NIS2 Article 21(2)(g): basic cyber hygiene
Measure (g) is about everyday security habits and training. Most of that happens where we can't see it, in updates, passwords, devices and backups. Some of it does show on your domain, though, and that part you can check for free.
Written by the SkyQon engineering team · Last checked against the legal texts on 2 October 2026
What NIS2 asks for
Article 21(2)(g) of Directive (EU) 2022/2555 asks for basic cyber hygiene practices and cybersecurity training. The articles don't define hygiene. Recital 89 gives examples instead: zero-trust principles, software updates, device configuration, network segmentation, identity and access management, and making users aware of threats.
Implementing Regulation (EU) 2024/2690 has a section on hygiene and security training for the digital providers it covers. Training also lands on the board personally: Article 20(2) says members of the management body must follow it.
Official text: Directive (EU) 2022/2555 · Implementing Regulation (EU) 2024/2690
The part we can check
For a domain, good hygiene mostly means the basics are set up and nothing is quietly running out. Our free check looks at:
- Your certificates: anything expired, close to expiring or self-signed, and how renewal seems to be done.
- Protection against fake email in your name, through SPF, DKIM and DMARC.
- DNS basics: nameservers that answer properly, DNSSEC, and a CAA record saying which certificate authorities may issue certificates for you.
- Your domain registration: when it runs out, and whether it is locked so it can't be transferred away.
A typical case
The certificates renew automatically and email authentication is in order. But the domain registration runs out in five weeks, and the renewal reminders go to the address of someone who left the company last year. The check shows the five weeks. It can't know about the mailbox, which is exactly the kind of thing hygiene is about.
This is a composite of things we often see, not a specific customer.
What stays out of view
We can't see patching, passwords, laptops, backups or how your network is divided up, and we can't tell whether your staff have been trained. That is most of what hygiene means, and it lives in your own records. A clean result from us says the visible basics of one domain are in place. It doesn't say your hygiene as a whole is.
What auditors look for
Auditors want to see hygiene as a routine rather than a tidy-up the week before they arrive. That means certificates renewed on time month after month, monitoring that kept running, and problems that got fixed. ENISA's June 2025 guidance mentions certificate-management records and continuous-monitoring logs as examples.
Keeping the record going
When the Digital Trust Center monitors your domains, it notes every renewal and every lapse as it happens. With the NIS2 Evidence Pack, that history becomes signed monthly evidence. Our NIS2 mapping counts it as supporting evidence for 21(2)(g): useful, but one piece among several, never the whole measure.
NIS2 Evidence Pack pricing · Open a sample signed report (PDF) · Check a report's signature yourself
Look at your domain's visible hygiene
No account is needed, and the result shows on screen straight away.
The other measures
Article 21(2) has ten measures in total. Most of them are about how you work inside the company, and we can't see those from outside. Our longer guide goes through all ten and says which ones leave something visible.
- All ten measures: what counts as evidence
- 21(2)(d) Supply chain security: check a supplier from outside
- 21(2)(e) Maintenance and vulnerability handling
- 21(2)(f) Showing that your measures work
- 21(2)(h) Cryptography and encryption
- A one-page NIS2 summary for your managing director
We explain the law here as plainly as we can, but this is not legal advice. NIS2 reaches you through your own country's law, and the details differ from one country to the next.