Law / European Union

Commission Implementing Regulation (EU) 2024/2690, Technical and Methodological Requirements for NIS2 Risk-Management Measures

Regulation (EU) 2024/2690, Art. 2 and Annex

In force since .

A sector security regimes rule binding public and private bodies.

Obligation class
Security, Governance

As of .

What it requires

  • This duty reaches you if you declare that you are an essential or important entity under Article 3 of Directive (EU) 2022/2555 and provide a service Article 1 names: a DNS service provider, top-level domain (TLD) name registry, cloud computing service provider, data centre service provider, content delivery network provider, managed service provider, managed security service provider, provider of an online marketplace, online search engine or social networking services platform, or trust service provider. Under Article 2 of that Directive you are in scope if you are a medium-sized enterprise or larger, or, whatever your size, if you are a trust service provider, a TLD name registry or a DNS service provider, or if Article 2(2), points (b) to (e), applies to you.
  • Ensure a level of security of your network and information systems appropriate to the risks posed when you implement the requirements, taking due account of your exposure to risks, your size, the likelihood of occurrence of incidents and their severity, including their societal and economic impact (Article 2(2)).
  • Where the Annex applies a requirement where appropriate, where applicable or to the extent feasible and you consider it not appropriate, not applicable or not feasible for you to apply it, document your reasoning in a comprehensible manner (Article 2(2)).
  • Maintain a policy on the security of network and information systems that your management bodies approve and review at least annually and when significant incidents or significant changes to operations or risks occur, and have at least one person report directly to your management bodies on network and information system security (Annex points 1.1.1(k), 1.1.2 and 1.2.3).
  • Establish a risk management framework, perform and document risk assessments, and establish, implement and monitor a risk treatment plan, reviewing the assessment results and the plan at planned intervals and at least annually (points 2.1.1 and 2.1.4).
  • Establish and implement an incident handling policy, monitor and log activity on your network and information systems to detect events that could be incidents, assess suspicious events to determine whether they are incidents, and assess the existence of recurring incidents under Article 4 on a quarterly basis (points 3.1.1, 3.2.1, 3.4.1 and 3.4.2(b)).
  • Establish communication plans and procedures with your CSIRT or, where applicable, your competent authority for incident notification (point 3.5.3(a)).
  • Lay down and maintain a business continuity and disaster recovery plan, carry out a business impact analysis, and maintain backup copies of data (points 4.1.1, 4.1.3 and 4.2.1).
  • Establish a supply chain security policy that governs your relations with your direct suppliers and service providers, and ensure, where appropriate, that your contracts with them specify an obligation to notify you without undue delay of incidents that present a risk to the security of your network and information systems (points 5.1.1 and 5.1.4(d)).
  • Before you develop a network and information system, including software, lay down rules for secure development and apply them to in-house and outsourced development (point 6.2.1).
  • Apply security patches within a reasonable time after they become available and test them before applying them in production systems, unless you document and substantiate a decision that the disadvantages of applying a patch outweigh the cybersecurity benefits (points 6.6.1 and 6.6.2).
  • Address without undue delay the vulnerabilities you identify as critical to your operations, and lay down a procedure for disclosing vulnerabilities in accordance with the applicable national coordinated vulnerability disclosure policy (points 6.10.2(c) and (e)).
  • Ensure, where appropriate and in accordance with the classification of the asset to be accessed, that users are authenticated by multiple authentication factors or continuous authentication mechanisms (point 11.7.1).
  • Establish a policy and procedures to assess whether your cybersecurity risk-management measures are effectively implemented and maintained (point 7.1), offer your employees an awareness raising programme and give those whose roles require security skills regular training (points 8.1.2 and 8.2.1), and apply the Annex's requirements on cryptography, human resources security, access control, asset management, and environmental and physical security (points 9 to 13).

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

Article 34(4) of Directive (EU) 2022/2555: where an essential entity infringes Article 21 or 23, it is subject to an administrative fine of a maximum of at least EUR 10,000,000 or at least 2 percent of total worldwide annual turnover, whichever is higher. Article 34(5) sets a lower tier for an important entity, a maximum of at least EUR 7,000,000 or at least 1.4 percent of turnover, whichever is higher. The fine tiers that apply to an infringement of the measures this Regulation specifies under Article 21(2) are those of Article 34. The figures are the floor each Member State's own transposing law must set as its statutory maximum, not a cap the Union applies directly.

Rule
Higher of
As of
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The competent authority designated or established by each EU Member State under Article 8 of Directive (EU) 2022/2555, which supervises compliance and applies the Chapter VII enforcement measures, with coordination at Union level through the NIS Cooperation Group and the CSIRTs network.

Settledness

ENISA's guidance is advisory and not legally binding, and Member States keep the freedom to determine their approach to the supervision of the requirements.

As of
Guidance link
https://www.enisa.europa.eu/sites/default/files/2025-06/ENISA_Technical_implementation_guidance_on_cybersecurity_risk_management_measures_version_1.0.pdf
Guidance body
European Union Agency for Cybersecurity (ENISA), Technical Implementation Guidance on Commission Implementing Regulation (EU) 2024/2690, version 1.0 of June 2025

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 2(1) sets out, in the Annex, the technical and methodological requirements of the cybersecurity risk-management measures referred to in Article 21(2), points (a) to (j), of Directive (EU) 2022/2555.

Article 1 lays down the requirements with regard to DNS service providers, top-level domain (TLD) name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online marketplaces, online search engines and social networking services platforms, and trust service providers, which it calls the relevant entities.

Article 2(2) requires the relevant entities to ensure a level of security of network and information systems appropriate to the risks posed when they implement the requirements. In doing so they take due account of their exposure to risks, their size, the likelihood of occurrence of incidents and their severity, including their societal and economic impact.

Where the Annex applies a requirement where appropriate, where applicable or to the extent feasible, and an entity considers it not appropriate, not applicable or not feasible to apply it, the entity must document its reasoning in a comprehensible manner.

The Annex has thirteen sections, covering the security policy, risk management, incident handling, business continuity and crisis management, supply chain security, security in the acquisition, development and maintenance of network and information systems, assessment of the effectiveness of the measures, cyber hygiene and security training, cryptography, human resources security, access control, asset management, and environmental and physical security.

Point 6.2.1 requires an entity, before it develops a network and information system including software, to lay down rules for secure development and to apply them to in-house and outsourced development. Point 6.6.1 requires procedures ensuring that security patches are applied within a reasonable time after they become available.

Point 6.6.2 lets an entity choose not to apply a security patch when the disadvantages of applying it outweigh the cybersecurity benefits, provided the entity documents and substantiates its reasons. Point 6.10.2 requires an entity to lay down a procedure for disclosing vulnerabilities in accordance with the applicable national coordinated vulnerability disclosure policy.

Point 11.7.1 requires an entity to ensure, where appropriate and in accordance with the classification of the asset to be accessed, that users are authenticated by multiple authentication factors or continuous authentication mechanisms. Point 3.4.2 requires an entity to assess the existence of recurring incidents under Article 4 on a quarterly basis.

When LexLint raises it

When your app profile says your app operates a social platform or runs an essential service.

Back to the example  ·  Lint your app