The thirteen measures, all in one place
The measures are set out in Annex II of Regulation NN 135/2024. The basic, medium and advanced levels are determined by the national risk assessment during categorisation, under Article 38 of the Regulation, not by the entity category.
Thirteen measures, 99 sub-measures, 137 controls
The thirteen risk management measures are broken down into 99 sub-measures, matched by 137 controls from the catalogue of the Information Systems Security Bureau. What is binding differs across the three levels, basic, medium and advanced. Of the 99 sub-measures, 59 are binding at the basic level, 80 at the medium level and 87 at the advanced level. The rest are voluntary or binding subject to a condition. Every control requires written evidence, and scoring follows the methodology of the Information Systems Security Bureau. The deadline for implementation is twelve months from delivery of the categorisation notice, under Article 26(5) of the Act.
How to read the tables
Each measure is broken down into sub-measures. For every sub-measure the table shows whether it is binding at the basic, medium and advanced level, and which controls from the ZSIS control catalogue the auditor checks alongside it, by their code.
OBLIGATION
- A
- Binding sub-measure at that level.
- B
- Binding subject to a condition Annex II sets out with the measure. The condition is stated below the relevant table.
- C
- Voluntary sub-measure. Implemented according to the entity’s risk assessment, and additionally credited in self-assessment and audit.
LEVELS AND CONTROLS
- BAS
- Basic level.
- MED
- Medium level.
- ADV
- Advanced level.
- CONTROLS
- Codes of the controls from the ZSIS control catalogue checked alongside that sub-measure.
The same catalogue control serves several sub-measures, for example NAD-002 sits with sub-measure 5.4 and with sub-measure 5.6. The CONTROLS column therefore holds 240 entries in total, while the number of unique controls is 137.
Jump to a measure
The thirteen measures of Annex II, each with its sub-measures.
Commitment and accountability of those responsible for implementing the measures
Cyber security becomes a management topic, not just an IT topic.
The Regulation requires the management body to adopt a strategic cyber security policy, provide the money, people and equipment to carry it out, assign roles and responsibilities, and receive an annual report on the state of cyber security. The evidence is not a slide deck but a decision, a set of minutes and a signature. From the medium level onwards it also requires separating roles that could create a conflict of interest and appointing a person operationally responsible for cyber security.
Software and hardware asset management
You cannot protect what you do not know you have.
This measure requires an inventory of critical software and hardware assets with an identifier, location and owner, a list of critical data, and rules for removable media and for equipment used outside the entity's premises. The inventory has to be a living record. A table compiled once and then forgotten is spotted immediately during an audit, because it no longer matches what is actually in the server room.
Risk management
What is required is a process, not a single document.
The entity must describe how a risk is identified, how it is assessed, who owns it and what is done about it. The assessment follows an all hazards approach, so it covers fire, failure and human error, not just attacks. The result is kept in a risk register updated at least once a year.
CONDITION FROM ANNEX IISub-measure 3.8 is binding for an entity that already runs enterprise risk management. In that case sub-measures 3.1 to 3.7 are carried out within that framework.
Human resources security and digital identities
It joins up HR records and access rights, which in practice are usually kept apart.
The measure requires verification of candidates' qualifications before hiring, documented training for people with security duties, regular cyber hygiene training for everyone, and disciplinary measures for breaking the rules. On the other side sit unique digital identities, rights assigned by job role on a need to know and least privilege basis, and timely removal of access when someone leaves or changes post.
Basic cyber hygiene practices
The largest measure, and the one most visible in day to day work.
This is where passwords, multi-factor sign-in, anti-virus, patching, logging and regular vulnerability scanning sit. Logs are kept for at least ninety days and systems must have synchronised time so that logs can be correlated. All of the above is binding from the basic level onwards; central log storage, blocking known malicious sites and reducing the attack surface become binding only at the medium level.
CONDITION FROM ANNEX IISub-measure 5.7 is binding if the entity uses software it develops itself. Sub-measures 5.1 to 5.11 apply in full to IT systems; for operational technology all apply except 5.4, which depends on a risk assessment.
Securing the network
The network is divided so that a breach in one part is not a breach of everything.
This requires a documented network architecture with protective measures, separation and segmentation, monitoring of network use and network accessible resources, and an annual comprehensive review of those measures. The measure has only five sub-measures but is among the more expensive in practice, because segmentation usually means reworking an existing network.
