Skip to content
safemode.space
nis2-implPolicies and procedures to assess the effectiveness of cybersecurity risk-management measures

Annex 7.2

Policies and procedures to assess the effectiveness of cybersecurity risk-management measures

Official heading, as published in NIS2 Implementing Regulation.

Read from this provision's own operative text, its duty falls on relevant entities.

The provision opens in the derivative form, "The policy and procedures referred to in point 7.1 shall take into account results of the risk assessment", but it does not stop there: its second sentence names an addressee of its own, "The relevant entities shall determine:", and that stem carries the six lettered obligations that are the bulk of the text. Because the provision states its own addressee, the inherited test of naming none fails. The lettered items fix what is monitored, by what methods, when, and who is responsible internally, which is an allocation inside the entity and not an obligation on a second class of legal person.

This corpus maps obligations. It does not determine applicability: whether any of these instruments binds a particular organisation turns on facts about that organisation, and none of those facts is in here.

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision (OJ L, 2024/2690, 18.10.2024).

Mapped SPARTA techniques (2)

All 2 mappings on this page were reasoned and reviewed by SafeMode Space. This junction carries no imported cross-references.

What relationship, confidence, and evidence mean
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

Disagree with a mapping here? Send a correction. Say which pair and cite the source text you are reading it against; corrections are the fastest way to improve the corpus.

Techniques referencing this article

  • DE-0003.12Poison AI/ML Training for EvasionST0006
    addresses
    moderate
    inferred
    #

    Annex 7.2 requires the entity to name what is monitored, by what method, on what schedule and by whom, when it assesses whether its risk-management measures are working. That is the section under which a defect in this technique's subject matter would be found by the entity itself rather than by an adversary. It sets no measure against the technique and interdicts nothing, capping at addresses under entry 15 as its parent provision does.

  • REC-0006.02Security Testing ToolsST0001
    addresses
    moderate
    inferred
    #

    Annex 7.2 requires the entity to name what is monitored, by what method, on what schedule and by whom, when it assesses whether its risk-management measures are working. That is the section under which a defect in this technique's subject matter would be found by the entity itself rather than by an adversary. It sets no measure against the technique and interdicts nothing, capping at addresses under entry 15 as its parent provision does.

Cite as SafeMode Space, Annex 7.2 (NIS2 Implementing Regulation OJ L, 2024/2690, 18.10.2024), https://safemode.space/reference/regulations/nis2-impl/articles/annex-7-2, accessed YYYY-MM-DD. Replace YYYY-MM-DD with the date you read the page; the corpus is curated continuously, so mappings can change between readings. To cite one mapping rather than this page, append its anchor to the URL — every mapping row has an id of the form technique--collection--target, the same on every page that lists it. See how to cite. Sources and licence: sources and attribution. A mapping on this page is interpretive analysis of how a technique and a provision relate, not a statement of law and not compliance guidance. Read the disclaimer.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.