The 10 NIS2 Risk-Management Measures Under Article 21 — A Practical Checklist for Poland

Published: · AIPOS OÜ · nis2europe.eu

What Article 21 actually requires

If your company falls under the Polish cybersecurity regime, the heart of your compliance obligation is a set of risk-management measures. These come from Article 21 of Directive (EU) 2022/2555 (NIS2) and are transposed into Polish law through the Ustawa o krajowym systemie cyberbezpieczeństwa (uKSC) (Dz.U. 2026 poz. 252).

Article 21(1) sets the standard. Essential and important entities must take *"appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems"* they use — and to prevent or minimise the impact of incidents on the recipients of their services.

Two words matter here: appropriate and proportionate. The directive says you must take into account:

In other words, a mid-sized manufacturer is not expected to build the same defences as a national telecom operator — but both must genuinely manage their risks. Article 21(2) then makes this concrete by listing ten minimum measures, based on an *all-hazards approach* covering both digital systems and their physical environment.

The 10 measures — your Article 21(2) checklist

Here is the full list from Article 21(2), points (a)–(j), presented as a practical checklist. These are the *minimum* — your risk assessment may require more.

#PointMeasure
1(a)Policies on risk analysis and information system security
2(b)Incident handling
3(c)Business continuity, such as backup management and disaster recovery, and crisis management
4(d)Supply chain security, including security aspects of relationships with direct suppliers or service providers
5(e)Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure
6(f)Policies and procedures to assess the effectiveness of cybersecurity risk-management measures
7(g)Basic cyber hygiene practices and cybersecurity training
8(h)Policies and procedures on the use of cryptography and, where appropriate, encryption
9(i)Human resources security, access control policies and asset management
10(j)Use of multi-factor authentication or continuous authentication, secured voice/video/text communications and secured emergency communication systems, where appropriate

How to read this checklist: Points (a) and (f) form a management loop — you analyse risks, act, then measure whether your actions work. Points (b) and (c) prepare you for when something goes wrong. Points (d) and (e) push security outward into your suppliers and your software lifecycle. Points (g), (h), (i) and (j) are the everyday controls — training, encryption, access control, and multi-factor authentication — that stop the majority of common attacks.

Article 21(2) point (e) explicitly includes vulnerability handling and disclosure, and point (d) explicitly names the relationship between each entity and its direct suppliers. These two are often the weakest links, so treat them seriously rather than as box-ticking.

How Polish law transposes these obligations

The Polish transposition sits in the uKSC (Dz.U. 2026 poz. 252). The law distinguishes two categories of regulated organisation, and you should confirm which one applies to you before building your programme:

Governance is a board-level duty. Under Article 20(1) of the directive, management bodies must *approve* the risk-management measures, *oversee* their implementation, and *can be held liable* for infringements of Article 21. This means the ten measures are not just an IT project — leadership carries the responsibility.

Fixing gaps is mandatory. Under Article 21(4), an entity that finds it does not comply with the measures must take, *without undue delay*, all necessary, appropriate and proportionate corrective measures. Finding a gap is not a violation in itself — ignoring it is.

The precise national provision restating the Article 21 measures and the sector-specific supervisory arrangements under the Polish multi-authority model are [TÄPSUSTAB PARTNER-JURIST].

Why getting this right matters: reporting and penalties

The ten measures do not exist in isolation. If a major incident (incydent poważny) occurs — defined in uKSC art. 2 pkt 7 as an incident that causes or may cause serious degradation or interruption of a service, financial loss, or serious material or non-material harm to others — your incident-handling measure under point (b) must feed directly into strict reporting deadlines to the relevant sectoral CSIRT:

Penalties for failing to manage risk are significant:

Starting with the ten-point checklist above is the most efficient way to build a defensible programme. Use our free scoping and gap tool to map each Article 21(2) measure against what your organisation already has in place — and to see where your priorities lie.

Frequently asked questions

Where do the 10 NIS2 risk-management measures come from?

They are set out in Article 21(2), points (a) to (j), of Directive (EU) 2022/2555 (NIS2), which is transposed into Polish law through the Ustawa o krajowym systemie cyberbezpieczeństwa (uKSC), Dz.U. 2026 poz. 252. The list is the legal minimum, based on an all-hazards approach.

Do all ten measures apply to every organisation equally?

The ten measures are a minimum for both essential and important entities, but Article 21(1) requires them to be appropriate and proportionate. Proportionality takes account of your exposure to risk, your size, and the likelihood and severity of incidents, so implementation depth can differ.

What is the difference between podmiot kluczowy and podmiot ważny?

Podmiot kluczowy (essential entity) is defined in uKSC art. 5 ust. 1 and podmiot ważny (important entity) in uKSC art. 5 ust. 2. The categories differ in criteria such as sector, size and type of service, and they carry different maximum penalties under uKSC art. 73 ust. 3 and ust. 4.

What happens if we discover we do not comply with a measure?

Under Article 21(4) of the directive, an entity that finds it does not comply with the Article 21(2) measures must take all necessary, appropriate and proportionate corrective measures without undue delay. Identifying a gap and fixing it promptly is exactly what the law expects.

Check your NIS2 compliance

Run the free gap analysis

Start the free scoping test Run the free surface scan

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home