Glowing network nodes on a dark background with one cluster in sharp focus, representing prioritisation of NIS2 Article 21 security measures

NIS2 Prioritisation Framework: The 10 Article 21 Measures Risk-Scored — and Why Entity Class Changes the Order

Every prioritisation list for NIS2 you will find asserts its order. None of them show their working. That is why they disagree with each other: one says start with multi-factor authentication, another says start with the risk assessment, a third says start with your supplier register — and none discloses the weighting that produced the answer.

This article scores the ten Article 21(2) measures on three axes, publishes the weights, and shows the arithmetic. Two of the three axes come from the directive’s own proportionality test. The result is not the order most lists give you, and it is not the same order for every reader: an essential entity and an important entity get materially different answers from the same scores, because Articles 32 and 33 subject them to structurally different supervision.

Start here: essential entity or important entity?

This is the first input to your priority order, not an administrative detail. It changes which of the three axes carries the most weight.

If you are… Your supervision regime What that means for sequencing
An essential entity Article 32 — proactive, ex ante. Authorities may act with no trigger at all. Evidence gets requested on a schedule. Measures that produce documents move up.
An important entity Article 33 — reactive, ex post. Authorities act only on “evidence, indication or information” of alleged non-compliance. An incident is the usual trigger. Measures that prevent or shrink incidents move up.
In a digital category named in Article 21(5) — DNS, TLD registries, cloud, data centres, CDN, managed service and managed security providers, online marketplaces, search engines, social platforms, trust services Both of the above, plus Commission Implementing Regulation (EU) 2024/2690, which converts Article 21(2) into 13 chapters of specific requirements. Your obligations are itemised. Sequencing is a resourcing question, not an interpretation one.

If you are outside those digital categories, CIR 2024/2690 does not bind you — your member state decides the precise measures, subject to the Article 21(2) minimum. The CIR is still the best available evidence of what “adequate” looks like, which is why it is used as evidence below, and why entities it does not bind should treat it as a reference rather than a rulebook. If you are unsure which class you are in, resolve that before reading further; the rest of this framework depends on it.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

The directive already contains a prioritisation function

Most readers treat Article 21(1) as preamble and skip to the list of ten in 21(2). The second subparagraph of 21(1) is where the scoring lives.

“Taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, the measures referred to in the first subparagraph shall ensure a level of security of network and information systems appropriate to the risks posed. When assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact.”
— Directive (EU) 2022/2555, Article 21(1) [1]

Cost of implementation. Exposure to risk. Size. Likelihood and severity of incidents. Those are not context — they are variables, and the directive tells you to weigh them. Recital 82 restates the principle in one sentence, though as a recital it is interpretive and creates no obligation of its own [2].

Note carefully what is absent from that list: how likely you are to be audited. Supervisory exposure is a real and rational input to a project plan, but it is not a proportionality factor. Article 21(1) asks how exposed you are to attackers, not to inspectors. Any framework that quietly blends the two — including this one — has to say so out loud.

Every measure has a floor and a ceiling

Here is why “which three of the ten do I do first?” is the wrong question. Ireland’s NCSC — a national competent authority — publishes draft guidance that splits every risk-management measure into two layers, and the split is doing more work than any priority list on the market [3]:

  • Foundation Actions — “controls, which the NCSC consider to be the minimum required to meet the legislative obligations of the Directive… a baseline of security practices that all entities are expected to uphold.” Every entity is expected to implement all of them, regardless of risk profile.
  • Supporting Actions — “Further controls may be required, depending on specific risks faced by the organisation.” These are decided by a risk assessment weighing exposure, size, likelihood and severity, societal impact, and cost. Which is to say: by the Article 21(1) factors.

Across its sixteen risk-management measures, the guidance defines 74 Foundation Actions and 129 Supporting Actions (counts derived from the published draft). So roughly two-thirds of the work is discretionary and one-third is not — but the discretion sits inside each measure, not between the measures. You cannot decide to skip supply chain security this year. You can decide that supply chain security means five foundation controls this year rather than ten.

