Industry

NIS2 Article 21: The 10 Risk Management Measures Explained

Equip IgeraSolutions
September 27, 2026
9 min read
NIS2 Article 21: The 10 Risk Management Measures Explained
🎧 Listen with AI Voice

2-minute executive summary

⚡ Quick Answer in 30s

NIS2 Article 21 sets 10 minimum cybersecurity measures for manufacturers. Clear breakdown of each requirement and what it means on the factory floor.

✓ Citing current regulationsSee detailed guide below ↓

NIS2 Article 21: The 10 Risk Management Measures Explained

Article 21 of the NIS2 Directive is the operational heart of the regulation: it sets out ten minimum categories of cybersecurity risk management measures that essential and important entities must implement, following an "all-hazards approach." These are not a rigid checklist applied identically to everyone — they are baseline requirements that each organisation must scale to its own size, risk exposure and the cost of implementation. For a manufacturer, that means treating OT security, supply chain relationships with component suppliers, and factory-floor access control as core parts of compliance, not afterthoughts.

Note on regulatory status: NIS2 transposition, guidance and enforcement practice are still evolving across EU member states at the time of writing, and implementing acts and national laws can vary in detail and timing. This article explains the structure of Article 21 as set out in the Directive; it does not substitute for advice from a qualified compliance consultant or lawyer on how the rules apply to your specific entity and jurisdiction.

What Article 21 actually requires

Article 21 requires in-scope entities to take "appropriate and proportionate technical, operational and organisational measures" to manage the risks posed to the security of network and information systems, and to prevent or minimise the impact of incidents on recipients of their services and on other services. Proportionality is built into the text: the Directive explicitly says these measures must account for the entity's degree of exposure to risk, its size, the likelihood of incidents, their severity (including societal and economic impact), and the state of the art and cost of implementation. In practice, this means a 40-person precision parts manufacturer and a multinational automotive supplier will both need to address all ten areas below, but the depth, tooling and budget behind each one will differ substantially.

For manufacturing and industrial companies specifically, two themes cut across almost all ten measures: the convergence of IT and OT (operational technology — the systems that run production lines, SCADA, PLCs and industrial control systems) and the security of a often long and opaque supply chain of component and equipment suppliers. Both are called out explicitly below where relevant.

The 10 minimum measures

1. Risk analysis and information system security policies

A documented process for identifying, assessing and treating risk, plus formal security policies that govern how systems are configured, used and maintained.

Manufacturing note: risk analysis must cover OT/ICS environments alongside corporate IT — a compromised PLC or SCADA system can halt production or create physical safety risks in ways a typical office-IT breach cannot.

2. Incident handling

Defined processes for detecting, managing, and responding to security incidents, including internal escalation and the reporting obligations NIS2 introduces.

Manufacturing note: incident handling plans should distinguish between an IT-side breach (data, email, ERP) and an OT-side event (a line stoppage or safety-system anomaly), since containment and escalation paths often differ.

3. Business continuity and crisis management

Backup management, disaster recovery, and crisis management procedures that keep the organisation functioning — or recover it quickly — during and after a major incident.

Manufacturing note: continuity planning has to include production continuity, not just data and IT recovery — a ransomware event that locks operator terminals on the line has direct output and revenue consequences.

4. Supply chain security

Security aspects of relationships with direct suppliers and service providers, including assessing their cybersecurity practices where relevant to the risk they pose.

Manufacturing note: this measure matters acutely for industrial companies. Component suppliers, contract manufacturers, and machinery vendors with remote-access maintenance links are frequent entry points for attackers, and a compromise anywhere upstream can propagate into your production environment.

5. Security in system acquisition, development and maintenance

Secure practices when acquiring, developing or maintaining network and information systems, including vulnerability handling and disclosure processes.

Manufacturing note: covers both new IT projects and the procurement of industrial equipment and control systems — vulnerability handling should extend to legacy OT assets that cannot always be patched on the same cadence as IT systems.

6. Policies to assess the effectiveness of risk management measures

Ongoing evaluation of whether the measures actually work — audits, testing, and review cycles rather than a one-off implementation.

Manufacturing note: effectiveness reviews should include OT-specific testing (e.g. tabletop exercises simulating a line disruption), not only standard IT penetration testing.

7. Basic cyber hygiene and cybersecurity training

Fundamental practices such as patching, secure configuration and password hygiene, paired with regular staff training and awareness.

Manufacturing note: training needs to reach shop-floor operators and maintenance staff, not just office employees — they are often the first to notice an anomaly on OT systems and the first target of phishing aimed at gaining network access.

8. Cryptography and encryption policies

Policies governing when and how encryption is used to protect data in transit and at rest.

Manufacturing note: proportionality matters here — some legacy OT protocols were never designed with encryption in mind, so compensating controls (network segmentation, monitoring) may be the practical answer where retrofitting encryption isn't feasible.

9. Human resources security, access control and asset management

Policies covering personnel security, controlling who can access which systems, and maintaining an accurate inventory of assets.

Manufacturing note: asset management is a real challenge on the factory floor, where OT devices, sensors and legacy controllers are often undocumented or managed outside the IT department's usual inventory processes.

10. Multi-factor authentication and secured communications

Use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems within the entity, where appropriate.

Manufacturing note: MFA should extend to remote-access accounts used by equipment vendors and maintenance contractors connecting into OT networks — a common and often under-secured entry point.

