Chapter IVCYBERSECURITY RISK-MANAGEMENT MEASURES AND REPORTING OBLIGATIONS
- Article 20Governance
1. Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with…
- Article 21Cybersecurity risk-management measures
1. Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of…
- Article 22Union level coordinated security risk assessments of critical supply chains
1. The Cooperation Group, in cooperation with the Commission and ENISA, may carry out coordinated security risk assessments of specific critical ICT services, ICT systems or ICT products…
- Article 23Reporting obligations
1. Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4…
- Article 24Use of European cybersecurity certification schemes
1. In order to demonstrate compliance with particular requirements of Article 21 , Member States may require essential and important entities to use particular ICT products, ICT services…
- Article 25Standardisation
1. In order to promote the convergent implementation of Article 21(1) and (2) , Member States shall, without imposing or discriminating in favour of the use of a…
https://nis2.digiphile.law/chapter/chapter-IV.html
Text as at 19 September 2026.
This is an unofficial convenience version of the EU NIS2 Directive (Directive (EU) 2022/2555). It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.