Mapping those sixteen measures onto the ten Article 21(2) points is our synthesis, not the NCSC’s, and it changes what “prioritisation” means:

Art. 21(2) point Foundation Actions (mandatory floor) Supporting Actions (risk-dependent) Share discretionary
(i) HR security, access control, asset management 16 29 64%
(a) Risk analysis and IS security policies 8 12 60%
(b) Incident handling 8 24 75%
(d) Supply chain security 5 5 50%
(e) Acquisition, development, maintenance, vulnerability handling 5 21 81%
(h) + (j) Cryptography and authentication 5 1 17%
(c) Business continuity and crisis management 4 9 69%
(f) Assessing effectiveness of measures 4 9 69%
(g) Basic cyber hygiene and training 4 3 43%

The right-hand column is the most useful number in this article, and nobody publishes it. Call it finishability. Cryptography and authentication have almost no discretionary layer — five mandatory controls, one optional one. You can close that measure and it stays closed. Secure development under (e) is 81% discretionary and incident handling under (b) is 75%: those are never “done”, because the supporting layer expands with your risk assessment forever. Treating a programme like a task is how compliance plans slip.

The three axes — and which two the law gives you

Each measure is scored 1–5 on three axes. Two are statutory. One is not, and is labelled accordingly.

Axis A — supervisory exposure (not a statutory factor). How early a competent authority is likely to examine this measure. Evidence: how many chapters of the CIR 2024/2690 Annex are anchored to each Article 21(2) point. Every Annex chapter opens with the words “For the purpose of Article 21(2), point (x)”, so the Commission’s own weighting is directly readable [4]. Two findings from that census matter here: point (i) anchors three whole chapters plus a section of a fourth — more than any other point, and point (j), multi-factor authentication, anchors none at all. The market’s default first move is the one measure the Commission’s implementing regulation writes no requirements under. Our sibling analysis of which controls give the widest CIR coverage counts this from the control side and reaches the same place.

Axis B — incident likelihood (statutory: Article 21(1), “likelihood of occurrence of incidents and their severity”). Scored against the EU’s own incident corpus rather than vendor surveys. ENISA’s Threat Landscape 2025 analysed 4,875 incidents between 1 July 2024 and 30 June 2025: phishing was “the dominant intrusion vector (60%)”, vulnerability exploitation “a cornerstone of initial access (21.3%)” with campaigns “rapidly weaponising them within days of their disclosure”, and DDoS was the most prevalent threat overall, affecting 81.4% of sectors [5]. A measure that addresses a 60% vector outranks one that addresses a 1% vector.

Axis C — implementation cost, inverted (statutory: Article 21(1), “the cost of implementation”). Proxied by the size of the mandatory floor and its finishability ratio from the table above. A high score means cheap to close and likely to stay closed.

The scored matrix

Scores are ours, on the evidence above. Five is best.

Art. 21(2) measure A: supervisory exposure B: incident likelihood C: cost (inverted) Unweighted
(g) Basic cyber hygiene, training 3 5 5 13
(a) Risk analysis, IS security policies 5 2 3 10
(c) Business continuity, crisis management 3 4 3 10
(e) Acquisition, development, vulnerability handling 4 4 2 10
(i) HR security, access control, asset management 5 4 1 10
(j) MFA, continuous authentication, secured comms 1 4 5 10
(b) Incident handling 4 3 2 9
(d) Supply chain security 3 3 3 9
(f) Assessing effectiveness 4 2 3 9
(h) Cryptography and encryption 2 2 5 9

Nine of the ten measures land between 9 and 10. That near-tie is a finding, not a failure of the method: on equal weights the measures really are close to indistinguishable, which is precisely why every published priority list disagrees with the next one. Anyone who hands you a confident top three has applied a weighting and not told you what it was.

Only one measure separates from the pack on equal weights, and it is the one most guides mention last: (g) basic cyber hygiene practices and cybersecurity training. It scores 13 because it addresses the 60% intrusion vector, ties for the smallest mandatory floor of any measure at four foundation controls, and is only 43% discretionary — cheap, high-yield, and finishable. It is not glamorous and it is not technical, and it beats MFA on this evidence.

