NIS2 Recitals: All 144 Are Non-Binding — and ENISA Still Sends You to 3 of Them to Define Cyber Hygiene
ENISA’s Technical Implementation Guidance, the 170-page document the EU’s own cybersecurity agency wrote to explain the binding technical rules, hits a wall at point 8.1 and tells readers this: “Refer to recitals 49, 50 and 89 of the NIS2 Directive for clarifications of the term ‘cyber hygiene’.” [9]
That line is the whole case for reading the preamble. Recitals create no obligations. But Article 21(2)(g) imposes a duty to apply “basic cyber hygiene practices” without saying what those are, the implementing regulation repeats the phrase without defining it either, and the EU agency charged with explaining it sends you to three non-binding paragraphs. Below: what recitals can and cannot do, which ones carry content the articles do not, and how to cite one without weakening your position.
What a recital is, and the two things it can never do
In plain terms: the recitals are the numbered “Whereas” paragraphs before Article 1. NIS2 has 144 of them, against 46 articles. They record why the legislature acted. They are not the law.
The Court of Justice has stated the limit directly. In Nilsson (C-162/97), at paragraph 54, the Court held that “the preamble to a Community act has no binding legal force and cannot be relied on as a ground for derogating from the actual provisions of the act in question” [6]. Later judgments extend the point to interpretation: a recital cannot be used to read a provision in a way clearly contrary to its wording. The drafting rulebook agrees from the other direction — Guideline 10 of the 1998 Interinstitutional Agreement requires recitals to “set out concise reasons for the chief provisions of the enacting terms, without reproducing or paraphrasing them” and states they “shall not contain normative provisions or political exhortations” [8].
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
So a recital cannot create a duty or cancel one. What it can do is settle meaning. In TWD (C-355/95 P), at paragraph 21, the Court held that “the operative part of an act is indissociably linked to the statement of reasons for it, so that, when it has to be interpreted, account must be taken of the reasons which led to its adoption” [7]. That is the narrow doorway every legitimate use of a NIS2 recital passes through: the article is ambiguous, and the recital resolves the ambiguity without contradicting the text.
The recital map most guides get wrong
Secondary summaries misnumber these constantly, and a wrong recital number in a regulator submission costs more credibility than leaving the citation out. The table below is checked against the primary text. The right-hand column is the one that matters: it shows whether the operative articles already say the same thing.
| Topic practitioners look for | Actual recital | Binding twin | Is the recital adding anything? |
|---|---|---|---|
| Proportionality, state of the art, cost of implementation | 81 | Art 21(1) | No — the article carries the same wording with binding force |
| Proportionate to exposure, size, societal and economic impact | 82 | Art 21(1) | No — same test, already binding |
| All-hazards approach | 79 | Art 21(2) | Partly — the article states the principle, the recital supplies the examples |
| What “basic cyber hygiene” means | 49, 50, 89 | Art 21(2)(g) | Yes — the article names the duty and defines nothing |
| Public administration entities excluded | 8 | Art 2(7) | Yes — the article states the exclusion flatly; only the recital limits it to bodies “predominantly” in those areas |
| Force majeure, state-sponsored attacks | none | none | The phrase appears nowhere in the instrument |
The recitals most often cited for proportionality are therefore redundant, and the phrase practitioners most want to find is not in the Directive at all — a point covered in our analysis of what a state-sponsored attack actually changes under NIS2. For the underlying risk-management provision, see our complete guide to Article 21.
Recital 8 is the clearest example of a recital doing real work. Article 2(7) excludes public administration entities that “carry out their activities in the areas of national security, public security, defence or law enforcement” — flatly, with no threshold. Read alone, any police-adjacent function could arguably take a body out of scope. Recital 8 limits the exclusion to entities whose activities are “predominantly” in those areas and states that bodies “only marginally related” to them should not be excluded. The word “marginally” appears nowhere in the 46 articles. Our guide to which public bodies Recital 8 exempts works through the boundary.
Fifteen terms that appear in the preamble and in none of the 46 articles
To find where the preamble carries weight rather than restating the articles, we built a local corpus of the Directive — all 144 recitals and all 46 articles from a verbatim mirror, with the mirror’s editorial commentary stripped out before counting — and searched both halves for the vocabulary practitioners expect to find. Fifteen security terms occur zero times across the entire operative text:
| Term | Occurrences in Articles 1-46 | Recital |
|---|---|---|
| zero-trust | 0 | 89 |
| network segmentation | 0 | 89 |
| identity and access management | 0 | 89 |
| device configuration | 0 | 89 |
| phishing | 0 | 89 |
| social engineering | 0 | 89 |
| artificial intelligence / machine learning | 0 | 51, 89 |
| password | 0 | 49 |
| administrator-level access | 0 | 49 |
| ISO/IEC (27000 series) | 0 | 33, 58, 79 |
| theft / fire / flood | 0 | 79 |
| human error | 0 | 79 |
The pattern is not random. Almost all of these terms cluster in just three recitals — 49, 79 and 89 — and each of those three attaches to a provision that states its obligation in abstract terms. Article 21(2) requires an “all-hazards approach”; Recital 79 is the only place the Directive says what hazards it means, naming theft, fire, flood, telecommunication and power failures, human error and natural phenomena, and pointing to the ISO/IEC 27000 series as the reference standard [4]. The operative text names none of them.
A caveat on method: because the editorial commentary was removed before counting, a zero here is a genuine zero rather than an artefact of how the text was scraped.
“Basic cyber hygiene”: the one duty NIS2 defines only in its preamble
Article 21(2)(g) requires essential and important entities to have “basic cyber hygiene practices and cybersecurity training” [2]. It stops there. Follow the definition through the official chain of authority and it never lands on binding text:
- Article 21(2)(g) — names the duty. No definition.
