SentriKat is live, launch pricing and hands-on onboarding for founding customers. Get started
All articles

NIS2 Effectiveness Assessment (Article 21(2)(f)): Proving Your Controls Work

NIS2 Article 21(2)(f) requires policies to assess whether your risk-management measures are actually effective. Present, on paper, isn't the same as working, here's how to show the difference.

Denis Sota · · 3 min read

Most of the NIS2 measures ask you to have a control. Article 21(2)(f) asks something sharper: do you have a way to know whether those controls actually work? It requires “policies and procedures to assess the effectiveness of cybersecurity risk-management measures.” In other words: a feedback loop.

General direction, not legal advice. Because NIS2 is transposed country by country (in Italy through D.Lgs. 138/2024 and the ACN), confirm the specifics that apply to you with the relevant authority.

Present vs. effective

A firewall in the rack is present. Whether its rules actually block what they should is effectiveness. A backup job that runs nightly is present; whether you can restore from it is effectiveness. NIS2’s point is that controls degrade, configurations drift, and assumptions rot, so you need a deliberate, repeatable way to check.

What an effectiveness programme looks like

You don’t need a Big-Four audit. You need evidence that you periodically verify, and act on the findings:

  • Internal control reviews, a checklist walk-through of your key controls against your own policy, on a cadence, with findings logged and closed.
  • Technical testing, vulnerability assessments at minimum; penetration testing for higher-risk systems. The output is a prioritised list of what’s actually exploitable, not a theoretical one.
  • Restore and incident tests, covered under continuity and incident handling, but they’re effectiveness evidence too.
  • Metrics that mean something, e.g. time-to-remediate for exploited vulnerabilities, percentage of assets with current backups, MFA coverage. Trend them.
  • Management review, leadership sees the results and decides on improvements, closing the loop NIS2 cares about.

Continuous, not annual

The strongest version of this measure isn’t a once-a-year scramble; it’s continuous. Control state changes daily, a new vulnerability is disclosed, a server is added, a patch is missed. A continuous view of your exploited-vulnerability exposure is one of the cleanest effectiveness signals you can have, because it’s measurable and it moves. That’s the honest fit for SentriKat: continuous, evidence-backed tracking of whether your most security-relevant risk, known exploited vulnerabilities, is actually going down, with signed reports you can put in front of an assessor.

Start here

Pick three controls that matter most (say: patching of exploited CVEs, backup restorability, MFA coverage). Define one metric for each, measure it this month, and put the results in a short management-review note. That’s a working effectiveness loop in miniature, and you expand from there.

See how effectiveness stacks up against the other nine measures with the free NIS2/DORA readiness check.

Ready to automate your vulnerability management?

Deploy SentriKat on-premises in minutes. Track CISA KEV vulnerabilities, generate NIS2 compliance reports, and protect your infrastructure.

Request a Demo