Article 21 — Cybersecurity risk-management measures
NIS2 — direktiv (EU) 2022/2555
| I rettsakten | EU 2022/2555 |
| Kapittel | IV · Cybersecurity risk-management measures and reporting obligations |
| CELEX | 32022L2555 |
| Lest | 2026-08-14 |
Offisiell tekst
Lest hos EUs publikasjonskontor for dette CELEX-nummeret. Ordlyden står slik den er publisert, ingenting er skrevet om eller sammenfattet.
Teksten vises på engelsk. Norsk er ikke et offisielt EU-språk, så den offisielle ordlyden finnes ikke på norsk.
1. Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services.
Taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, the measures referred to in the first subparagraph shall ensure a level of security of network and information systems appropriate to the risks posed. When assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact.
2. The measures referred to in paragraph 1 shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the following:
(a) policies on risk analysis and information system security;
(b) incident handling;
(c) business continuity, such as backup management and disaster recovery, and crisis management;
(d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers;
Artikkelen fortsetter i den offisielle teksten.
Andre artikler i kapitlet
Teksten er sitert fra den offisielle kilden og er ikke juridisk rådgivning. En nasjonal domstol leser språkversjonen som binder i sin jurisdiksjon.
Tilbake til rettsakten · EU-rettsakter, lest helt ned til nasjonal lov
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.