Archer GRC for NIS2: Mapping Article 21’s Ten Measures to Archer Use Cases — and the Three With No Native Home
Archer does not sell a NIS2 module. There is no "NIS2 solution" on the price list, and Archer’s own IT & Security Risk Management and Third Party Governance product pages do not mention the Directive at all [6][7]. What Archer sells is a catalogue of solutions broken into individually licensed use cases — and NIS2 compliance work happens by mapping Article 21(2)’s ten measures onto those use cases yourself.
What Archer Actually Ships for NIS2 (and What It Doesn’t)
Plain-language summary: Archer is a configurable risk and compliance platform, not a compliance product. It gives you the record structures, workflows and reporting to evidence NIS2 obligations — it does not tell you what those obligations are.
Archer’s public catalogue lists nine core solutions — Audit Management, Business Resiliency, Enterprise and Operational Risk Management, ESG Management, IT & Security Risk Management, Operational Resilience, Public Sector, Regulatory and Corporate Compliance, and Third Party Governance — plus newer Evolv, AI Governance and Risk Quantification offerings [8]. Underneath, the help documentation breaks these into roughly forty named use cases [5]. The use case, not the solution, is the unit Archer documents by — and, in most commercial arrangements, the unit it licenses by. Any credible NIS2 conversation about Archer happens at that level.
Archer’s own NIS2 blog post argues that GRC is an ally rather than a burden, but names only generic capability categories — automated risk assessment, automated incident response, machine learning for false positives. It maps nothing to Article 21(2) and names no use case [12]. The ten-vendor NIS2 tool round-ups do no better. So the mapping below is this article’s own analysis, built from Archer’s primary documentation [5][6][7] against the verbatim Article 21(2) text [2].
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
The Article 21(2) to Archer Use Case Map
Article 21(2) sets ten minimum measure categories, framed by Article 21(1) as an "all-hazards approach" covering the physical environment as well as the systems themselves — theft, fire, flood, power failure, unauthorised physical access [1]. Germany’s BSI, as national competent authority, states the same obligation runs through § 30 BSIG, and that the documentation duty exists so entities can produce evidence documents to the authority on request under § 61 Absatz 3 BSIG [4] — the test a platform actually has to pass.
| Art. 21(2) | Measure | Archer use case(s) | Coverage |
|---|---|---|---|
| (a) | Risk analysis and information system security policies | IT Risk Management; IT & Security Policy Program Management; Risk Catalog | Native |
| (b) | Incident handling | Cyber Incident & Breach Response; Incident Management | Native |
| (c) | Business continuity, backup, disaster recovery, crisis management | Business Continuity & IT Disaster Recovery Planning; Business Impact Analysis; Crisis Management | Native |
| (d) | Supply chain security, direct suppliers and service providers | Third Party Catalog; Third Party Engagement; Third Party Risk Management; Third Party Governance | Native |
| (e) | Acquisition, development and maintenance; vulnerability handling and disclosure | IT Security Vulnerabilities Program | Native (vulnerability half) |
| (f) | Assessing the effectiveness of risk-management measures | IT Controls Assurance; Continuous Controls Monitoring; Audit Planning & Quality; Issue Management | Native |
| (g) | Basic cyber hygiene and cybersecurity training | — none | No native use case |
| (h) | Cryptography and, where appropriate, encryption | — none | No native use case |
| (i) | Human resources security, access control policies, asset management | IT Risk Management (asset inventory only) | Partial |
| (j) | MFA or continuous authentication; secured voice, video, text and emergency communications | — none | No native use case |
Measure wording above is condensed; the verbatim text is at [2]. Six measures land on a named Archer use case, one is partial, and three have no home at all. That ratio, rather than any feature list, is the honest starting point for an Archer NIS2 budget.
Where Archer Genuinely Earns Its Licence Fee
The five measures Archer handles well are workflow-and-record problems rather than technical controls.
Article 21(2)(a) — risk analysis and security policies. IT Risk Management captures an inventory of business and IT assets using pre-built risk assessment methodologies and IT control libraries [6]; IT & Security Policy Program Management holds the policy documents and assigns ownership. This is the closest Archer comes to an out-of-the-box NIS2 answer, because the platform was designed for exactly this record shape. Our full Article 21 breakdown covers what each measure demands in substance.
Article 21(2)(b) — incident handling. Cyber Incident & Breach Response catalogues assets and uses that business context to prioritise, escalate and close incidents [6]. But Archer ships incident workflow, not NIS2 reporting deadlines. Article 23(4) requires an early warning "within 24 hours of becoming aware of the significant incident", an incident notification "within 72 hours", an intermediate report on request, and a final report "not later than one month after the submission of the incident notification" [3]. Those clocks have to be built as SLA fields, calculated dates and escalation rules — nothing in the shipped content knows they exist. Map the incident reporting timeline before you configure, not after.
