NIS2 Effectiveness Assessment (Article 21(2)(f)): Proving Your Controls Work
NIS2 Article 21(2)(f) requires policies to assess whether your risk-management measures are actually effective. Present, on paper, isn't the same as working, here's how to show the difference.
Most of the NIS2 measures ask you to have a control. Article 21(2)(f) asks something sharper: do you have a way to know whether those controls actually work? It requires “policies and procedures to assess the effectiveness of cybersecurity risk-management measures.” In other words: a feedback loop.
General direction, not legal advice. Because NIS2 is transposed country by country (in Italy through D.Lgs. 138/2024 and the ACN), confirm the specifics that apply to you with the relevant authority.
Present vs. effective
A firewall in the rack is present. Whether its rules actually block what they should is effectiveness. A backup job that runs nightly is present; whether you can restore from it is effectiveness. NIS2’s point is that controls degrade, configurations drift, and assumptions rot, so you need a deliberate, repeatable way to check.
What an effectiveness programme looks like
You don’t need a Big-Four audit. You need evidence that you periodically verify, and act on the findings:
- Internal control reviews, a checklist walk-through of your key controls against your own policy, on a cadence, with findings logged and closed.
- Technical testing, vulnerability assessments at minimum; penetration testing for higher-risk systems. The output is a prioritised list of what’s actually exploitable, not a theoretical one.
- Restore and incident tests, covered under continuity and incident handling, but they’re effectiveness evidence too.
- Metrics that mean something, e.g. time-to-remediate for exploited vulnerabilities, percentage of assets with current backups, MFA coverage. Trend them.
- Management review, leadership sees the results and decides on improvements, closing the loop NIS2 cares about.
Continuous, not annual
The strongest version of this measure isn’t a once-a-year scramble; it’s continuous. Control state changes daily, a new vulnerability is disclosed, a server is added, a patch is missed. A continuous view of your exploited-vulnerability exposure is one of the cleanest effectiveness signals you can have, because it’s measurable and it moves. That’s the honest fit for SentriKat: continuous, evidence-backed tracking of whether your most security-relevant risk, known exploited vulnerabilities, is actually going down, with signed reports you can put in front of an assessor.
Start here
Pick three controls that matter most (say: patching of exploited CVEs, backup restorability, MFA coverage). Define one metric for each, measure it this month, and put the results in a short management-review note. That’s a working effectiveness loop in miniature, and you expand from there.
See how effectiveness stacks up against the other nine measures with the free NIS2/DORA readiness check.
Ready to automate your vulnerability management?
Deploy SentriKat on-premises in minutes. Track CISA KEV vulnerabilities, generate NIS2 compliance reports, and protect your infrastructure.
Request a Demo