NIS2Art. 21(2)(g)voice-validated

NIS2 Art21g: Art. 21(2)(g)

Network and Information Security Directive 2 (EU 2022/2555)

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Essential and important entities must implement basic cyber hygiene practices and cybersecurity training. This includes user awareness programs, secure password practices, multi-factor authentication where appropriate, and regular training on emerging threats and proper security behavior.

ATT&CK techniques this article tests · 15

TechniqueWhy it mapsConfidence
T15661. User awareness programs and regular training, as mandated by Art. 21(2)(g), directly reduce the success rate of phishing attempts by educating users on identifying malicious communications.
90%
T11331. Multi-factor authentication and secure password practices, required by Art. 21(2)(g), significantly harden external remote services against unauthorized access.
80%
T10781. Secure password practices and multi-factor authentication, per Art. 21(2)(g), directly prevent unauthorized use of valid accounts by adversaries.
90%
T10981. Secure password practices and MFA, as specified in Art. 21(2)(g), make it substantially more difficult for adversaries to manipulate or compromise accounts.
80%
T11101. Multi-factor authentication and secure password practices, mandated by Art. 21(2)(g), directly mitigate brute force attacks by increasing credential complexity and requiring additional verification.
90%
T10031. Basic cyber hygiene and user awareness, as per Art. 21(2)(g), reduce the likelihood of initial compromise, thereby limiting opportunities for OS credential dumping.
70%
T15391. User awareness programs, outlined in Art. 21(2)(g), educate users on avoiding social engineering tactics that lead to session cookie theft.
70%
T10271. Regular training on emerging threats and proper security behavior, as per Art. 21(2)(g), enhances user ability to identify and avoid obfuscated malicious content.
70%
T10871. Secure password practices and MFA, required by Art. 21(2)(g), limit the utility of discovered accounts by making them harder to compromise.
70%
T10211. Multi-factor authentication and secure password practices, specified in Art. 21(2)(g), protect remote services from unauthorized access, hindering lateral movement.
80%
T10051. User awareness programs and proper security behavior, as per Art. 21(2)(g), reduce the risk of users inadvertently exposing or collecting sensitive data for adversaries.
70%
T11051. User awareness and training on proper security behavior, mandated by Art. 21(2)(g), help prevent users from executing or allowing ingress of malicious tools.
70%
T10411. General cyber hygiene and user awareness, as per Art. 21(2)(g), contribute to a more secure environment, making it harder for adversaries to establish and use C2 channels for exfiltration.
60%
T14851. Comprehensive basic cyber hygiene practices, including secure passwords and MFA from Art. 21(2)(g), reduce the overall attack surface and likelihood of successful attacks leading to data destruction.
60%
T10591. User awareness and training on proper security behavior, as per Art. 21(2)(g), help users identify and avoid executing malicious scripts or commands.
70%

Defending mitigations · 6

MitigationWhat it doesConfidence
M10321. Art. 21(2)(g) explicitly requires the implementation of 'multi-factor authentication where appropriate,' directly addressing this mitigation.
100%
M10271. Art. 21(2)(g) explicitly mandates 'secure password practices,' directly aligning with the establishment and enforcement of password policies.
100%
M10171. Art. 21(2)(g) explicitly requires 'user awareness programs' and 'regular training on emerging threats and proper security behavior,' directly implementing user training.
100%
M10381. Secure password practices and multi-factor authentication, as per Art. 21(2)(g), are fundamental components of effective user account management, ensuring secure access.
90%
M10401. User awareness programs and training on emerging threats, as specified in Art. 21(2)(g), enhance the effectiveness of antivirus/antimalware by reducing user-initiated infections.
70%
M10351. Secure password practices and multi-factor authentication, required by Art. 21(2)(g), are critical for limiting access to resources to authorized individuals.
80%

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-5211. Art. 21(2)(g)'s requirement for 'secure password practices' directly addresses and mitigates the weakness of weak password requirements.
100%
CWE-2871. The mandate for 'multi-factor authentication' and 'secure password practices' in Art. 21(2)(g) directly counters improper authentication vulnerabilities.
100%
CWE-3071. Secure password practices and multi-factor authentication, as per Art. 21(2)(g), significantly reduce the success of excessive authentication attempts like brute force attacks.
90%
CWE-2001. 'User awareness programs' and 'proper security behavior' training, as required by Art. 21(2)(g), aim to prevent the exposure of sensitive information by users.
80%
CWE-7981. 'Secure password practices,' as mandated by Art. 21(2)(g), discourage the use of hard-coded credentials by promoting proper credential management.
70%
CWE-6011. 'User awareness programs' and 'regular training on emerging threats,' specified in Art. 21(2)(g), help users identify and avoid malicious open redirects used in phishing.
70%
CWE-3061. 'Multi-factor authentication' and 'secure password practices,' as per Art. 21(2)(g), ensure that critical functions are protected by robust authentication mechanisms.
80%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0187 compute · voice-rubric self-validated