Article 21: Cybersecurity risk-management measures
NIS2 Art. 21, Chapter IV
1. Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services
648 words in the official text.
Sits inside (1)
Cites (3)
Recitals matched by wording (15)
- Recital 44
- Recital 49
- Recital 59
- Recital 63
- Recital 77
- Recital 78
- Recital 79
- Recital 81
- Recital 82
- Recital 84
- Recital 85
- Recital 89
- Recital 90
- Recital 91
- Recital 93
These recitals name no article. The dataset matched them to this one by text similarity, and they are marked so nobody reads a match as a citation.
Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.
Every connection on this page is drawn from the official text of Directive (EU) 2022/2555. Study aid, not legal advice.
See how NIS2 sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.