NIS2 / Full version
NIS2
NIS2 is Directive (EU) 2022/2555. Article 21 is the risk-management duty. Article 23 is the incident report. Neither article names SPF, DKIM, or DMARC.
The two obligations
Article 21 is the risk-management duty for essential and important entities. Article 23 is how a significant incident is reported, and on what clocks.
Neither article names an email authentication record. A page on this site that treats DMARC as a NIS2 requirement would be adding a sentence the directive does not contain.
Where DNS shows up
DNS shows up in scope and in the implementing-act list, not as a mail record. Article 2 and Article 3 name DNS service providers. Article 21(5) names them again, with TLD name registries and a longer list of provider types, as subjects of Commission implementing acts.
The short pages on scope and on Article 21 quote those provisions. This page is only the map.