Skip to content
OnTrackio

NIS2

The Article 21(2) checklist, honestly labelled

NIS2 Article 21(2) lists ten risk-management measures. An IT asset management platform can produce native audit evidence for three of them, a necessary baseline for four, a proxy metric for two, and nothing useful for one. This page goes sub-control by sub-control: what the law asks, what OnTrackio contributes, and exactly what you still have to produce yourself.

Last updated 2026-07-18

All ten measures at a glance

Measure Article 21(2) area ITAM evidence class
21(2)(a) Risk analysis and information system security policies ITAM hygiene floor
21(2)(b) Incident handling ITAM-native evidence
21(2)(c) Business continuity and crisis management Outside ITAM scope
21(2)(d) Supply chain security ITAM hygiene floor
21(2)(e) Security in acquisition, development and maintenance ITAM proxy
21(2)(f) Effectiveness assessment ITAM-native evidence
21(2)(g) Cyber hygiene and training ITAM hygiene floor
21(2)(h) Cryptography ITAM proxy
21(2)(i) HR security, access control and asset management ITAM hygiene floor
21(2)(j) MFA, continuous authentication and secure communications ITAM-native evidence
ITAM-native evidence

OnTrackio produces full evidence for this slice directly.

ITAM hygiene floor

OnTrackio contributes a necessary baseline; you produce the rest.

ITAM proxy

OnTrackio contributes a coverage metric, not direct control evidence.

Outside ITAM scope

This evidence has to come from your own programme.

Read this first. No tool makes you NIS2 compliant, including ours. These labels are the same evidence-class taxonomy the product prints in its evidence pack, so what you show an auditor never claims more than it demonstrates (the methodology is public: how we label evidence). The legal detail behind each sub-control lives in the evidence-requirements guide.

21(2)(a)

Risk analysis and information system security policies

ITAM hygiene floor

What the law asks: A risk analysis grounded in what you actually run, plus board-approved security policies.

What OnTrackio contributes: The asset register with categorization and serial tracking: the population a real risk analysis starts from.

What you still produce yourself:

  • A risk register linking assets to threats (ISO/IEC 27005 or a sectoral methodology)
  • A risk treatment plan with owners, dates, and prioritized mitigations
  • Management-body acceptance of residual risk, in writing
  • An information-system security policy approved at board level
21(2)(b)

Incident handling

ITAM-native evidence

What the law asks: Incident handling internally, and Article 23 notifications to your CSIRT on 24-hour, 72-hour, and one-month clocks.

What OnTrackio contributes: The regulator-facing half natively: an Article 23 workflow with the 24h early warning, 72h notification, and final-report deadlines computed from detection time, plus a structured CSIRT mailable.

What you still produce yourself:

  • An internal incident-response policy and runbooks
  • Detection infrastructure (SIEM or log management)
  • A root-cause analysis template and post-incident review process
21(2)(c)

Business continuity and crisis management

Outside ITAM scope

What the law asks: Continuity of YOUR operations: backups, disaster recovery, and crisis management for the systems you run.

What OnTrackio contributes: Honestly: little. Our own SaaS backups protect the register itself, not your production systems. No ITAM tool can evidence your BCP.

What you still produce yourself:

  • A business continuity plan covering your production systems (ERP, MES, OT)
  • Disaster-recovery test reports, at least annual
  • A crisis-management playbook with a communications plan
  • Backup verification records for your non-SaaS systems
21(2)(d)

Supply chain security

ITAM hygiene floor

What the law asks: A supplier security programme: policy, selection criteria, contract clauses, and per-supplier risk assessment (Article 21(3)).

What OnTrackio contributes: The vendor inventory: every software and hardware supplier with active licence counts, which is the population your supplier risk assessment covers.

What you still produce yourself:

  • A supply-chain security policy with vendor selection criteria (CIR Annex 5.1)
  • The eight mandatory contract-clause areas, including audit rights and incident notification
  • A per-vendor risk assessment and classification
  • Article 21(3) vulnerability assessment per direct supplier
21(2)(e)

Security in acquisition, development and maintenance

ITAM proxy

What the law asks: Secure development, change management, vulnerability handling, patching, and security testing across the lifecycle.

What OnTrackio contributes: A procurement-record proxy: purchase dates, invoices, transfer agreements at handover, wipe certificates at disposal. Useful records, but not the SDLC and vulnerability-management evidence the control is really about.

What you still produce yourself:

  • SDLC documentation with secure-development practices (or a written statement that you do not develop in-house)
  • A secure-baseline registry for the workstation and server estate
  • A vulnerability-management programme with prioritized remediation SLAs
  • An annual penetration test report with a remediation tracker
21(2)(f)

Effectiveness assessment

ITAM-native evidence

What the law asks: Policies and procedures to assess whether your risk-management measures actually work: measurable indicators, not assertions.

