NIS2 Article 21: The 10 Risk Management Measures Explained
Article 21 of the NIS2 Directive is the operational heart of the regulation: it sets out ten minimum categories of cybersecurity risk management measures that essential and important entities must implement, following an "all-hazards approach." These are not a rigid checklist applied identically to everyone — they are baseline requirements that each organisation must scale to its own size, risk exposure and the cost of implementation. For a manufacturer, that means treating OT security, supply chain relationships with component suppliers, and factory-floor access control as core parts of compliance, not afterthoughts.
Note on regulatory status: NIS2 transposition, guidance and enforcement practice are still evolving across EU member states at the time of writing, and implementing acts and national laws can vary in detail and timing. This article explains the structure of Article 21 as set out in the Directive; it does not substitute for advice from a qualified compliance consultant or lawyer on how the rules apply to your specific entity and jurisdiction.
What Article 21 actually requires
Article 21 requires in-scope entities to take "appropriate and proportionate technical, operational and organisational measures" to manage the risks posed to the security of network and information systems, and to prevent or minimise the impact of incidents on recipients of their services and on other services. Proportionality is built into the text: the Directive explicitly says these measures must account for the entity's degree of exposure to risk, its size, the likelihood of incidents, their severity (including societal and economic impact), and the state of the art and cost of implementation. In practice, this means a 40-person precision parts manufacturer and a multinational automotive supplier will both need to address all ten areas below, but the depth, tooling and budget behind each one will differ substantially.
For manufacturing and industrial companies specifically, two themes cut across almost all ten measures: the convergence of IT and OT (operational technology — the systems that run production lines, SCADA, PLCs and industrial control systems) and the security of a often long and opaque supply chain of component and equipment suppliers. Both are called out explicitly below where relevant.
The 10 minimum measures
1. Risk analysis and information system security policies
A documented process for identifying, assessing and treating risk, plus formal security policies that govern how systems are configured, used and maintained.
Manufacturing note: risk analysis must cover OT/ICS environments alongside corporate IT — a compromised PLC or SCADA system can halt production or create physical safety risks in ways a typical office-IT breach cannot.
2. Incident handling
Defined processes for detecting, managing, and responding to security incidents, including internal escalation and the reporting obligations NIS2 introduces.
Manufacturing note: incident handling plans should distinguish between an IT-side breach (data, email, ERP) and an OT-side event (a line stoppage or safety-system anomaly), since containment and escalation paths often differ.
3. Business continuity and crisis management
Backup management, disaster recovery, and crisis management procedures that keep the organisation functioning — or recover it quickly — during and after a major incident.
Manufacturing note: continuity planning has to include production continuity, not just data and IT recovery — a ransomware event that locks operator terminals on the line has direct output and revenue consequences.
4. Supply chain security
Security aspects of relationships with direct suppliers and service providers, including assessing their cybersecurity practices where relevant to the risk they pose.
Manufacturing note: this measure matters acutely for industrial companies. Component suppliers, contract manufacturers, and machinery vendors with remote-access maintenance links are frequent entry points for attackers, and a compromise anywhere upstream can propagate into your production environment.
5. Security in system acquisition, development and maintenance
Secure practices when acquiring, developing or maintaining network and information systems, including vulnerability handling and disclosure processes.
Manufacturing note: covers both new IT projects and the procurement of industrial equipment and control systems — vulnerability handling should extend to legacy OT assets that cannot always be patched on the same cadence as IT systems.
6. Policies to assess the effectiveness of risk management measures
Ongoing evaluation of whether the measures actually work — audits, testing, and review cycles rather than a one-off implementation.
Manufacturing note: effectiveness reviews should include OT-specific testing (e.g. tabletop exercises simulating a line disruption), not only standard IT penetration testing.
7. Basic cyber hygiene and cybersecurity training
Fundamental practices such as patching, secure configuration and password hygiene, paired with regular staff training and awareness.
Manufacturing note: training needs to reach shop-floor operators and maintenance staff, not just office employees — they are often the first to notice an anomaly on OT systems and the first target of phishing aimed at gaining network access.
8. Cryptography and encryption policies
Policies governing when and how encryption is used to protect data in transit and at rest.
Manufacturing note: proportionality matters here — some legacy OT protocols were never designed with encryption in mind, so compensating controls (network segmentation, monitoring) may be the practical answer where retrofitting encryption isn't feasible.
9. Human resources security, access control and asset management
Policies covering personnel security, controlling who can access which systems, and maintaining an accurate inventory of assets.
Manufacturing note: asset management is a real challenge on the factory floor, where OT devices, sensors and legacy controllers are often undocumented or managed outside the IT department's usual inventory processes.
10. Multi-factor authentication and secured communications
Use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems within the entity, where appropriate.
Manufacturing note: MFA should extend to remote-access accounts used by equipment vendors and maintenance contractors connecting into OT networks — a common and often under-secured entry point.