Evidence should prove both design and operation. For example, a policy alone may show intent, but Article 21 evidence should also show risk treatment, role assignment, testing, supplier review, asset classification, training, and remediation where those items are relevant to the entity's services.
For its named provider types, the implementing regulation requires detail such as management-body approval, topic-specific policies, risk treatment plans, event monitoring, supplier policies and contract clauses, security testing, patch management, access policy, asset inventory, and assigned cybersecurity roles. It also requires at least annual review of the security policy, risk assessment, and risk-treatment plan, plus event-driven review after significant incidents or significant changes to operations or risks. Other sectors can use these as examples, but the Regulation's annex is not automatically binding on them.