Directive (EU) 2022/2555CIR (EU) 2024/2690 · Annex
Article 21(2) of the directive names ten risk-management measures in prose. Commission Implementing Regulation (EU) 2024/2690 turns them into an Annex of thirteen numbered points with sub-requirements — the only EU-wide enumeration specific enough to measure against, and the one an assessor cites.
CIR (EU) 2024/2690 applies directly to DNS providers, TLD name registries, cloud, data centre and content delivery providers, managed service and managed security service providers, online marketplaces, search engines, social networking platforms and trust service providers. Other essential and important entities meet Article 21 through the national law that transposes it. In either case the numbered controls are the technical reading of Article 21, which is why they are used here.
Against each one, what a monitoring system can honestly say. Six are documents and decisions rather than events, and are reported as open with the evidence an assessor will request.
| Point | Requirement | Evidenced by |
|---|---|---|
| 1 | Policy on the security of network and information systems | Documents and decisions |
| 2 | Risk management policy | Documents and decisions |
| 3 | Incident handling | Measurement |
| 4 | Business continuity and crisis management | Partly measurable |
| 5 | Supply chain security | Documents and decisions |
| 6 | Security in network and information systems acquisition, development and maintenance | Measurement |
| 7 | Policies and procedures to assess the effectiveness of cybersecurity risk-management measures | Documents and decisions |
| 8 | Basic cyber hygiene practices and security training | Partly measurable |
| 9 | Cryptography | Partly measurable |
| 10 | Human resources security | Documents and decisions |
| 11 | Access control | Measurement |
| 12 | Asset management | Partly measurable |
| 13 | Environmental and physical security | Documents and decisions |
Approximately one third of the numbered controls are evidenced by measurement. A coverage claim that exceeds what a monitoring system can observe does not survive an assessment, so the remainder are reported as open rather than quietly counted as met.
ReportingArticle 23
A significant incident must be reported to the national CSIRT or competent authority in three stages. The deadlines run from the moment the entity becomes aware of the incident.
Quoted from Directive (EU) 2022/2555. This is the binding wording, not a summary of ours. Article 23(4)
Quanovio records first detection with its timestamp, which is what an assessor compares the filing against. Filing itself is a process you operate; no monitoring system can do it for you, and one that claims to is describing an alert.
4. Member States shall ensure that where they infringe Article 21 or 23, essential entities are subject, in accordance with paragraphs 2 and 3 of this Article, to administrative fines of a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the essential entity belongs, whichever is higher.
5. Member States shall ensure that where they infringe Article 21 or 23, important entities are subject, in accordance with paragraphs 2 and 3 of this Article, to administrative fines of a maximum of at least EUR 7 000 000 or of a maximum of at least 1,4 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the important entity belongs, whichever is higher.
Quoted from Directive (EU) 2022/2555. This is the binding wording, not a summary of ours. Article 34(4) and (5)
1. Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article.
ReferencesEUR-Lex · ENISA
Every figure, deadline and requirement title on this site is taken from the texts below. Where this site quotes, it quotes the official language version you are reading it in.
Describe your environment and you will receive a point-by-point statement, including the ones no system can measure for you.
See your coverage