which ten measures must I take according to NIS2
Ten measures together form the duty of care
The ten measures from Article 21(2) of the NIS2 Directive together form the minimum package with which an organisation fulfils the duty of care. These are: policies for risk analysis and security of information systems, incident handling, business continuity and crisis management (think of backup management and recovery from a disaster), supply chain security, security in the acquisition, development and maintenance of network and information systems (including vulnerability policy), policy and procedures to assess the effectiveness of measures, basic cyber hygiene and training, cryptography and encryption policy, personnel security and access control policy, and the use of multi-factor authentication or comparable solutions. This enumeration appears exactly as stated in the Directive and is reflected in the national transposition thereof.
In the Netherlands this is the Cybersecurity Act, which adopts the same ten points as an obligation for essential and important entities. For those who encounter these requirements through a customer without being subject to the obligation themselves, it is useful to know that precisely the point on supply chain security is the reason why the own security of suppliers is assessed. The ten measures are not a checklist to be ticked off once: they are worked out in practice into policies, procedures and evidence, and it is that elaboration where most of the time is spent — see also what that means in time and effort.
Where this appears in the Directive and the standards
Article 21(1) of the NIS2 Directive gives the ten points as minimum requirements, and Article 21(1) links to that the measures must be "appropriate and proportionate" — based on a risk assessment, not on a fixed standard for everyone. The Cybersecurity Act translates this obligation into the Dutch context, and the explanation from the NCSC describes how this duty of care is implemented in practice. Many of the ten points substantively overlap with the control measures in Annex A of ISO/IEC 27001, which explains why organisations with an existing ISO certificate often already have part of the foundation in place — although that in itself is no guarantee that all ten points are fully covered.
What this is based on
- Directive (EU) 2022/2555 (NIS2), Article 21(2) — the ten measures
- Cybersecurity Act — the Dutch transposition of NIS2
- ISO/IEC 27001 — Annex A, the control measures
- NCSC — guidance on the security obligation and the reporting obligation
The Regulation itself is available on EUR-Lex. We provide references for each statement; you need not take our word for it.
What you concretely need to do
The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.
View the subscription First the free NIS2 checkThis is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.
Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.