🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Resource · NIS2 Directive

NIS2 Article 21: Which Technical Measures Need Network Testing?

Reviewed: 24 August 2026 — reviewed quarterly

Quick Answer

NIS2 Article 21(2) sets out ten categories of risk-management measures. Several are naturally technical and network/infrastructure-related — network and information systems security (2)(e), cryptography (2)(h), and access control/MFA (2)(i)/(2)(j) — and are commonly evidenced through external network and cloud configuration testing. Article 21(2)(f) separately requires you to demonstrate the effectiveness of your measures, which is where independent testing becomes the practical evidence most entities rely on. NIS2 is a Directive, not a Regulation — specifics vary by EU member state's transposing law.

What Does Article 21 Ask For, in Plain Terms?

Directive (EU) 2022/2555 sets out ten minimum categories of risk-management measures in Article 21(2) — spanning governance, incident handling, business continuity, supply-chain security, network and system security, cryptography, human resources, and access control. Not all ten are equally "technical": some are primarily organisational (policies, training, governance), while others are squarely about how your network, systems, and infrastructure are actually configured and defended.

For a full breakdown of all ten measures and the Article 21(2)(f) effectiveness-assessment clause specifically, see our NIS2 and Penetration Testing page. This page focuses narrowly on the subset of measures that are specifically about your network and infrastructure.

Article 21(2) Measures Most Relevant to Network/Infrastructure Testing

A selection of Article 21(2) sub-clauses, not the full list of ten — see the NIS2 and Penetration Testing page for all ten.

ClauseMeasureNatureWhere our service fits
Art. 21(2)(b)Incident handlingLargely organisational (process + tooling)Not directly — see Compliance-as-a-Service
Art. 21(2)(e)Security in network and information systems acquisition, development, and maintenanceTechnical — includes network/infrastructure securityExternal network and cloud configuration testing
Art. 21(2)(f)Policies and procedures to assess the effectiveness of risk-management measuresOutcome requirement — testing is one practical methodPenetration testing (any tier) or Vulnerability/Infrastructure assessment
Art. 21(2)(h)Cryptography and encryptionTechnicalCovered as part of cloud configuration review (encryption settings)
Art. 21(2)(i)Human resources security, access control, asset managementLargely organisational, with technical access-control componentsIAM misconfiguration review (cloud configuration review)
Art. 21(2)(j)Use of multi-factor authentication, secured communicationsTechnicalIAM/MFA misconfiguration review (cloud configuration review)

NIS2 Is a Directive, Not a Regulation

Unlike GDPR, NIS2 takes legal effect through each EU member state's own transposing legislation, and specifics — including exactly which technical measures are expected and how rigorously they're enforced — vary by jurisdiction. Nothing on this page should be read as a definitive legal statement of what your specific national law requires; check your relevant member state's implementing legislation or national NIS2 competent authority for the current, binding requirement.

For the network/infrastructure-specific measures, our €899 External Infrastructure & Cloud Security Assessment is scoped to this evidence. For the full range of NIS2 compliance services covering the other measures, see our NIS2 Directive hub.

See Infrastructure & Cloud Assessment

Frequently Asked Questions

Does NIS2 Article 21 require external network and cloud testing specifically?+
The Directive doesn't name "external network penetration test" or "cloud configuration review" as standalone mandatory line items. Article 21(2) sets out ten categories of risk-management measures, several of which — network/infrastructure security (2)(e), cryptography (2)(h), access control and MFA (2)(i)/(2)(j) — are naturally technical and commonly evidenced through exactly this kind of external assessment. Article 21(2)(f) separately requires you to be able to demonstrate the effectiveness of whatever measures you've put in place, which is where independent testing becomes the practical evidence most in-scope entities rely on.
How is this different from your NIS2 and Penetration Testing page?+
That page (at /compliance/sector-specific/nis2/penetration-testing/) focuses on Article 21(2)(f) — the effectiveness-assessment clause — and explains why NIS2 never literally mandates "penetration testing" as a named method. This page focuses on which of the ten Article 21(2) measures are specifically about your network and infrastructure, and how our External Infrastructure & Cloud Security Assessment maps to those measures in particular.
Is my organisation in scope for NIS2 at all?+
It depends on your sector and size, set out in NIS2 Annexes I and II, and on how your specific EU member state has transposed the Directive into national law. We don't publish a definitive applicability checker here — check your national NIS2 competent authority or your compliance advisor for a scope determination specific to your situation.
Does external network/cloud testing alone make us NIS2 compliant?+
No. Article 21 requires a defined set of measures spanning governance, incident handling, business continuity, supply-chain security, and more — external network/cloud testing addresses a subset of the technical measures, not the whole Article. See our full range of NIS2 compliance services for the other measures.
Which NIS2 services do you offer beyond testing?+
Our sector-specific NIS2 category includes applicability assessment, incident response planning, access management, risk assessment, and other Article 21 measures beyond network/infrastructure testing — see the NIS2 Directive hub for the full list.