CONDITION FROM ANNEX IISub-measures 6.1, 6.3 and 6.5 apply in full to operational technology as well. Sub-measure 6.2 depends on a further assessment of data criticality in the OT environment, and 6.4 on assessing the effect of automatic blocking on the operation and safety of those systems.
Physical and logical access control
Who may enter a room and who may enter an application are governed by the same rules.
Every application has an owner who approves user rights, rights are reviewed at least once a year, and privileged and administrator accounts have dedicated procedures and monitoring. The more advanced sub-measures, dynamic access control and user behaviour analytics, remain voluntary at all three levels.
Supply chain security
Responsibility does not stop at the front door.
This requires a list of all direct suppliers and service providers, security clauses in contracts covering the right to audit, vulnerability management and competence requirements, and regular checks on how suppliers meet them. It is the measure most likely to mean reopening existing contracts, so it pays to start earlier than seems necessary.
Security in the development and maintenance of network and information systems
The focus is on system configuration across the whole life cycle.
Systems must have an established, documented and continuously monitored configuration, including the security settings of all software and hardware assets and of the external services and networks in use. Security requirements must also enter the technical specification and the procurement stage, and every change needs categorisation, approval and a rollback path.
CONDITION FROM ANNEX IISub-measures 9.4 and 9.5 are binding for entities that develop or maintain network and information systems themselves.
Cryptography
A written rule on when and how critical data is protected.
Critical data must be protected both in transit and at rest, under rules covering authenticity, integrity and confidentiality. In practice the sticking point is key management, because it is rarely written down anywhere, and the auditor asks for exactly that record: who issues the key, where it is held and how it is revoked.
Incident handling
The procedure has to exist before the incident does.
It must be clear who triages a suspicious event, within what deadline it is reported internally, who decides and who notifies the competent CSIRT. Under the Regulation an early warning goes out without delay and no later than 24 hours after becoming aware, an initial notification within 72 hours, and a final report within 30 days of the initial notification. Trust service providers submit the initial notification within 24 hours.
Business continuity and cyber crisis management
The question is not whether a system will stop but how long it may stay down.
A business impact analysis sets the recovery objectives: how much data may be lost and how long a service may be unavailable. Recovery and continuity plans describe how those objectives are met, and backups have to be verified, not merely taken. From the medium level plans are tested at least once a year.
CONDITION FROM ANNEX IISub-measure 12.6 becomes binding at the request of the competent authorities.
Physical security
The same logic as system access control, applied at the door.
This requires a physical security policy matched to the risks of the environment the entity operates in, basic protection of premises and equipment, and regular review and updating of security protocols.
CONDITION FROM ANNEX IIFor entities in the digital infrastructure sector, Annex III of the Regulation sets out an extended set of physical security measures, under Article 46 of the Regulation.
Frequently asked questions
The questions most often asked about this list of measures.
Where do the thirteen measures come from?
From Annex II of Regulation NN 135/2024, which implements Act NN 14/2024. The Regulation breaks them into 99 sub-measures, and the ZSIS control catalogue into 137 controls that the auditor checks.Do we have to implement all thirteen?
Yes. All of them apply to every categorised entity. What differs is the level of implementation, not the list of measures.What do the marks A, B and C mean?
A is a binding sub-measure at that level. B is binding subject to a condition Annex II sets out with the measure, for example if the entity develops its own software. C is voluntary, implemented according to the risk assessment, and its implementation is additionally credited in self-assessment and audit.How many sub-measures are binding at the basic level?
Marked A at the basic level are 59 of the 99 sub-measures. At the medium level it is 80, and at the advanced level 87. The rest are voluntary or binding subject to a condition.How are the measures scored?
Under the methodology of the Information Systems Security Bureau, control by control, with written evidence required for each. The result is a scored maturity picture by measure.Which measure is hardest in practice?
Supply chain security and business continuity, because they need records over time rather than a single document. Supply chain work usually also means reopening existing contracts.Do all measures apply to operational technology?
Not in full. For measures 5 and 6, Annex II states which sub-measures apply to OT without restriction and which depend on a risk assessment. This is noted below the relevant tables.Where to go next
The measures are a list of obligations. These pages cover how the evidence is built.
From the blog: the Cyber Security Act
The three latest texts on the Act, the measures and the audit.
Let us check which measures you already have evidence for.
Half an hour, no obligation. We go measure by measure and separate what you already have from what still needs writing.
