What should a NIS2 Article 21 gap assessment produce?
It should produce a control-to-requirement map, evidence list, gap register, remediation owner map, residual-risk acceptance record, and review trigger list for the assessed service or entity.
Map existing cybersecurity controls to Article 21 risk-management measures, identify missing evidence, and assign owners for remediation and management review.
Pair this workflow with the NIS2 Directive, Commission Implementing Regulation (EU) 2024/2690 where it applies, and ENISA implementation guidance.
Structured answer sets in this page tree.
Cited legal and guidance references.
This workflow helps security, legal, risk, procurement, and operations teams assess gaps in the required by NIS2 Article 21. Confirm the legal entity, service, Member State rule, and proportionality context first; then map current controls and operating evidence to all ten Article 21(2) areas, assign remediation and risk-acceptance owners, and set reassessment triggers.
Confirm whether the legal entity, service, country implementation, sector, and size or regardless-of-size rule bring the activity within NIS2 before scoring controls. Article 21 applies to essential and important entities, but Member State implementation and equivalent sector-specific Union rules can affect which requirements and evidence requests govern a particular service.
For the gap assessment, record the risk context that Article 21 uses: state of the art, relevant European and international standards where applicable, cost of implementation, entity size, exposure to risk, and the likelihood and severity of incidents.
Use Article 21(2) as the control taxonomy for the first pass. Each row should name the current control, owner, system or process covered, evidence location, gap rating, and remediation action.
Do not collapse supplier security, incident handling, access control, cryptography, and business continuity into one generic security-policy row. Article 21 expects coverage across multiple technical, operational, and organisational measure areas.
Commission Implementing Regulation (EU) 2024/2690 gives directly applicable technical and methodological requirements for the provider types listed in its Article 1: DNS services, TLD registries, cloud computing, data centres, content delivery networks, managed and managed security services, online marketplaces, online search engines, social networking service platforms, and trust services. It also specifies significant-incident cases for those providers. For another NIS2 entity, the regulation is a comparator, not a binding control catalogue for that entity.
When it applies, align the gap assessment to the regulation's annexed requirements and ENISA's evidence examples. For other NIS2 entities, record the national rule or supervisory expectation that turns Article 21 into a concrete control requirement.
Each assessment row should let a reviewer trace the requirement to the actual control, proof, owner, and decision on residual risk. A maturity score without that traceability is incomplete.
Use evidence that shows the measure is in place and maintained. ENISA examples include documented frameworks, risk assessments, treatment plans, approval records, procedures, logs, organisational charts, and review change logs, depending on the requirement being assessed.
Article 20 links Article 21 measures to management-body approval, oversight, training, and potential liability under Member State law. The close-out package should therefore be ready for management review, not only security-team tracking.
Before closing the assessment, confirm that residual risks have been accepted through the entity's governance process, that necessary appropriate and proportionate corrective measures are tracked without undue delay when the entity finds non-compliance with Article 21(2), and that the evidence can be retrieved for the competent authority. Customer or auditor requests may call for a separate, appropriately redacted evidence set.
It should produce a control-to-requirement map, evidence list, gap register, remediation owner map, residual-risk acceptance record, and review trigger list for the assessed service or entity.
No. ENISA guidance is useful for implementation and evidence examples, but the binding source remains the NIS2 Directive, applicable implementing regulation, and the relevant Member State implementation or supervisory requirements.
No. It applies to the provider types listed in its Article 1, including DNS, TLD registry, cloud, data centre, content delivery network, managed service, managed security service, specified online-platform, and trust-service providers. Other NIS2 entities should assess Article 21 against applicable national law and sector rules; they may use the regulation as a labelled comparator, but not present it as binding on them.
Sorena can help convert Article 21 requirements, implementing-regulation annex points, and ENISA evidence examples into control mappings, evidence requests, and management-ready remediation tracking.
Ask questions tied to cited sources about Article 21 controls, evidence examples, implementing-regulation scope, and remediation planning using the cited sources on this page.
Review your Article 21 control map, evidence gaps, and management review package with Sorena.
"approve the cybersecurity risk-management measures"
"Documented risk treatment plan"
"NIS2 Directive"
"Annex to this Regulation"