21(2)(a)
Risk analysis and information system security policies
ITAM hygiene floor What the law asks: A risk analysis grounded in what you actually run, plus board-approved security policies.
What OnTrackio contributes: The asset register with categorization and serial tracking: the population a real risk analysis starts from.
What you still produce yourself:
- A risk register linking assets to threats (ISO/IEC 27005 or a sectoral methodology)
- A risk treatment plan with owners, dates, and prioritized mitigations
- Management-body acceptance of residual risk, in writing
- An information-system security policy approved at board level
21(2)(b)
Incident handling
ITAM-native evidence What the law asks: Incident handling internally, and Article 23 notifications to your CSIRT on 24-hour, 72-hour, and one-month clocks.
What OnTrackio contributes: The regulator-facing half natively: an Article 23 workflow with the 24h early warning, 72h notification, and final-report deadlines computed from detection time, plus a structured CSIRT mailable.
What you still produce yourself:
- An internal incident-response policy and runbooks
- Detection infrastructure (SIEM or log management)
- A root-cause analysis template and post-incident review process
21(2)(c)
Business continuity and crisis management
Outside ITAM scope What the law asks: Continuity of YOUR operations: backups, disaster recovery, and crisis management for the systems you run.
What OnTrackio contributes: Honestly: little. Our own SaaS backups protect the register itself, not your production systems. No ITAM tool can evidence your BCP.
What you still produce yourself:
- A business continuity plan covering your production systems (ERP, MES, OT)
- Disaster-recovery test reports, at least annual
- A crisis-management playbook with a communications plan
- Backup verification records for your non-SaaS systems
21(2)(d)
Supply chain security
ITAM hygiene floor What the law asks: A supplier security programme: policy, selection criteria, contract clauses, and per-supplier risk assessment (Article 21(3)).
What OnTrackio contributes: The vendor inventory: every software and hardware supplier with active licence counts, which is the population your supplier risk assessment covers.
What you still produce yourself:
- A supply-chain security policy with vendor selection criteria (CIR Annex 5.1)
- The eight mandatory contract-clause areas, including audit rights and incident notification
- A per-vendor risk assessment and classification
- Article 21(3) vulnerability assessment per direct supplier
21(2)(e)
Security in acquisition, development and maintenance
ITAM proxy What the law asks: Secure development, change management, vulnerability handling, patching, and security testing across the lifecycle.
What OnTrackio contributes: A procurement-record proxy: purchase dates, invoices, transfer agreements at handover, wipe certificates at disposal. Useful records, but not the SDLC and vulnerability-management evidence the control is really about.
What you still produce yourself:
- SDLC documentation with secure-development practices (or a written statement that you do not develop in-house)
- A secure-baseline registry for the workstation and server estate
- A vulnerability-management programme with prioritized remediation SLAs
- An annual penetration test report with a remediation tracker
21(2)(f)
Effectiveness assessment
ITAM-native evidence What the law asks: Policies and procedures to assess whether your risk-management measures actually work: measurable indicators, not assertions.
What OnTrackio contributes: A native implementation of the CIR section 7 requirements: a documented policy with a tamper check, cadenced metric snapshots computed from live asset and user data, and a quarterly review workflow with management sign-off.
What you still produce yourself:
- KPI coverage for the controls outside ITAM scope (patch latency, training completion, BCP test results)
- Your own effectiveness-assessment policy text; we provide the workflow and the tamper-checked storage
21(2)(g)
Cyber hygiene and training
ITAM hygiene floor What the law asks: Basic hygiene practices plus a real awareness-training programme with records.
What OnTrackio contributes: The hygiene half of the numbers: MFA and passkey enrolment percentages and the org-wide enforcement policy state. MFA is one hygiene practice; it is not a training programme.
What you still produce yourself:
- An awareness-training programme with an annual delivery cadence
- Completion records: sign-in sheets or certificates (the ENISA evidence list)
- Phishing-simulation results over time
- Board-member training records (Article 20(2) makes management personally liable)
21(2)(h)
Cryptography
ITAM proxy What the law asks: A cryptography policy and key management covering your estate, not just your vendors' platforms.
What OnTrackio contributes: A coverage proxy: the share of endpoints reporting through the agent. Knowing 80 percent of endpoints are managed says nothing about whether their disks are encrypted, so the evidence pack never grades this above partial.
What you still produce yourself:
- A cryptography policy covering the CIR Annex 9.2 sub-points, from algorithm choice to key destruction
- An encryption-status inventory: BitLocker, FileVault, removable media, file shares
- A key-management procedure (KMS, HSM, or PKI as applicable)
21(2)(i)
HR security, access control and asset management
ITAM hygiene floor What the law asks: Three areas in one clause: personnel security, access-control policies, and asset management.
What OnTrackio contributes: The asset-management third is where we go deepest: the inventory itself, plus the metric assessors reach for before anything else, offboarded people still holding assets. Role-based access and scoped, expiring API tokens cover our own surface.
What you still produce yourself:
- An access-control policy and a joiner-mover-leaver workflow with documented sign-off
- A privileged-account management procedure
- Background-verification records for security-relevant roles
- Asset handling and removable-media policies
21(2)(j)
MFA, continuous authentication and secure communications
ITAM-native evidence What the law asks: Multi-factor or continuous authentication, and secured emergency communications for when the primary channel is down.
What OnTrackio contributes: The MFA half natively: TOTP and phishing-resistant passkey enrolment percentages, org-wide policy enforcement across password, Google, Microsoft, and SAML sign-in paths, and the agent's signed request protocol.
What you still produce yourself:
- An out-of-band crisis communications channel that works when email and chat are compromised
- The secure emergency-communications procedure, documented in your BCP