NIS2 · the ten measures

The ten NIS2 risk-management measures

A control you cannot evidence is, to a supervisor, a control you do not have.

Extract from the NIS2 note · reviewed 28 August 2026 · primary sources

The obligation

The ten measures, and what evidence each one really means

The law sets a minimum list of ten risk-management measures. In the organisations we work with, documents for all ten usually exist. Evidence for all ten usually does not, and the distance between those two states is the compliance problem in its entirety.

  1. Risk analysis and information system security policies: dated, approved, and demonstrably connected to the risks you actually recorded.
  2. Incident handling: a procedure that has been used, with the record of a real or exercised incident behind it.
  3. Business continuity, backup management, disaster recovery and crisis management: tested, with the test report and what failed in it.
  4. Supply-chain security: the register of who you depend on, maintained rather than compiled once.
  5. Security in acquisition, development and maintenance, including vulnerability handling and disclosure.
  6. Policies to assess the effectiveness of the measures: the one most often missing, because it requires measuring yourself.
  7. Cyber hygiene practices and training: attendance and content, not a completion percentage.
  8. Cryptography and encryption policies, and the configuration that proves the policy is what is deployed.
  9. Human resources security, access control policies and asset management.
  10. Multi-factor authentication and secured communications, including the exceptions, and who approved each one.

Every one of the ten needs a named owner and a date, rather than a department.

Where this comes from

This page is an extract, and the note is the source

Every line above is taken word for word from NIS2 in Luxembourg, which carries the scope tests, the reporting clocks, the sanctions, and the primary sources these measures come from. Nothing here is behind a form and nothing is collected from you; the page exists so the list can be printed and taken into a meeting.

This page is a practitioner summary, not legal advice. We do not advise on your legal position, we do not determine your category for you as a matter of law, and we do not represent you before the ILR, the CSSF or any other authority.

Regulation notes

Or start from what is on your desk.

The practitioner pages: dated, sourced, and written for engineers and risk officers rather than for search engines.