Article 21(2)(c) — business continuity and crisis management. Archer’s strongest structural fit: the Directive’s wording splits almost exactly along three separate Resilience Management use cases — Business Impact Analysis, Business Continuity & IT Disaster Recovery Planning, and Crisis Management [5].
Article 21(2)(d) — supply chain security. Third Party Governance decomposes into a Third-Party Catalog (relationships, contracts, named accountable individuals), Third-Party Engagement (what each supplier delivers to which business process), Third-Party Risk Management (residual risk from assessments) and Third-Party Governance (SLA metrics) [7]. Article 21(3) requires entities to account for "the vulnerabilities specific to each direct supplier and service provider" [2] — Engagement is what makes that per-supplier granularity possible, and it is the use case buyers most often leave out of the initial licence. See our supply chain security requirements guide for what the assessment must contain.
Article 21(2)(f) — effectiveness assessment. IT Controls Assurance reports on control performance across assets, Continuous Controls Monitoring automates verification of IT, cloud and identity controls to detect drift [6], and Audit Management closes the loop through Issue Management. Measure (f) is the one most organisations under-serve and the one Archer answers best.
The Three Measures With No Native Archer Use Case
Measures (g) cyber hygiene and training, (h) cryptography and encryption, and (j) multi-factor authentication and secured communications have no dedicated Archer use case in the published catalogue [5].
This is a category boundary, not a defect. Training delivery lives in an LMS, encryption in key management and platform configuration, MFA in your identity provider. A GRC platform’s legitimate role here is narrower: hold the policy record, the control statement, the attestation, and the evidence that proves the control operates. For (g), (h) and (j) you are building control records and evidence fields inside Policy Program Management or IT Controls Assurance rather than licensing anything new — budget configuration time, not licence spend.
Measure (i) is the split case. "Human resources security, access control policies and asset management" [2] bundles three unrelated disciplines into one lettered point. Asset management is genuinely native — IT Risk Management’s asset inventory is the backbone of the whole deployment. HR security and access control policy are not; they are policy records with evidence pulled from HR and identity systems. Reading (i) as "covered, we have asset management" is the most common self-assessment error in this map.
The Authoritative Source Layer — and the February 2025 Freeze
Archer loads a regulation into the platform as an authoritative source. The Authoritative Sources application is hierarchical — Sources, then Topics, then Sections, then Subsections — with a separate feed populating Control Standards; the data-feed utility requires no prerequisite use cases and no on-demand application licences, though Master Controls and Question Library data must be imported through the Data Import Wizard first [10]. Article 21(2)’s ten lettered points fit that hierarchy cleanly, which is why the mapping above is buildable at all.
Archer Exchange lists an NIS 2 Directive (EU) 2022/2555 authoritative source [13]. Two cautions before you plan around it.
First, the Exchange also carries a separate U.K. NIS Regulations authoritative source [14]. Those are different instruments — the UK regime derives from the 2016 NIS Directive and is not EU NIS2. An organisation operating on both sides of the Channel needs both; neither substitutes for the other.
Second, and more consequential: Archer’s own Exchange announcement states that "Beginning February 2025, Archer will no longer provide updates to authoritative sources and more. Existing content will remain available on the Archer Exchange" [9]. The packages remain downloadable; they are no longer maintained.
For a static standard that would be minor. For NIS2 it is a planning assumption you have to make explicit, because NIS2 is a directive, not a regulation — the binding text your competent authority enforces is your member state’s transposition, and several member states only transposed during 2025 and 2026. Germany’s operative provision is § 30 BSIG, not Article 21 [4]. A frozen EU-level content package cannot track twenty-seven national variations.
The national layer is therefore yours to maintain, in Corporate Obligations Management. The LexisNexis Regulatory Compliance integration can automate the feed, but it "allows you to automatically import regulatory compliance data directly into the Archer Policy Program Management and Corporate Obligations Management use cases" — requiring both use cases — and its coverage depends entirely on your own LexisNexis content subscription [11]. Confirm NIS2 and your national transposition sit inside that subscription before assuming the feed solves it.