Why your entity class flips the order

Now apply the weight. Article 32 gives authorities seven supervisory powers over essential entities. Article 33 gives them five over important entities — and the two texts differ in ways that are easy to miss when they are summarised side by side.

Power Essential (Art. 32(2)) Important (Art. 33(2))
On-site inspections and off-site supervision Yes, “including random checks” Yes, but ex post only; no random checks
Security audits regular and targeted security audits” “targeted security audits” — the word regular is absent
Ad hoc audits Yes Not listed
Security scans Yes Yes
Requests for information / access to documents Yes Yes, to assess ex post
“Requests for evidence of implementation of cybersecurity policies, such as the results of security audits carried out by a qualified auditor” Yes — Art. 32(2)(g) No equivalent power

That last row is the one that moves the framework. An essential entity can be told, without any incident, to produce evidence that it implemented what it wrote down [6]. No such standalone power exists over an important entity, and Article 33 supervision of any kind begins only once an authority has “evidence, indication or information” of alleged non-compliance [7]. An important entity can still be asked for documents under Article 33(2)(d) and (e) — but only after something has prompted the question, and in practice the most common prompt is an incident you had to report. We cover the mechanics of both regimes in what Articles 32 and 33 mean for your next inspection.

Two national authorities show the same asymmetry in practice. Germany’s BSI states that most entities evidence their measures “nur auf Anfrage im Falle einer Anordnung durch das BSI” — only on request, following an order — while KRITIS operators must submit audits, inspections or certifications “auch ohne Aufforderung”, unprompted, on a cycle the NIS-2 implementation act extended from two years to three. The same FAQ closes the shortcut: “Ein allgemeines Zertifikat zum Nachweis der Anforderungen gibt es nicht” — there is no general certificate [8].

So: essential entities double axis A. Important entities double axis B. The rankings that produces:

Essential entity — axis A doubled Important entity — axis B doubled
1. (g) Cyber hygiene and training — 16 1. (g) Cyber hygiene and training — 18
2= (a) Risk analysis and policies — 15 2= (c) Business continuity — 14
2= (i) HR, access control, asset management — 15 2= (e) Vulnerability handling — 14
4. (e) Vulnerability handling — 14 2= (i) HR, access control, asset management — 14
5= (b) Incident handling — 13 2= (j) MFA and secured communications — 14
5= (c) Business continuity — 13 6= (a) Risk analysis and policies — 12
5= (f) Assessing effectiveness — 13 6= (b) Incident handling — 12
8. (d) Supply chain security — 12 6= (d) Supply chain security — 12
9= (h) Cryptography — 11 9= (f) Assessing effectiveness — 11
9= (j) MFA and secured communications — 11 9= (h) Cryptography — 11

The headline result is the inversion. Measure (a), risk analysis, is joint-second for an essential entity and joint-sixth for an important one. Measure (j), MFA, is joint-second for an important entity and last-equal for an essential one. They swap ends of the table — and they are the two measures most commonly named as “the place to start”. Both pieces of advice are right, for opposite readers, which is why the argument never resolves.

The other stable result: (g) ranks first under both weightings, and (f) and (h) rank last under both. If you want one recommendation that survives every weighting we tested, it is that basic cyber hygiene and training is the first measure to close.

Your first 30 days, by role

Role Do this first Effort
Board / management body Confirm your entity class in writing, then approve the scored priority order by minute. Article 20(1) requires the management body to approve Article 21 measures, oversee implementation, and makes it liable for infringements — the approval is the artefact, not the intention. Low
Compliance officer Re-score the matrix with your own numbers and record the assumptions. A dated, assumption-explicit model is the working paper behind a proportionality judgement — see the Article 21(1) business case for how that argument is built. Medium
IT / security lead Close the (g) floor: the four foundation controls for basic cyber hygiene. Then the (h)+(j) floor — five controls, one optional. Both are finishable inside a month. Low–Medium
HR Begin the (i) floor: joiners-movers-leavers, screening, and the access rights that follow them. It is the largest mandatory floor of any measure at sixteen controls — start now precisely because it will not finish quickly. High

Once the floor work is scoped, sequence it against the calendar rather than the score. Our 22, 32 or 44-week roadmap sizes the phases to headcount, and the five-phase gap analysis turns the scored order into a remediation backlog.