Practical impact: what this changes day to day

For most manufacturers, the biggest practical shift is that cybersecurity stops being purely an IT department concern and becomes a management-level responsibility with documentation requirements. Article 21 expects policies to exist in writing, to be reviewed for effectiveness, and to be understood by the people who operate the systems they cover — which for an industrial company includes production and maintenance teams, not only IT staff. Supply chain due diligence also becomes an ongoing exercise rather than a one-time vendor questionnaire, since component suppliers and machinery vendors are named explicitly as an area of focus.

One of the recurring practical difficulties is proving compliance quickly when it's needed — during an audit, a customer security questionnaire, or an insurance renewal. Compliance evidence tends to be scattered across policy documents, risk registers, training records and supplier contracts. This is where a tool like IgeraIndustria is useful in practice: it lets manufacturing companies query their own compliance and quality documents directly and get an answer that cites the exact source document and clause, rather than someone manually searching through folders of PDFs to find where a given control is documented.

Common mistakes

  • Treating the ten measures as a fixed checklist rather than a proportionate framework — Article 21 explicitly ties the required depth of each measure to the entity's size, risk profile and the cost of implementation.
  • Scoping risk analysis and asset inventories to IT only, leaving OT and industrial control systems undocumented and therefore unmanaged from a security standpoint.
  • Assuming supply chain security means a one-off supplier audit, when it is meant to be an ongoing assessment of the risk that direct suppliers and service providers pose.
  • Writing policies but never testing them — measure 6 exists precisely because policies that are never exercised or reviewed tend not to hold up during a real incident.
  • Leaving shop-floor and maintenance staff out of training, even though they interact daily with the OT systems that carry some of the highest operational risk.

Frequently asked questions

Do all ten measures in Article 21 apply to every entity in the same way?

No. The Directive requires a proportionate approach: the depth and cost of each measure should reflect the entity's size, risk exposure, and the likely severity of an incident. All ten categories must be addressed, but not necessarily to the same standard by every organisation.

Does Article 21 apply specifically to OT and industrial control systems, or just corporate IT?

The Directive refers broadly to "network and information systems," and for a manufacturer this reasonably includes OT and ICS environments where they support the entity's operations. Exactly how national transposition and guidance treat OT scope can vary, so this is a point worth confirming with a qualified adviser for your specific situation.

Is multi-factor authentication mandatory under measure 10?

Article 21 requires the use of MFA or continuous authentication solutions "where appropriate," alongside secured communications. As with the other measures, appropriateness is assessed against the entity's risk and circumstances rather than applied as an absolute, unconditional rule.

How does supply chain security under Article 21 affect relationships with component suppliers?

Entities are expected to consider the cybersecurity practices of their direct suppliers and service providers as part of managing their own risk. For manufacturers, this typically means assessing component suppliers, contract manufacturers and equipment vendors that have access to or influence over production systems.

What happens if an entity doesn't implement all ten measures?

Non-compliance consequences and enforcement mechanisms are set out in national implementing legislation, which varies by member state and is still being finalised or refined in several jurisdictions. For a definitive answer on the consequences in your country, consult a qualified compliance consultant or lawyer.

Can a smaller manufacturer implement a lighter version of these measures?

The proportionality principle in Article 21 is designed for exactly this — smaller entities with lower risk exposure are expected to implement measures that are reasonable for their size and resources, rather than mirroring the controls of a large multinational.

How can a company show it has actually implemented these measures during an audit?

Documentation is central: written policies, risk assessments, training records, incident logs and supplier assessments that can be produced and cited on request. Tools that let compliance and quality documents be searched and cited quickly, such as IgeraIndustria, can make this process considerably faster than manual document retrieval.

Disclaimer: This article is provided for general informational purposes only and does not constitute legal or certification advice. NIS2 transposition and enforcement details vary by EU member state and continue to evolve. For guidance specific to your organisation's obligations, scope and risk, consult a qualified compliance consultant or lawyer.

#NIS2 Article 21#NIS2 risk management measures#NIS2 compliance manufacturing#OT cybersecurity NIS2#NIS2 supply chain security#cyber hygiene NIS2#multi-factor authentication NIS2#IgeraIndustria compliance

Ask this article

IA 2026

Igera's AI answers questions citing the facts and regulations in this article

2 of 2 free queries

Suggested questions (click to test):

Diagnóstico Interactivo 60s

Technical Compliance & Industrial Operations Diagnostic

Analyze speed of access to regulations (CTE, OSH, CE) in your plant or jobsite

Pregunta 1 de 3

How do technicians and operators access safety protocols and manuals?

Was this article helpful?

🛡️IgeraRegTech2026 Diagnostic Matrix
GUÍA DESCARGABLE (TXT)

NIS2 & DORA 2026 Statutory Compliance Gap Assessment Matrix

Diagnostic tool for DPOs and CISOs: essential vs important entity classifier, 10 mandatory risk management measures under NIS2 Art. 21, and DORA ICT third-party rules.

  • Automatic entity classification based on revenue and sector thresholds
  • Real-time compliance scoring with automated remediation action roadmap
  • Mandatory 24h/72h cybersecurity incident alert templates for authorities

Instant download · No card · 100% spam-free

Share this article

Help spread knowledge by sharing this content with your network