NIS2Art. 21(2)(f)voice-validated

NIS2 Art21f: Art. 21(2)(f)

Network and Information Security Directive 2 (EU 2022/2555)

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Essential and important entities must establish policies and procedures to assess the effectiveness of cybersecurity risk-management measures. This includes regular testing, auditing, and review of the security measures to ensure they remain effective against evolving threats.

ATT&CK techniques this article tests · 15

TechniqueWhy it mapsConfidence
T11901. Ineffective security measures, not regularly tested as per NIS2 Art. 21(2)(f), allow attackers to exploit public-facing applications. 2. Regular testing identifies vulnerabilities before exploitation.
90%
T15661. Ineffective security awareness training or email filtering, not reviewed under NIS2 Art. 21(2)(f), enables successful phishing. 2. Auditing and review ensure controls mitigate social engineering.
85%
T10781. Compromised or misused valid accounts result from ineffective access controls, not regularly tested as per NIS2 Art. 21(2)(f). 2. Auditing user accounts and permissions prevents this.
90%
T1547.0011. Ineffective endpoint security or configuration management, not regularly reviewed under NIS2 Art. 21(2)(f), allows persistence via autostart execution. 2. Regular testing verifies system hardening.
80%
T10681. Exploitation for privilege escalation occurs when vulnerability management and patching are ineffective, contrary to NIS2 Art. 21(2)(f). 2. Regular testing identifies and remediates such vulnerabilities.
90%
T10551. Process injection succeeds due to ineffective endpoint protection or memory safeguards, not regularly reviewed under NIS2 Art. 21(2)(f). 2. Auditing and testing validate these protective measures.
80%
T10271. Obfuscated files bypass detection when security measures are ineffective and not regularly tested, as required by NIS2 Art. 21(2)(f). 2. Testing ensures detection mechanisms are robust.
85%
T1070.0041. Indicator removal on host succeeds when logging and monitoring are ineffective, not regularly reviewed under NIS2 Art. 21(2)(f). 2. Auditing ensures forensic readiness and log integrity.
80%
T10031. OS credential dumping occurs due to ineffective endpoint security or memory protection, not regularly tested as per NIS2 Art. 21(2)(f). 2. Regular security assessments verify credential protection.
90%
T10871. Account discovery is facilitated by ineffective network segmentation or access controls, not regularly reviewed under NIS2 Art. 21(2)(f). 2. Auditing ensures proper account and network isolation.
85%
T10461. Network share discovery indicates ineffective network monitoring or segmentation, not regularly tested as per NIS2 Art. 21(2)(f). 2. Regular reviews validate network access policies.
80%
T1021.0011. Remote Desktop Protocol misuse occurs when remote access controls are ineffective, not regularly managed and reviewed under NIS2 Art. 21(2)(f). 2. Auditing ensures secure remote access configurations.
85%
T10051. Data from local systems is collected due to ineffective data loss prevention or endpoint monitoring, not regularly tested as per NIS2 Art. 21(2)(f). 2. Regular testing validates data protection controls.
85%
T1071.0011. Command and control via web protocols succeeds when network egress filtering and monitoring are ineffective, not regularly reviewed under NIS2 Art. 21(2)(f). 2. Auditing ensures robust network traffic controls.
80%
T10411. Exfiltration over C2 channels occurs due to ineffective data exfiltration controls and monitoring, not regularly tested as per NIS2 Art. 21(2)(f). 2. Regular testing verifies data outflow prevention.
85%

Defending mitigations · 7

MitigationWhat it doesConfidence
M10131. Application Developer Guidance ensures secure coding practices. 2. NIS2 Art. 21(2)(f) mandates regular review of such measures to reduce vulnerabilities found during testing.
90%
M10151. Active Directory Configuration reduces attack surface for credential access. 2. NIS2 Art. 21(2)(f) requires auditing these configurations to verify their effectiveness against evolving threats.
85%
M10171. User Account Management involves regular review of permissions. 2. This directly aligns with the NIS2 Art. 21(2)(f) requirement for regular review and auditing of security measures.
90%
M10211. Audit directly corresponds to the 'auditing' requirement in NIS2 Art. 21(2)(f). 2. Audits assess the effectiveness of cybersecurity risk-management measures.
100%
M10301. Network Segmentation limits lateral movement. 2. NIS2 Art. 21(2)(f) mandates regular testing of network segmentation effectiveness to ensure it remains robust.
90%
M10351. Limiting Access to Resource Over Network is a core access control. 2. NIS2 Art. 21(2)(f) requires regular review and testing of these controls to prevent unauthorized access.
85%
M10511. Software Configuration ensures secure system baselines. 2. NIS2 Art. 21(2)(f) mandates regular review and testing of these configurations to maintain security posture.
85%

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-2001. Exposure of Sensitive Information results from ineffective security measures. 2. NIS2 Art. 21(2)(f) requires regular testing and review to prevent such exposures.
90%
CWE-2871. Improper Authentication allows unauthorized access. 2. NIS2 Art. 21(2)(f) mandates regular auditing and testing of authentication mechanisms to ensure their effectiveness.
85%
CWE-2691. Improper Privilege Management leads to privilege escalation. 2. NIS2 Art. 21(2)(f) requires regular review of privilege controls to prevent this weakness.
85%
CWE-7981. Use of Hard-coded Credentials creates exploitable vulnerabilities. 2. NIS2 Art. 21(2)(f) requires regular testing and auditing to uncover and remediate such weaknesses.
80%
CWE-7321. Incorrect Permission Assignment for Critical Resource undermines access control. 2. NIS2 Art. 21(2)(f) mandates regular review and testing of permissions to ensure proper access.
90%
CWE-221. Path Traversal vulnerabilities allow unauthorized file access. 2. NIS2 Art. 21(2)(f) requires regular testing of applications to identify and fix such flaws.
80%
CWE-6681. Exposure of Resource to Wrong Sphere indicates network segmentation or access control failures. 2. NIS2 Art. 21(2)(f) requires regular testing and review to prevent this exposure.
85%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0200 compute · voice-rubric self-validated