The duty of care: the ten measures from article 21
What is concretely expected of you, per measure — and how you can demonstrate it is arranged.
Ten topics, not a technical checklist
The directive does not prescribe products or institutions. It names ten topics on which you must take appropriate and proportionate measures, and leaves the implementation to you. Appropriate and proportionate means: in proportion to your risk, your size and the state of the art. A hospital with three thousand people does something different from a software company with sixty.
This makes it more difficult than a checklist, but also fairer. And it explains why there is no certificate: there is no standard to sign off against.
Where most organisations get stuck
Not on the technology. Almost everyone has backups, updates and password policies. Where it goes wrong is demonstrating it: it is not documented anywhere, there is no owner, and no one can show when it was last tested.
The duty of care requires not only that you do it, but that you can demonstrate it. That is also precisely what a customer wants to see in his checklist, and what a regulator requests first.
Starting without a year-long project
Start with what you already have. For each of the ten topics: is it arranged, partially, not, or not applicable, and who is responsible. That alone provides a picture you can show a customer, and makes clear which two or three things really need attention.
What you should not do is start with a zero baseline measurement costing tens of thousands of euros. Do the inventory yourself first, then you will know what advice you need.
Frequently asked questions
Does a NIS2 certificate exist?
No. There is no body that certifies that you comply with NIS2, and anyone offering that is selling something that does not exist. What is possible is to demonstrably document what you have arranged, with date and supporting evidence.
Does ISO 27001 help with this?
Considerably, because many of the ten topics are in it. But it is not the same and not a replacement: NIS2 has a notification obligation and a registration obligation that do not appear in the standard.
How often must I update this?
The directive names no timeframe but does ask that you assess effectiveness. Once a year and after each significant incident is a defensible approach.
This is explanation, not advice about your own situation. secria.eu does not assess your organization and does not provide assurance.