The 10 NIS2 Cybersecurity Risk-Management Measures (Article 21) and How Italy Transposes Them
What Article 21 of the NIS2 Directive Requires
Article 21 of directive (EU) 2022/2555 is the heart of NIS2 compliance. Under art 21(1), essential and important entities must take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the network and information systems they use for their operations or services, and to prevent or minimise the impact of incidents.
The directive makes clear that these measures are not one-size-fits-all. When assessing proportionality, due account is taken of:
- the state of the art and, where applicable, relevant European and international standards;
- the cost of implementation;
- the entity's degree of exposure to risks;
- the entity's size;
- the likelihood and severity of incidents, including their societal and economic impact.
Crucially, art 21(2) requires an all-hazards approach that protects both the information systems and their physical environment. It then lists ten minimum elements (points (a) to (j)) that every in-scope organisation must cover. If an entity discovers it is not compliant, art 21(4) obliges it to take, without undue delay, all necessary, appropriate and proportionate corrective measures.
The 10 Measures: A Practical Checklist
Here is the full list from art 21(2) of the directive, presented as a working checklist for your organisation. These are the *minimum* elements — you may need more depending on your risk profile.
| # | Measure (Article 21(2)) | What it means in practice |
|---|---|---|
| a | Policies on risk analysis and information system security | A documented, maintained risk-assessment methodology and security policy. |
| b | Incident handling | Procedures and tooling to detect, respond to and report incidents. |
| c | Business continuity | Backup management, disaster recovery where applicable, and crisis management. |
| d | Supply chain security | Security aspects of relationships with direct suppliers and service providers. |
| e | Security in acquisition, development and maintenance | Secure procurement and development of systems, including vulnerability handling and disclosure. |
| f | Effectiveness assessment | Policies and procedures to assess whether your risk-management measures actually work. |
| g | Cyber hygiene and training | Basic cyber hygiene practices and cybersecurity training. |
| h | Cryptography and encryption | Policies and procedures on the use of cryptography and, where appropriate, encryption. |
| i | Human resources security | Personnel security, access control policies and asset management. |
| j | Authentication and secure communications | Multi-factor or continuous authentication, secured voice/video/text and emergency communications, where appropriate. |
Use this table as a gap-analysis starting point: for each row, ask whether you have a documented, implemented and tested control — and whether it is proportionate to your size and risk exposure.
How Italy Transposes Article 21: Article 24 of D.Lgs 138/2024
Italy transposes the risk-management obligations through art 24 of Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2). The Italian text mirrors the directive closely.
Under art 24, comma 1, soggetti essenziali and soggetti importanti must adopt misure tecniche, operative e organizzative adeguate e proporzionate to manage risks to their network and information systems and to prevent or minimise the impact of incidents. As in the directive, these measures must ensure a level of security appropriate to the risks — taking account of the state of the art and relevant national, European and international standards — and be proportionate to the entity's risk exposure, size, and the likelihood and severity of incidents.
Art 24, comma 2 lists the same ten minimum elements as the directive, based on a multi-rischio (all-hazards) approach:
- a) risk-analysis and information system security policies;
- b) incident management, including the notification procedures under art 25 and art 26;
- c) business continuity, including backup, disaster recovery and crisis management;
- d) supply chain security;
- e) security in acquisition, development and maintenance, including vulnerability handling and disclosure;
- f) procedures to assess the effectiveness of the measures;
- g) basic cyber hygiene and training;
- h) cryptography and, where appropriate, encryption;
- i) personnel security, access control and asset management;
- l) multi-factor or continuous authentication and secured communications, where appropriate.
Art 24, comma 3 adds specific detail on supply-chain security (point d): entities must consider the specific vulnerabilities of each direct supplier and the overall quality of their products and security practices, including secure development procedures, and take into account the results of coordinated supply-chain risk assessments carried out by the NIS Cooperation Group.
Finally, art 24, comma 4 transposes the corrective-action duty: where an entity finds it is not compliant with the measures in comma 2, it must adopt all appropriate and proportionate corrective measures without undue delay.
