NIS2Art. 21(2)(a)voice-validated

NIS2 Art21a: Art. 21(2)(a)

Network and Information Security Directive 2 (EU 2022/2555)

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Essential and important entities must take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems, including policies on risk analysis and information system security as the foundation of the security management programme.

ATT&CK techniques this article tests · 15

TechniqueWhy it mapsConfidence
T10781. Art. 21(2)(a) mandates policies for information system security. Proper account management and authentication controls reduce the risk of valid accounts being compromised and used by attackers.
80%
T11332. Art. 21(2)(a) requires technical measures for network security. Secure configuration and monitoring of external remote services prevent unauthorized access, a key risk.
70%
T15473. Art. 21(2)(a) demands security management programs. Policies on system configuration and integrity checks mitigate persistence mechanisms that modify boot or logon processes.
70%
T10684. Art. 21(2)(a) specifies risk management for information systems. Identifying and patching vulnerabilities, alongside least privilege, reduces opportunities for privilege escalation.
80%
T10275. Art. 21(2)(a) requires technical measures. Robust security controls, including endpoint detection and network monitoring, can detect and prevent obfuscated malware execution.
70%
T10366. Art. 21(2)(a) mandates operational measures. Strict change management and integrity monitoring help identify masquerading attempts by attackers.
60%
T10037. Art. 21(2)(a) requires information system security policies. Strong credential protection, including hashing and multi-factor authentication, directly counters credential dumping.
90%
T10568. Art. 21(2)(a) demands technical and operational measures. Input capture prevention, through secure UI design and anti-keylogging software, protects sensitive data.
80%
T10469. Art. 21(2)(a) requires risk analysis. Network segmentation and intrusion detection systems limit and detect unauthorized network scanning activities.
70%
T108710. Art. 21(2)(a) mandates security management. Least privilege principles and regular auditing of user accounts restrict account discovery and misuse.
80%
T102111. Art. 21(2)(a) requires technical measures for network security. Secure remote access policies and network segmentation limit lateral movement via remote services.
70%
T100512. Art. 21(2)(a) requires policies on information system security. Data loss prevention and access controls prevent unauthorized collection of data from local systems.
80%
T107113. Art. 21(2)(a) demands technical measures. Network monitoring and egress filtering detect and block command and control communications over application layer protocols.
70%
T104114. Art. 21(2)(a) requires risk management and security policies. Data loss prevention, network monitoring, and egress filtering prevent exfiltration over C2 channels.
80%
T148615. Art. 21(2)(a) mandates measures to manage risks to network and information systems. Robust backup strategies, incident response plans, and data integrity controls mitigate the impact of data encryption.
90%

Defending mitigations · 7

MitigationWhat it doesConfidence
M10131. Art. 21(2)(a) requires appropriate technical measures. Multi-factor authentication significantly strengthens access controls, reducing the risk of unauthorized access via compromised credentials.
90%
M10152. Art. 21(2)(a) mandates technical and operational measures. Secure software configurations prevent exploitation of vulnerabilities and reduce attack surface, aligning with risk management.
80%
M10163. Art. 21(2)(a) requires information system security policies. Comprehensive auditing and logging provide visibility into system activities, crucial for detecting and responding to security incidents.
80%
M10174. Art. 21(2)(a) demands operational measures. Effective user account management, including least privilege and regular reviews, minimizes the attack surface related to user identities.
90%
M10275. Art. 21(2)(a) requires robust security management. Strict privileged account management, including segregation and monitoring, directly addresses a critical risk vector for attackers.
90%
M10306. Art. 21(2)(a) mandates technical measures for network security. Network segmentation limits the scope of breaches and lateral movement, containing potential damage.
80%
M10357. Art. 21(2)(a) requires technical measures. Blocking uncommon ports reduces the attack surface and prevents unauthorized communication channels, enhancing network security.
70%

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-2001. Art. 21(2)(a) requires measures to manage risks to information systems. Inadequate protection of sensitive information directly violates security principles and increases risk.
90%
CWE-2872. Art. 21(2)(a) mandates information system security policies. Flawed authentication mechanisms are a primary vector for unauthorized access, necessitating robust controls.
90%
CWE-2693. Art. 21(2)(a) requires operational measures. Poor privilege management allows attackers to gain elevated access, undermining the security of information systems.
80%
CWE-7984. Art. 21(2)(a) demands appropriate technical measures. Hard-coded credentials bypass secure authentication processes, creating easily exploitable backdoors.
80%
CWE-3265. Art. 21(2)(a) requires appropriate technical measures. Weak encryption strength fails to adequately protect data confidentiality and integrity, increasing data exposure risks.
70%
CWE-5026. Art. 21(2)(a) requires technical measures. Deserialization of untrusted data can lead to remote code execution, a critical vulnerability in information systems.
70%
CWE-6687. Art. 21(2)(a) requires technical and operational measures. Exposing resources to an incorrect security sphere allows unauthorized access or manipulation, increasing system risk.
70%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0190 compute · voice-rubric self-validated