Skip to main content
NIS2

NIS2 Directive: Implementing Articles 21 and 23

NIS2 Directive: Implementing Articles 21 and 23. What do these core provisions require, and how can organisations translate them into practice with risk management, security measures and clear incident reporting processes?

fuentis Team

fuentis Team

Team

NIS2 Directive: Implementing Articles 21 and 23

NIS2 Directive: Implementing Articles 21 and 23

What Are Articles 21 and 23 of NIS2?

The NIS2 Directive is a key pillar of the European cybersecurity strategy and, compared to its predecessor, applies to a significantly larger number of organisations. It obliges so-called “essential” and “important” entities to implement appropriate measures to ensure the security of their IT – on a binding basis.

Two provisions are particularly relevant: Article 21 defines concrete security requirements, while Article 23 regulates the obligations to report significant security incidents. Together, they require organisations to implement both technical and organisational measures – often under tight timelines.


Article 21: Security Requirements in Detail

Article 21 of NIS2 forms the core of the security requirements. It obliges organisations to take appropriate technical and organisational measures to identify, prevent and reduce risks to the security of their network and information systems. These measures must be state of the art and proportionate to the actual risks.

Key elements of Article 21 include:

Risk management and security policies Entities must establish structured procedures to systematically identify and assess risks to their IT systems. Based on this, security policies must be defined, documented and reviewed regularly.

Incident management Processes must be in place to detect, analyse, handle and follow up on security incidents. The objective is to limit impact and learn from incidents.

Business continuity and crisis management Organisations must ensure that critical services can continue in the event of disruptions. This includes backup strategies, contingency plans and recovery procedures.

Security in system development and maintenance Security must be considered throughout the entire lifecycle of IT systems – from design and development through to maintenance and updates.

Assessment of the effectiveness of security measures All measures must be evaluated regularly and adapted where necessary, for example through internal audits, external reviews or technical tests.

Cyber hygiene and training All employees should receive regular awareness training to anchor a basic security culture in the organisation. Simple measures such as strong passwords and phishing awareness are explicitly part of this.

Cryptography and encryption The protection of sensitive data through encryption technologies is strongly recommended – especially for data in transit and at rest.

Access management and personnel security Only authorised individuals should have access to sensitive systems. This includes background checks, role-based access control and clear procedures for role changes and leavers.

Authentication and communication security Article 21 calls for the use of modern authentication mechanisms, such as multi-factor authentication, and secure communication protocols.


Article 23: Incident Reporting Obligations

In addition to preventive security measures, NIS2 places strong emphasis on effective response capabilities. Article 23 obliges organisations to report significant security incidents to the competent authorities – quickly, in a structured manner and in line with defined procedures.

When must an incident be reported?

Any incident that has a significant impact on the provision of the affected services must be reported. Typical examples include:

  • Outages of critical systems

  • Data breaches involving sensitive information

  • Successful cyberattacks with major consequences

  • Long-lasting disruptions of services

Whether an incident is “significant” is assessed, among other factors, based on duration, geographic spread and extent of the disruption.

Timelines and reporting stages

NIS2 foresees a staged reporting process:

  • Early warning within 24 hours First high-level assessment of the incident, including whether it is suspected to result from unlawful or malicious action.

  • Incident notification within 72 hours More detailed information on the incident: affected systems, preliminary root cause analysis, measures taken and potential impact.

  • Final report within one month Comprehensive documentation of causes, consequences, final remediation measures and lessons learned.

Where must incidents be reported?

Reports must be submitted to the national competent authority or the relevant CSIRT (Computer Security Incident Response Team). In Germany, this is typically the Federal Office for Information Security (BSI) or another designated authority.

Why does this matter for organisations?

The reporting obligation ensures that threat situations are recognised and addressed early – but it also increases the operational pressure on organisations. A functioning incident response concept is therefore essential to be able to react within the strict timelines.


Practical Implementation of NIS2 in Organisations

At first glance, the requirements of NIS2 – especially Articles 21 and 23 – may appear complex and formalistic. In practice, however, they can be implemented step by step with a structured approach. The key is to integrate them into existing processes and systems rather than treating them in isolation.

1. Establish an ISMS as the foundation

A functioning Information Security Management System (ISMS) is the basis for complying with NIS2. It helps to capture risks, document measures and define responsibilities in a structured way. Organisations already working with ISO/IEC 27001 or the German BSI IT-Grundschutz have a considerable head start.

2. Document and prioritise security measures

Start by documenting all existing technical and organisational measures. Based on this, you can identify gaps – for example missing contingency plans, unclear roles or the absence of training concepts. Prioritising by risk helps you tackle the most important measures first.

3. Build incident response processes

To meet the requirements of Article 23, organisations need clear processes for handling and reporting security incidents, including:

  • Definition of when an incident is reportable

  • Designation of responsible roles (e.g. Incident Manager, CISO/ISB)

  • Checklists and templates for internal and external reporting

4. Engage and train staff

Technical controls alone are not sufficient – employee awareness is a critical success factor. Regular awareness training, phishing simulations and internal campaigns help to build a strong security culture.

5. Use tools and automation

Specialised ISMS and GRC tools can significantly simplify implementation – with modules for risk management, control tracking, role management and interfaces to technical systems. Automated detection, logging and documentation of incidents are becoming increasingly important.


Conclusion and Outlook on NIS2

With the NIS2 Directive, cybersecurity becomes a core element of corporate governance – not only for critical infrastructures, but for a wide range of organisations across Europe. Articles 21 and 23 form the core: they set binding expectations for technical and organisational security measures as well as for the handling and reporting of security incidents.

Organisations that proactively build structures, processes and clear responsibilities benefit twice: they achieve regulatory compliance and strengthen their resilience against cyber threats. Establishing an ISMS and robust reporting processes are key levers for a future-proof security strategy.

Looking ahead, NIS2 will not be the last regulatory wave. The ability to respond to change in a structured and integrated way will become a competitive differentiator – and information security a fixed component of modern corporate management.


NIS2 FAQ – Articles 21 and 23

Which organisations are in scope of the NIS2 Directive? All “essential” and “important entities” in sectors such as energy, transport, healthcare, public administration, digital services and others. The categorisation is based, among other factors, on size, sector and societal relevance.

What exactly must an organisation implement under Article 21? Article 21 requires comprehensive technical and organisational security measures – for example risk management, incident handling, access control, encryption, training and business continuity measures. These must be documented, reviewed regularly and continuously improved.

When exactly must a security incident be reported? An incident must be reported if it has a significant impact on the provision of the relevant services. An early warning is due within 24 hours of becoming aware, a more detailed notification within 72 hours and a final report within one month.

To whom must incidents be reported? Incidents must be reported to the competent national authority or CSIRT – in Germany typically the BSI or a designated state authority. Organisations should clearly define internally who is responsible for reporting and how the process works.

How can I prepare my organisation for NIS2? By building an ISMS, performing a structured risk analysis, training staff, documenting existing controls and, where helpful, using specialised ISMS/GRC tools to support implementation and ongoing compliance.

fuentis Team

fuentis Team

Team

The fuentis team brings together specialists in information security, data protection and risk management — supporting organizations with reliable, audit-ready solutions.

From reading to doing: your ISMS with fuentis

ISO 27001, BSI IT-Grundschutz, TISAX and NIS2 in one platform – the free/Basic plan is €0 for 12 months.