published 10 September 2026

If you run a company of 50 to 250 people in transport, logistics, waste, food production and distribution, manufacturing, digital infrastructure, IT services, energy, water, health or public administration, NIS2 almost certainly applies to you. Not to your IT provider. To you, as the entity, and to your management body by name.

Most directors first hear about it in a letter, a client questionnaire or an insurance renewal, and the reaction is reasonable: this reads like it was written for a company with a Chief Information Security Officer. It was not. Article 21(1) requires measures that are "appropriate and proportionate" to your size, your exposure and the cost of implementation. That proportionality clause is the whole game, and almost nobody uses it, because using it requires being able to show your reasoning.

Are you in scope, and as what

NIS2 splits covered organisations into two classes, and the class changes the supervision you get, not the measures you owe.

Scope, in the terms the directive uses
ClassRoughly whoSupervisionMaximum fine
Essential entity250+ staff, or turnover above €50m, in an Annex I sectorProactive: the regulator may audit you unprompted€10m or 2% of worldwide turnover, whichever is higher
Important entity50+ staff, or turnover above €10m, in an Annex I or II sectorReactive: the regulator acts on evidence of non-compliance€7m or 1.4% of worldwide turnover, whichever is higher

A 50-to-250-person company in a covered sector is, in almost every case, an important entity. Practically, that means nobody is coming to inspect you next quarter — and that when something does happen, or a client, insurer or acquirer asks, you are expected to produce documented measures that already existed.

The ten measures of Article 21(2), and what each one is really asking

Article 21(2) lists ten minimum measures. Read literally they sound enormous. Read as questions, each one has a version a 60-person company can honestly satisfy in an afternoon or two.

  1. aRisk analysis and information system security policies. Asking: is there a written document naming what could stop you, who owns each risk, and when it was last reviewed? Two pages, dated, signed by you, beats forty pages from 2019.
  2. bIncident handling. Asking: does someone know, in advance, who declares an incident, who is called, in what order, and who speaks to clients? If the answer lives in one person's head, you do not have this.
  3. cBusiness continuity — including backup management, disaster recovery and crisis management. Asking: if your main system dies tonight, how do you keep invoicing? When was a restore last actually tested? An untested backup is not a backup, and this is the single measure most often failed on evidence rather than intent.
  4. dSupply chain security, including the security of your direct suppliers and service providers. Asking: which suppliers could stop your operation, and what have you asked them in writing? Single-source dependencies are the most common structural failure we see in scoring, and they are rarely IT suppliers.
  5. eSecurity in acquisition, development and maintenance, including vulnerability handling. Asking: are systems patched on a schedule somebody owns, and is there a route for someone to report a flaw to you?
  6. fPolicies to assess the effectiveness of the measures. Asking: how do you know any of this works? This is the clause that turns a plan into a rhythm — a rehearsal, a test restore, a review date.
  7. gBasic cyber hygiene and cybersecurity training. Asking: has everyone been told, this year, how to recognise a payment-fraud email? Attendance list, date, done.
  8. hCryptography and, where appropriate, encryption. Asking: are laptops and backups encrypted, and can you say so in one sentence?
  9. iHuman resources security, access control and asset management. Asking: when someone leaves on a Friday, are their accounts closed by Monday? Do you have a list of who can access what?
  10. jMulti-factor authentication, secured communications and secured emergency communications. Asking: is MFA on email, banking and remote access — and if your email is the thing that is down, how does the crisis team talk to each other?

The reporting clock: 24 hours, 72 hours, one month

Article 23 is the part that surprises people, because it runs on a stopwatch. For a significant incident, you owe your national CSIRT or competent authority:

  • An early warning within 24 hours of becoming aware of it — a few lines, including whether you suspect an unlawful or malicious act and whether it may have cross-border impact.
  • An incident notification within 72 hours, with an initial assessment, severity, impact and any indicators of compromise.
  • A final report within one month: a detailed description, the type of threat or root cause, the mitigation applied, and any cross-border effect.
  • An intermediate status update whenever the authority asks for one.

Twenty-four hours sounds generous until you picture the actual morning: systems are down, your IT provider is diagnosing, a client has already called, and nobody in the room knows which authority to write to or who is allowed to sign the message. The reporting obligation is not hard. It is hard *at hour three of a crisis*, which is why it belongs in a written playbook and not in a policy binder.

What management is personally on the hook for

Article 20 is short and pointed. Management bodies must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements. They are also required to follow training themselves, and to offer similar training to staff. There is no version of NIS2 where this is delegated to the IT provider and forgotten: the directive puts the signature at the top.

For a director, that reframes the whole exercise. The question is not "are we compliant?" — a binary nobody can honestly answer. It is "if I am asked, can I show what we decided, when, and what we tested?"

A proportionate first pass, in the order we would do it

  1. 01Write down, on one page, the four things that would stop you operating for a week: name each one, name who owns it. That is measure (a), honestly done.
  2. 02Test one restore. Pick your most important system, restore yesterday's backup to somewhere harmless, note how long it took and what failed. Date it. That is measure (c) with evidence, and it is the single highest-value hour available to you.
  3. 03Write the call list. Who declares an incident, who calls the IT provider, who calls the insurer, who talks to clients, who reports to the authority — with mobile numbers, on paper, off the network. That is (b) and half of (j).
  4. 04Turn on MFA for email, banking and remote access this week. Nothing else on this list moves the risk as much per hour spent.
  5. 05List your suppliers you cannot replace inside a month and send each of them one written question about their own continuity. Keep the replies. That is (d).
  6. 06Put a date in the calendar, six months out, to rehearse the call list against a scenario and review the page from step 01. That is (f), which is the clause that keeps the other nine alive.

None of that requires a consulting project, and all of it is the sort of thing that only ever happens if somebody sets a number against it and watches the number.

Your reading

Fifteen questions. A score out of 100, and the three exposures costing you the most points.

Six of the fifteen Diagnostic questions map directly to Article 21(2). The score tells you which of the ten measures you cannot currently evidence.

Take the free Diagnostic10 minutes · no account · no card

Also worth reading