In short: Article 21 of the NIS2 Directive requires critical and significant entities to implement risk management measures that explicitly include the hardening of information systems. With French implementation expected in July 2026, affected SMEs and mid-market companies must immediately translate these obligations into concrete actions on their Windows endpoints—or face penalties of up to €10 million or 2% of global revenue.
What does Article 21 of NIS2 actually require in terms of endpoint security?
Article 21 of the NIS2 Directive (EU 2022/2555) is the operational core of the regulation: it defines the cybersecurity risk management measures that all relevant entities must implement. Unlike NIS1, which remained very general, NIS2 lists ten categories of mandatory measures, explicitly including:
- Policies regarding risk analysis and information system security (Art. 21.2.a)
- Security in the procurement, development, and maintenance of networks and systems (Art. 21.2.e)
- Basic cyber hygiene practices and cybersecurity training (Art. 21.2.g)
- Vulnerability management and coordinated disclosure (Section 21.2.h, as implemented by implementing regulations)
In practice, for an CISO at an SME or mid-sized company, these requirements boil down to one concrete question: Is the security configuration of your Windows endpoints documented, monitored, and compliant with a recognized standard? If the answer isn’t an immediate “yes,” your organization is at risk.
The French implementation of NIS2 is expected in July 2026. The first formal notices from ANSSI could be issued as early as fall 2026. The time available for preparation is now measured in weeks, not months.
What security measures do the NIS2-related standards recommend?
NIS2 does not prescribe a single technical framework—it refers to industry best practices and recognized standards. In France, ANSSI is the authoritative body on this matter. For Windows endpoints, two frameworks are essential.
CIS Benchmarks for Windows: The Industry Standard
The CIS Benchmarks for Windows Server 2022 and Windows 11 define several hundred configuration checks organized into two levels:
- Level 1: Basic measures applicable to the entire infrastructure without a significant impact on productivity. These include password policies, disabling unnecessary services, configuring the local firewall, and controlling code execution.
- Level 2: Enhanced measures for environments that handle sensitive data or are subject to strict regulatory requirements (healthcare, finance, OIV/OSE). These include granular access control, mandatory disk encryption, and advanced auditing policies.
Under NIS2, Level 1 represents the minimum requirement for all significant entities. Critical entities must demonstrate a Level 2 security posture for their critical systems.
ANSSI Guidelines: The French Interpretation of NIS2 Requirements
ANSSI publishes secure configuration guides specific to Windows environments, aligned with NIS2 requirements. These guides cover, in particular, the management of privileged accounts (LAPS), Windows firewall configuration, AppLocker or WDAC (Windows Defender Application Control) policies, and the configuration of Windows audit logs —a direct NIS2 requirement regarding incident detection and notification.
According to ANSSI, implementing these measures reduces the attack surface exploitable by the techniques listed in the MITRE ATT&CK framework by approximately 85%.
The 5 NIS2 Article 21 requirements that apply directly to your endpoints
1. Inventory and classification of assets (Sec. 21.2.a)
You must be able to list all your endpoints, their operating system versions, their update levels, and the network segments to which they belong. Without an accurate inventory, no credible risk analysis is possible.
2. Vulnerability management and patch management (Section 21.2.h)
NIS2 requires a formalized process for identifying and addressing vulnerabilities, with remediation deadlines determined based on severity (critical patches within 72 hours, important patches within 30 days).
3. Access control and the principle of least privilege (Art. 21.2.e)
Removing permanent local administrator privileges, deploying LAPS, and documenting privileged accounts are no longer optional best practices: they are requirements documented by ANSSI in the context of NIS2.
4. Securing the software supply chain (Art. 21.2.d)
NIS2 requires that you verify the security of the software deployed on your systems. On Windows endpoints, this is achieved through application whitelisting policies (AppLocker, WDAC) that allow only signed and approved binaries.
5. Logging and Incident Detection (Art. 21.2.b)
NIS2 requires that ANSSI be notified within 24 hours of the detection of a significant incident. These deadlines can only be met if Windows audit logs are properly configured and centralized.
How can you streamline NIS2 compliance across your Windows environment without disrupting operations?
The main challenge lies in the tension between strict compliance and operational continuity. There are three approaches to resolving this: simulate before deploying (test the impact of each control on business applications before going live), prioritize by risk (address the 20% of controls that eliminate 80% of the risk first, according to MITRE ATT&CK), and monitor compliance continuously (a hardened endpoint can drift over time—without automated monitoring, your NIS2 compliance score is an outdated snapshot).
Cyberlib addresses these three challenges head-on with an agentless SaaS platform: deployment without modifying endpoints, impact simulation prior to applying baselines, and continuous compliance scoring aligned with CIS, ANSSI, and MITRE ATT&CK.
→ Assess your Windows environment’s NIS2 compliance with Cyberlib
FAQ
Does NIS2 Article 21 apply to my company?
NIS2 applies to essential entities (large companies in critical sectors) and significant entities (those with more than 50 employees or €10 million in revenue across 18 broad sectors). In France, implementation is expected in July 2026. ANSSI provides a self-assessment tool on its website.
Which security standards are recognized by ANSSI under NIS2?
ANSSI primarily recognizes the CIS Benchmarks for Windows (Levels 1 and 2), its own secure configuration guides, and the MITRE ATT&CK framework for prioritizing measures. ISO 27001 controls (Annex A) are also accepted as a complementary governance framework.
What are the incident reporting deadlines required by NIS2?
NIS2 requires an early warning within 24 hours of the detection of a significant incident, a full notification within 72 hours including an initial assessment, and a final report within one month of resolution.
What are the penalties for non-compliance with NIS2 Article 21?
Up to €10 million or 2% of global revenue for essential entities; €7 million or 1.4% of global revenue for significant entities.
Is hardening endpoints enough to ensure compliance with NIS2?
No. Article 21 of NIS2 includes ten categories of measures. However, endpoint hardening is the most practical measure and the one that ANSSI can verify most immediately during an audit.
How can you demonstrate NIS2 compliance to ANSSI?
The demonstration is based on three elements: documentation of the measures implemented, evidence of effective controls (audit reports, logs), and a documented periodic review process.
