NIS2 / Full version
Article 21
Article 21 is the measures paragraph, the minimum list, and the DNS provider sentence in paragraph 5. It does not name SPF, DKIM, or DMARC.
Paragraph 1
Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services.
The measures have to take account of the state of the art, relevant European and international standards where applicable, and the cost of implementation. Proportionality takes account of exposure, size, and the likelihood and severity of incidents, including societal and economic impact.
The minimum list
Paragraph 2 requires an all-hazards approach and at least these: policies on risk analysis and information system security; incident handling; business continuity, including backup management, disaster recovery, and crisis management; supply chain security; security in acquisition, development, and maintenance, including vulnerability handling and disclosure; policies to assess whether the measures work; basic cyber hygiene and cybersecurity training; policies on cryptography and, where appropriate, encryption; human resources security, access control, and asset management; and the use of multi-factor or continuous authentication, secured voice, video, and text communications, and secured emergency communications, where appropriate.
Mail authentication is not one of those points. Cryptography and encryption are. Supply chain security is. An operator can use SPF, DKIM, or DMARC as a way of meeting a measure. The article does not require those records by name.
DNS service providers
Paragraph 5 says that by 17 October 2024 the Commission shall adopt implementing acts laying down the technical and methodological requirements of the paragraph 2 measures for a listed set of providers. The list includes DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online marketplaces, online search engines, and social networking services platforms, and trust service providers.
That date is the deadline written in the directive. This page does not say whether a given implementing act was adopted.