The exact methods and timelines for implementing these obligations are set according to articoli 30, 31 e 32, where the Autorità nazionale competente NIS applies proportionality and a graduated approach.
Management Accountability and the Cost of Getting It Wrong
NIS2 puts these measures firmly on the desk of senior leadership. Under art 23 of D.Lgs 138/2024, the administrative and management bodies of essential and important entities must:
- approve the way risk-management measures under art 24 are implemented;
- oversee implementation of the obligations;
- be held responsible for infringements of the decree.
In addition, under art 23, comma 2, these bodies must undergo cybersecurity training and promote equivalent, periodic training for their staff. This reflects art 20(1) of the directive on governance.
The stakes are significant. Under art 38 of D.Lgs 138/2024, failures to meet the risk-management obligations (art 24) or incident-notification obligations (art 25) — listed at comma 8 — are punishable (comma 9):
- for soggetti essenziali (excluding public administrations): administrative fines up to a maximum of €10,000,000 or 2% of total worldwide annual turnover for the previous financial year, whichever is higher;
- for soggetti importanti (excluding public administrations): up to a maximum of €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher.
Given this exposure, mapping your controls to the ten measures is not just a technical exercise — it is a board-level responsibility.
Where to Start: Scoping and Gap Analysis
Before you can implement the ten measures, you need to confirm two things: whether you are in scope and what your current gaps are.
Scope. Under art 3 and art 6 of D.Lgs 138/2024, in-scope organisations include entities in the highly critical (Allegato I) and critical (Allegato II) sectors that exceed the small-enterprise thresholds, together with specific categories that apply regardless of size (such as public electronic communications providers, trust service providers and DNS-related providers). Entities are classified as soggetti essenziali or soggetti importanti according to art 6.
Registration. Under art 7, in-scope entities register or update their registration on the digital platform made available by the Autorità nazionale competente NIS between 1 January and 28 February each year following the decree's entry into force. ACN (Agenzia per la Cybersicurezza Nazionale) draws up the list of essential and important entities by 31 March.
Gap analysis. Once you know your classification, run each of the ten measures in art 24, comma 2 against your existing controls. A structured self-assessment lets you prioritise investment where risk exposure is highest — exactly the proportionality logic the law expects.
Try our free NIS2 scoping and gap tool to check your likely classification and produce an initial checklist mapped to the ten Article 21 measures.
Frequently asked questions
How many cybersecurity risk-management measures does NIS2 require?
Article 21(2) of directive (EU) 2022/2555 lists ten minimum elements, points (a) to (j), ranging from risk-analysis policies and incident handling to supply chain security, cryptography and multi-factor authentication. In Italy these are transposed in art 24, comma 2 of D.Lgs 138/2024. They are a minimum baseline — entities may need additional measures based on their risk profile.
Which Italian law transposes Article 21 of the NIS2 Directive?
Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2) transposes the directive in Italy. The risk-management measures of Article 21 are set out in art 24, which lists the same ten minimum elements and requires appropriate and proportionate technical, operational and organisational measures based on an all-hazards (multi-rischio) approach.
Are company directors personally responsible for NIS2 measures?
Yes. Under art 23 of D.Lgs 138/2024, the administrative and management bodies of essential and important entities must approve the implementation of the art 24 measures, oversee implementation, and can be held responsible for infringements. They must also undergo cybersecurity training and promote it for staff.
What are the fines for failing to implement the NIS2 risk-management measures in Italy?
Under art 38, comma 9 of D.Lgs 138/2024, failures relating to art 24 (risk management) or art 25 (incident notification) can be fined up to €10,000,000 or 2% of total worldwide annual turnover for soggetti essenziali, and up to €7,000,000 or 1.4% of turnover for soggetti importanti (both excluding public administrations), whichever amount is higher.
Check your NIS2 compliance
This article is general information, not legal advice. A partner lawyer confirms your specific situation.