What OnTrackio contributes: A native implementation of the CIR section 7 requirements: a documented policy with a tamper check, cadenced metric snapshots computed from live asset and user data, and a quarterly review workflow with management sign-off.

What you still produce yourself:

  • KPI coverage for the controls outside ITAM scope (patch latency, training completion, BCP test results)
  • Your own effectiveness-assessment policy text; we provide the workflow and the tamper-checked storage
21(2)(g)

Cyber hygiene and training

ITAM hygiene floor

What the law asks: Basic hygiene practices plus a real awareness-training programme with records.

What OnTrackio contributes: The hygiene half of the numbers: MFA and passkey enrolment percentages and the org-wide enforcement policy state. MFA is one hygiene practice; it is not a training programme.

What you still produce yourself:

  • An awareness-training programme with an annual delivery cadence
  • Completion records: sign-in sheets or certificates (the ENISA evidence list)
  • Phishing-simulation results over time
  • Board-member training records (Article 20(2) makes management personally liable)
21(2)(h)

Cryptography

ITAM proxy

What the law asks: A cryptography policy and key management covering your estate, not just your vendors' platforms.

What OnTrackio contributes: A coverage proxy: the share of endpoints reporting through the agent. Knowing 80 percent of endpoints are managed says nothing about whether their disks are encrypted, so the evidence pack never grades this above partial.

What you still produce yourself:

  • A cryptography policy covering the CIR Annex 9.2 sub-points, from algorithm choice to key destruction
  • An encryption-status inventory: BitLocker, FileVault, removable media, file shares
  • A key-management procedure (KMS, HSM, or PKI as applicable)
21(2)(i)

HR security, access control and asset management

ITAM hygiene floor

What the law asks: Three areas in one clause: personnel security, access-control policies, and asset management.

What OnTrackio contributes: The asset-management third is where we go deepest: the inventory itself, plus the metric assessors reach for before anything else, offboarded people still holding assets. Role-based access and scoped, expiring API tokens cover our own surface.

What you still produce yourself:

  • An access-control policy and a joiner-mover-leaver workflow with documented sign-off
  • A privileged-account management procedure
  • Background-verification records for security-relevant roles
  • Asset handling and removable-media policies
21(2)(j)

MFA, continuous authentication and secure communications

ITAM-native evidence

What the law asks: Multi-factor or continuous authentication, and secured emergency communications for when the primary channel is down.

What OnTrackio contributes: The MFA half natively: TOTP and phishing-resistant passkey enrolment percentages, org-wide policy enforcement across password, Google, Microsoft, and SAML sign-in paths, and the agent's signed request protocol.

What you still produce yourself:

  • An out-of-band crisis communications channel that works when email and chat are compromised
  • The secure emergency-communications procedure, documented in your BCP

Working the asset-register rows by hand first? Start from the ungated asset register template (XLSX), mapped to the four adjectives in Implementing Regulation 2024/2690. US-framework readers: the same register renders as SOC 2 evidence via the built-in crosswalk.

Frequently asked questions

Does completing this checklist make us NIS2 compliant?

No. Compliance is a determination against your national transposition law, made by you and, ultimately, your supervisory authority. This checklist maps which Article 21(2) evidence an IT asset management platform can produce and which evidence has to come from your own programme. That split is the point: only three sub-controls can get native ITAM evidence; the rest need your own programme to different degrees, and the checklist shows exactly where.

Why do you label some of your own coverage as a proxy or outside scope?

Because an assessor will. Agent coverage is not encryption status, purchase records are not an SDLC, and a vendor list is not a supplier risk assessment. Labelling those honestly means the evidence pack you hand an auditor never claims more than it shows, which is exactly what keeps it usable as evidence.

What do the four coverage classes mean?

ITAM-native evidence: the platform produces the full evidence for that slice directly. ITAM hygiene floor: the platform contributes a necessary baseline, like the asset register a risk analysis starts from, and you produce the control itself. ITAM proxy: the platform contributes a related metric that does not measure the control directly. Outside ITAM scope: no asset platform can evidence it; it comes from your own programme or a GRC tool.

Where do these labels come from?

They are the same evidence-class taxonomy the product prints in its NIS2 evidence pack, applied per sub-control against Implementing Regulation (EU) 2024/2690 and ENISA's Technical Implementation Guidance. This page and the product are kept in sync deliberately.

Every label on this page comes from the live evidence pack

Book a demo and we will generate the Article 21 pack from a real workspace while you watch, then trace any label on this page back to the data behind it. Bring your supervisory authority's question list.