Skip to content

NIS2

NIS2 Article 21

Article 21 requires essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems they use, and to prevent or minimise the impact of incidents.

The minimum list is points (a) to (j), from risk-analysis policies through multi-factor authentication and secured communications. Paragraph 5 tells the Commission to adopt implementing acts for a named set of providers, including DNS service providers and TLD name registries, by 17 October 2024. The article does not name SPF, DKIM, or DMARC.