A Configuration Sequence That Produces Evidence, Not Dashboards
Order matters — each layer depends on the one before it. Effort ratings are practitioner estimates for an organisation with an existing Archer footprint, not vendor figures.
| Step | What you build | Owner | Effort |
|---|---|---|---|
| 1 | Load the NIS2 authoritative source; add your national transposition as obligations in Corporate Obligations Management | Compliance / Legal | Medium |
| 2 | Derive Control Standards from (a)-(j); tag each to its lettered point so reporting filters by measure | CISO | High |
| 3 | Populate the IT Risk Management asset inventory — every later measure inherits its scope | IT / CMDB owner | High |
| 4 | Configure IT Controls Assurance and Continuous Controls Monitoring against those standards (measure (f)) | CISO | Medium |
| 5 | Build the Article 23 clocks into Cyber Incident & Breach Response: 24-hour, 72-hour, one-month fields | SOC / IR lead | Medium |
| 6 | Onboard direct suppliers into Third Party Catalog and Engagement, then assess (measure (d)) | Procurement + CISO | High |
| 7 | Attach policy and attestation records for (g), (h), (j) — configuration only, no new licence | Compliance | Low |
| 8 | Build the management reporting pack; Article 20 places approval and oversight on the management body | Board sponsor | Low |
The output that matters is the one BSI describes: documents you can put in front of the authority when it asks [4]. If a configuration decision does not improve the evidence you could hand over tomorrow, it is a dashboard, not compliance work.
Who Should Configure Archer for NIS2 — and Who Shouldn’t
Configure Archer if you already run an Archer estate with IT Risk Management or Third Party Governance live, you have a dedicated GRC administrator, and NIS2 is one of several regimes you are evidencing from one control set. The marginal cost of adding NIS2 to a running Archer program is low, and its measure (f) tooling beats most alternatives.
Do not start here if NIS2 is your first compliance program. Implementation partners typically describe Archer rollouts in quarters rather than weeks, and in practice an important entity of fifty to two hundred staff is likely to spend more on configuration than the exposure warrants. Our scored comparison of ten NIS2 GRC tools covers the lighter end of that market, and the ServiceNow IRM module map runs the same analysis on the closest comparable platform.
Either way, no platform changes what the Directive requires. Article 21(4) obliges an entity that finds it does not comply to take "all necessary, appropriate and proportionate corrective measures" without undue delay [2]. Archer surfaces that gap faster than a spreadsheet. It cannot close it.
Frequently Asked Questions
Does Archer have a NIS2 module? No. Archer sells solutions broken into individually licensed use cases, and none is NIS2-specific. NIS2 enters the platform as authoritative-source content and control standards mapped onto general-purpose use cases [5][9].
Is the Archer NIS2 authoritative source still updated? Archer’s Exchange announcement states that from February 2025 it no longer updates authoritative sources, though existing content remains available [9]. Treat the NIS2 package as a starting structure you maintain, not a subscription that tracks the law.
Which Archer use cases are the minimum for a credible NIS2 program? From the map above: IT Risk Management, IT & Security Policy Program Management, Cyber Incident & Breach Response and Third Party Risk Management. IT Controls Assurance is what turns them into measure (f) evidence.
Does Archer handle the 24-hour and 72-hour reporting deadlines automatically? Not out of the box. Cyber Incident & Breach Response provides the workflow; the Article 23(4) clocks are configuration you build [3][6].
Key Takeaways
- Archer ships no NIS2 module; its own IT & Security Risk Management and Third Party Governance pages never mention the Directive [6][7].
- Six of the ten measures map to a named Archer use case, one is partial, and three — (g) training, (h) cryptography, (j) MFA and secured communications — have none.
- Measure (i) is the trap: asset management is native, HR security and access control policy are not.
- Archer stopped updating authoritative sources in February 2025 [9], so the national transposition layer is yours to maintain — and the Exchange’s U.K. NIS Regulations content is a different instrument from EU NIS2.
- Article 23’s 24-hour, 72-hour and one-month clocks [3] are configuration, not shipped behaviour.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Directive (EU) 2022/2555 (NIS2) — EUR-Lex
- NIS 2 Directive Article 21 — Cybersecurity risk-management measures
- NIS 2 Directive Article 23 — Reporting obligations
- #nis2know: NIS-2-Risikomanagementmassnahmen — BSI, Germany
- Archer Use Cases — Archer Help Center
- Archer IT & Security Risk Management
- Archer Third Party Governance
- Archer GRC Solutions
- Archer Exchange Announcement — February 2025
- Archer Authoritative Source Data Feed — Archer Help Center
- LexisNexis Regulatory Compliance integration — Archer Help Center
- NIS 2: Friend or Foe? Make GRC Your Ally — Archer
- "NIS 2 Directive (EU) 2022/2555 Authoritative Source" — Archer Exchange listing (archerirm.exchange, app 455579; listing page redirects to Archer’s migrated help centre)
- "U.K. NIS Regulations Authoritative Source" — Archer Exchange listing (archerirm.exchange, app 420884)
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