What this framework cannot do

Three limits, stated plainly.

It does not make anything optional. All ten measures in Article 21(2) are minimum requirements. Prioritisation orders the work; it does not reduce it, and Article 21(4) obliges you to take “all necessary, appropriate and proportionate corrective measures” without undue delay once you find a shortfall. Sequencing is defensible. Omission is not.

The scores are ours, and the evidence under them is uneven. The CIR chapter census, the ENISA incident figures, and the Article 32/33 comparison are primary and verifiable. The 1–5 ratings and the doubling weights are our judgement applied to that evidence. The NCSC Ireland counts come from guidance that is explicitly draft and pending Ireland’s National Cybersecurity Bill, and the mapping from its sixteen measures onto the ten Article 21(2) points is ours rather than the authority’s. Re-score with your own numbers — that is the point of publishing the method.

It is not a compliance determination. Proportionality is assessed against the measures you actually implemented, and a competent authority is not bound by your reasoning about them. A scored matrix evidences that a judgement was made deliberately, on stated assumptions, at a known date. It does not establish that the judgement was right.

Frequently Asked Questions

Can I defer one of the ten measures entirely?

No. Article 21(2) sets minimum requirements across all ten areas. What varies is depth: NCSC Ireland’s split shows a mandatory foundation layer that every entity implements and a supporting layer sized to risk. Prioritisation applies to the second layer and to the order of work, never to whether a measure applies.

Why does MFA rank last for essential entities when everyone recommends it first?

Because two of the three axes disagree with the recommendation. MFA addresses a genuinely dominant intrusion vector and is cheap to finish, which is why it ranks joint-second for important entities. But point (j) is the one Article 21(2) point that CIR 2024/2690 anchors no Annex requirement to, and its wording ends “where appropriate” — so under scheduled, evidence-driven supervision it is unlikely to be where an auditor starts. Implement it. Just do not expect it to carry an inspection.

What if I am both an essential entity and subject to CIR 2024/2690?

Then your obligations are itemised in 13 Annex chapters and the sequencing question becomes purely a resourcing one. Use axis A weighting, and read the chapter structure directly — our measure-by-measure breakdown of Article 21 and the CIR sub-requirements maps them.

Does an ISO 27001 certificate change the ranking?

It changes your starting position on several measures, not the ranking itself. Germany’s BSI is explicit that no general certificate evidences NIS2 requirements. A certificate is evidence you can offer; it is not a substitute for the measures.

How often should I re-score?

Every chapter of the CIR Annex carries a review-and-update requirement, and the trigger it uses — repeated 22 times across the Annex — is “when significant incidents or significant changes to operations or risks occur”. Use the same trigger for the matrix, plus an annual pass. If you re-score after an incident and nothing moves, that is itself a finding worth recording.

Sources

  1. Directive (EU) 2022/2555, Article 21 — cybersecurity risk-management measures. Canonical text in the Official Journal; article-level reproduction at nis2resources.eu and nis-2-directive.com.
  2. Directive (EU) 2022/2555, Recital 82 (non-binding) — Preamble 81–90.
  3. NCSC Ireland, NIS 2 Risk Management Measures Guidance (Draft, June 2025) — Foundation and Supporting Actions.
  4. ENISA, NIS2 Technical Implementation Guidance — verbatim reproduction of the CIR 2024/2690 Annex.
  5. ENISA, Threat Landscape 2025 — 4,875 incidents, 1 July 2024 to 30 June 2025.
  6. Directive (EU) 2022/2555, Article 32 — supervision of essential entities.
  7. Directive (EU) 2022/2555, Article 33 — supervision of important entities.
  8. BSI, Allgemeine FAQ zu NIS-2 — evidence obligations and the Nachweiszyklus.
  9. Directive (EU) 2022/2555, Article 20 — governance and management-body approval.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: