NIS2 · Article 21(2)(g)

NIS2 Article 21(2)(g): basic cyber hygiene

Measure (g) is about everyday security habits and training. Most of that happens where we can't see it, in updates, passwords, devices and backups. Some of it does show on your domain, though, and that part you can check for free.

Check my domain's hygiene

Written by the SkyQon engineering team · Last checked against the legal texts on 2 October 2026

What NIS2 asks for

Article 21(2)(g) of Directive (EU) 2022/2555 asks for basic cyber hygiene practices and cybersecurity training. The articles don't define hygiene. Recital 89 gives examples instead: zero-trust principles, software updates, device configuration, network segmentation, identity and access management, and making users aware of threats.

Implementing Regulation (EU) 2024/2690 has a section on hygiene and security training for the digital providers it covers. Training also lands on the board personally: Article 20(2) says members of the management body must follow it.

Official text: Directive (EU) 2022/2555 · Implementing Regulation (EU) 2024/2690

The part we can check

For a domain, good hygiene mostly means the basics are set up and nothing is quietly running out. Our free check looks at:

  • Your certificates: anything expired, close to expiring or self-signed, and how renewal seems to be done.
  • Protection against fake email in your name, through SPF, DKIM and DMARC.
  • DNS basics: nameservers that answer properly, DNSSEC, and a CAA record saying which certificate authorities may issue certificates for you.
  • Your domain registration: when it runs out, and whether it is locked so it can't be transferred away.

A typical case

The certificates renew automatically and email authentication is in order. But the domain registration runs out in five weeks, and the renewal reminders go to the address of someone who left the company last year. The check shows the five weeks. It can't know about the mailbox, which is exactly the kind of thing hygiene is about.

This is a composite of things we often see, not a specific customer.

What stays out of view

We can't see patching, passwords, laptops, backups or how your network is divided up, and we can't tell whether your staff have been trained. That is most of what hygiene means, and it lives in your own records. A clean result from us says the visible basics of one domain are in place. It doesn't say your hygiene as a whole is.

What auditors look for

Auditors want to see hygiene as a routine rather than a tidy-up the week before they arrive. That means certificates renewed on time month after month, monitoring that kept running, and problems that got fixed. ENISA's June 2025 guidance mentions certificate-management records and continuous-monitoring logs as examples.

Keeping the record going

When the Digital Trust Center monitors your domains, it notes every renewal and every lapse as it happens. With the NIS2 Evidence Pack, that history becomes signed monthly evidence. Our NIS2 mapping counts it as supporting evidence for 21(2)(g): useful, but one piece among several, never the whole measure.

NIS2 Evidence Pack pricing · Open a sample signed report (PDF) · Check a report's signature yourself

Look at your domain's visible hygiene

No account is needed, and the result shows on screen straight away.

The other measures

Article 21(2) has ten measures in total. Most of them are about how you work inside the company, and we can't see those from outside. Our longer guide goes through all ten and says which ones leave something visible.

We explain the law here as plainly as we can, but this is not legal advice. NIS2 reaches you through your own country's law, and the details differ from one country to the next.