Skip to main content
NIS2Directive (EU) 2022/2555

Article 21: Cybersecurity risk-management measures

NIS2 Art. 21, Chapter IV

1. Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services

648 words in the official text.

Sits inside (1)

Recitals matched by wording (15)

These recitals name no article. The dataset matched them to this one by text similarity, and they are marked so nobody reads a match as a citation.

Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.

NIS2 32022L2555

Every connection on this page is drawn from the official text of Directive (EU) 2022/2555. Study aid, not legal advice.

See how NIS2 sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.