NIS2 Article 21: Which Technical Measures Need Network Testing?
Reviewed: 24 August 2026 — reviewed quarterly
Quick Answer
NIS2 Article 21(2) sets out ten categories of risk-management measures. Several are naturally technical and network/infrastructure-related — network and information systems security (2)(e), cryptography (2)(h), and access control/MFA (2)(i)/(2)(j) — and are commonly evidenced through external network and cloud configuration testing. Article 21(2)(f) separately requires you to demonstrate the effectiveness of your measures, which is where independent testing becomes the practical evidence most entities rely on. NIS2 is a Directive, not a Regulation — specifics vary by EU member state's transposing law.
What Does Article 21 Ask For, in Plain Terms?
Directive (EU) 2022/2555 sets out ten minimum categories of risk-management measures in Article 21(2) — spanning governance, incident handling, business continuity, supply-chain security, network and system security, cryptography, human resources, and access control. Not all ten are equally "technical": some are primarily organisational (policies, training, governance), while others are squarely about how your network, systems, and infrastructure are actually configured and defended.
For a full breakdown of all ten measures and the Article 21(2)(f) effectiveness-assessment clause specifically, see our NIS2 and Penetration Testing page. This page focuses narrowly on the subset of measures that are specifically about your network and infrastructure.
Article 21(2) Measures Most Relevant to Network/Infrastructure Testing
A selection of Article 21(2) sub-clauses, not the full list of ten — see the NIS2 and Penetration Testing page for all ten.
| Clause | Measure | Nature | Where our service fits |
|---|---|---|---|
| Art. 21(2)(b) | Incident handling | Largely organisational (process + tooling) | Not directly — see Compliance-as-a-Service |
| Art. 21(2)(e) | Security in network and information systems acquisition, development, and maintenance | Technical — includes network/infrastructure security | External network and cloud configuration testing |
| Art. 21(2)(f) | Policies and procedures to assess the effectiveness of risk-management measures | Outcome requirement — testing is one practical method | Penetration testing (any tier) or Vulnerability/Infrastructure assessment |
| Art. 21(2)(h) | Cryptography and encryption | Technical | Covered as part of cloud configuration review (encryption settings) |
| Art. 21(2)(i) | Human resources security, access control, asset management | Largely organisational, with technical access-control components | IAM misconfiguration review (cloud configuration review) |
| Art. 21(2)(j) | Use of multi-factor authentication, secured communications | Technical | IAM/MFA misconfiguration review (cloud configuration review) |
NIS2 Is a Directive, Not a Regulation
Unlike GDPR, NIS2 takes legal effect through each EU member state's own transposing legislation, and specifics — including exactly which technical measures are expected and how rigorously they're enforced — vary by jurisdiction. Nothing on this page should be read as a definitive legal statement of what your specific national law requires; check your relevant member state's implementing legislation or national NIS2 competent authority for the current, binding requirement.
For the network/infrastructure-specific measures, our €899 External Infrastructure & Cloud Security Assessment is scoped to this evidence. For the full range of NIS2 compliance services covering the other measures, see our NIS2 Directive hub.
See Infrastructure & Cloud Assessment