- Commission Implementing Regulation (EU) 2024/2690, Annex point 8.1.1 — binding, but only for the eleven entity types listed in Article 21(5): DNS providers, TLD registries, cloud and data centre providers, CDNs, MSPs, MSSPs, online marketplaces, search engines, social networking platforms and trust service providers [10]. It says relevant entities “shall ensure that their employees are aware of risks, are informed of the importance of cybersecurity and apply cyber hygiene practices” [9]. Still no definition.
- ENISA’s Technical Implementation Guidance (v1.0, June 2025) — which describes itself as “non-binding guidance” — fills the gap by instructing readers to “refer to recitals 49, 50 and 89 of the NIS2 Directive for clarifications of the term ‘cyber hygiene'” [9].
- Recitals 49 and 89 — the only enumeration in the instrument: software and hardware updates, password changes, management of new installs, limitation of administrator-level access accounts and backing-up of data [3]; plus zero-trust principles, device configuration, network segmentation, identity and access management, and awareness of phishing and social engineering [5].
The definitional buck stops at text with no binding legal force, and it does so by design. Guideline 10 forbids recitals from carrying normative provisions, so the legislature could not have put the list in the preamble as a rule. It put it there as an explanation — and the Commission and ENISA have both since treated that explanation as the operative reference.
The consequence differs by entity type. If you are one of the eleven types covered by the implementing regulation, your auditable requirements sit in its Annex and the recitals explain the vocabulary. Any other essential or important entity has no EU-level technical specification yet — Article 21(5) says the Commission “may” adopt one — so the recitals plus your national transposition are the whole of the available guidance on what cyber hygiene training must cover.
The proportionality trap: why citing Recital 81 weakens your argument
Recital 81 is the most-quoted paragraph in NIS2 commentary, because it says measures should be proportionate “in order to avoid imposing a disproportionate financial and administrative burden”, taking into account the state of the art and the cost of implementation [5]. Recital 82 adds exposure, criticality, entity size and societal impact.
Both are the weaker copy of something you already have. Article 21(1) states, in binding terms, that measures “shall ensure a level of security… appropriate to the risks posed”, “taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation”, and that “when assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact” [2].
Every factor is there, with “shall”. Leading a proportionality argument with Recital 81 invites the obvious reply that recitals have no binding force, and signals you did not find the article. Cite Article 21(1), and bring Recital 81 in only as secondary support for the one point the article leaves implicit: that avoiding a disproportionate administrative burden was a purpose of the drafting.
How to use a recital without undermining your position
Three rules cover almost every case. First, never let a recital be your only authority for a duty or an exemption — Nilsson forecloses it. Second, if the operative article says the same thing, cite the article and drop the recital. Third, reserve recitals for genuine gaps: undefined terms, unlisted examples, and the reasoning behind a threshold.
What that means in practice depends on your role:
| Role | Where recitals actually help you |
|---|---|
| Compliance officer / legal | Use Recitals 49, 50 and 89 as the documented basis for how you scoped “basic cyber hygiene”. Cite ENISA’s guidance alongside them, so the choice reads as following official direction rather than as your own interpretation. Never cite a recital as the source of an obligation in a submission. |
| CISO / IT security manager | Recital 79 is your control-selection checklist for the all-hazards duty: physical and environmental security, human resources security, access control, and the ISO/IEC 27000 series as the mapping target. Recital 89’s list maps cleanly onto zero-trust, segmentation and IAM workstreams. |
| SME owner / non-technical | Read Recitals 49 and 89 before any vendor proposal. They are the closest thing the Directive has to a plain-English baseline, and they are short. If a proposal goes far beyond them, ask which article requires it. |
| Board / C-suite | Recitals 81 and 82 explain why the spend can be scaled to the organisation’s risk and size — useful framing for a budget discussion, but the authority to cite in board minutes is Article 21(1). |
Frequently asked questions
How many recitals does NIS2 have? 144, numbered (1) to (144), against 46 articles.
Are NIS2 recitals legally binding? No. Per Nilsson, paragraph 54, a preamble has no binding legal force [6]. Recitals guide interpretation of ambiguous articles; they cannot create or remove an obligation.
Can a regulator rely on a recital against me? Only in the same limited way you can rely on one: to interpret an article that is genuinely ambiguous. A national authority enforcing “basic cyber hygiene” is likely to read Article 21(2)(g) through Recitals 49 and 89, because ENISA’s own guidance directs it there.
Where do I read the recitals? They appear before Article 1 in the consolidated text on EUR-Lex [1]. Our guide on finding the NIS2 full text covers the navigation.
Does the same apply to my national transposition? Not automatically. Member States transpose the articles, not the preamble, and national implementing laws carry their own explanatory materials. Check what your national law says before assuming an EU recital transfers.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Directive (EU) 2022/2555 (NIS2), full text — EUR-Lex
- NIS2 Directive, Article 21: Cybersecurity risk-management measures
- NIS2 Directive, Preamble, Recitals 41-50
- NIS2 Directive, Preamble, Recitals 71-80
- NIS2 Directive, Preamble, Recitals 81-90
- Judgment of 19 November 1998, Nilsson and Others, C-162/97 — EUR-Lex
- Judgment of 15 May 1997, Textilwerke Deggendorf v Commission, C-355/95 P — EUR-Lex
- Interinstitutional Agreement of 22 December 1998 on common guidelines for the quality of drafting of Community legislation — EUR-Lex
- ENISA, Technical Implementation Guidance on cybersecurity risk-management measures, v1.0, June 2025
- Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 — EUR-Lex
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
