NIS2 Article 21(2)(f): showing that your measures work
Measure (f) asks a fair question: how do you know your other measures actually work? We'll be straight with you. A single check can't answer it, because that only becomes visible over weeks and months. A first check does give you a starting point to measure against.
Written by the SkyQon engineering team · Last checked against the legal texts on 2 October 2026
What is required
Article 21(2)(f) of Directive (EU) 2022/2555 asks for policies and procedures to assess how effective your cybersecurity risk-management measures are. Having the measures isn't the end of it. You need a way to show they're working, and to notice when one stops.
Article 21(4) follows on from this: if you find you're not complying, you have to put it right without undue delay. For the digital providers it covers, Implementing Regulation (EU) 2024/2690 asks for a policy that spells out how effectiveness is assessed, including what you measure, how, and how often.
Official text: Directive (EU) 2022/2555 · Implementing Regulation (EU) 2024/2690
What a first check gives you
A single check is a snapshot, but a snapshot is still useful here. You get:
- Where you stand today on certificates, email authentication, DNS and domain registration, summed up in a Domain Check Score.
- A short list of what to fix first, so your next measurement has something to show.
A typical case
Your first check shows DMARC at none. Over two months you move it to quarantine and then to reject, and the score goes up. That's good, but the score alone isn't what an auditor needs. What they need is the dated record behind it: when the problem was first seen, each step you took, and the fact that it has stayed fixed since.
This is a composite of things we often see, not a specific customer.
Why one check isn't enough
Effectiveness shows up as a trend. One check can't tell anyone that a control kept working all year, that a lapse was caught, or how long the fix took. And for internal measures such as incident response or backups, no outside check can judge effectiveness at all, ours included.
What auditors ask for
Auditors look for measurements that show controls working, and for test results over a period of time. ENISA's June 2025 guidance gives the results of regular effectiveness reviews as an example.
Building the record over time
The Digital Trust Center measures your domains all the time and keeps a ledger of how your controls performed: how often each one held, every lapse, and how long each fix took, period after period. With the NIS2 Evidence Pack it becomes a signed monthly report. Our NIS2 mapping counts it as direct evidence for 21(2)(f), for the controls we can see from outside.
NIS2 Evidence Pack pricing · Open a sample signed report (PDF) · Check a report's signature yourself
Start your record with a first check
Free, with no account. Keep the result as your starting point.
The other measures
Article 21(2) has ten measures in total. Most of them are about how you work inside the company, and we can't see those from outside. Our longer guide goes through all ten and says which ones leave something visible.
- All ten measures: what counts as evidence
- 21(2)(d) Supply chain security: check a supplier from outside
- 21(2)(e) Maintenance and vulnerability handling
- 21(2)(g) Basic cyber hygiene
- 21(2)(h) Cryptography and encryption
- A one-page NIS2 summary for your managing director
We explain the law here as plainly as we can, but this is not legal advice. NIS2 reaches you through your own country's law, and the details differ from one country to the next.