🇪🇺 NIS2 Compliance Toolkit

Meet NIS2 Article 21 Obligations with
AI-Powered Incident Response Exercises

The EU NIS2 Directive (Directive 2022/2555) requires Essential and Important entities to maintain, test, and document incident handling and crisis management processes. Skyhigh provides 65 ready-to-run ICS/OT tabletop scenarios in four languages, AI-generated After Action Reports, and audit-ready compliance evidence — supporting your NIS2 obligations from Article 20 governance through to Article 21 technical measures.

Art. 21(b) — Incident handling & response
Art. 21(c) — Business continuity & crisis management
Art. 20 — Management body oversight evidence
EN / FR / PT / ES — 4 EU languages
Start Free — 3 Exercises Included 📋 Take NIS2 Readiness Assessment → Talk to Our EU Compliance Team
Compliance Note: Skyhigh's exercise scenarios and evidence artifacts support NIS2 Article 21 incident handling and crisis management obligations as part of a structured preparedness programme. Formal NIS2 compliance determination — including notification obligations under Article 23 — requires engagement with your designated national competent authority and qualified legal counsel familiar with your Member State's transposition legislation.
Who NIS2 Applies To

Essential Entities vs. Important Entities

NIS2 expands significantly on NIS1, covering 11 essential sectors and 7 important sectors. Both categories must implement Article 21 measures — including documented incident handling and crisis management testing.

Essential Entities

Higher Scrutiny, Proactive Supervision

Essential entities are subject to proactive supervision by national competent authorities, stricter incident reporting timelines (24hr early warning / 72hr notification / 1-month final report), and potential sanctions of up to €10M or 2% of global annual turnover.

  • Energy (electricity, oil, gas, hydrogen)
  • Transport (air, rail, water, road)
  • Banking & Financial Market Infrastructure
  • Health (hospitals, labs, pharma manufacturers)
  • Drinking water & wastewater
  • Digital infrastructure (IXPs, DNS, TLD, cloud, data centres)
  • ICT service management (managed services)
  • Public administration (central government)
  • Space (ground infrastructure operators)
Tabletop exercises directly evidence Art. 21(b) incident handling and Art. 21(c) business continuity testing obligations for Essential Entities.
Important Entities

Reactive Supervision, Same Measures

Important entities face reactive (complaint-driven) supervision and lower penalty caps (up to €7M or 1.4% of global turnover), but must implement the same Article 21 cybersecurity risk management measures as Essential Entities.

  • Postal & courier services
  • Waste management
  • Chemicals (manufacture, production, distribution)
  • Food (large-scale production & distribution)
  • Manufacturing (medical devices, electronics, machinery, motor vehicles)
  • Digital providers (online marketplaces, search engines, social platforms)
  • Research organisations
Same Article 21 technical and operational measures apply. Exercise documentation requirements are identical.
🌎

Multilingual Support for EU Teams

The NIS2 Directive applies across 27 Member States in multiple working languages. Skyhigh delivers exercises, AI facilitation outputs, and After Action Reports in four languages — enabling cross-border and multilingual teams to run exercises in their working language.

🇬🇧 English 🇫🇷 Français 🇵🇹 Português 🇪🇸 Español
Article 21 Mapping

NIS2 Article 21 — Cybersecurity Risk Management Measures

Article 21 defines ten mandatory cybersecurity measures for all covered entities. Tabletop exercises directly satisfy (b) and (c), and support evidence generation for six additional measures.

Article 21 Requirements Reference

Coverage: Core = exercise directly required  |  Supporting = exercise validates / documents  |  Partial = scenario content covers the risk domain

Article Measure Requirement Summary Skyhigh Capability Coverage
Art. 21(a) Risk analysis & IS policies Policies on information security risk analysis and information system security AI Facilitator Briefing surfaces policy gaps; AAR documents policy weaknesses identified during exercises; Gap Analysis flags absent policies Supporting
Art. 21(b) Incident handling Procedures for incident detection, analysis, containment, and recovery. Documented testing of incident response plans Live Session mode executes structured incident response exercises. AI AAR documents detection, containment, and recovery steps taken. Compliance evidence package provides audit-ready incident handling test record Core
Art. 21(c) Business continuity & crisis management Backup management, disaster recovery, and crisis management plans — including documented testing Recovery-focused scenario variants test backup activation and DR procedures; Crisis management steps are recorded and reflected in the AAR; Compliance evidence package documents the crisis management exercise Core
Art. 21(d) Supply chain security Security of supply chain relationships, including vendor risk assessment and contractual security requirements Supply chain attack scenarios exercise third-party compromise detection and vendor communication procedures; Gap Analysis flags supply chain vulnerabilities identified during exercise Partial
Art. 21(e) Network & IS security Security in network and information systems acquisition, development, and maintenance Network-layer attack scenarios (lateral movement, OT/IT boundary crossing) exercise detection and response; AAR documents control gaps in network security posture Partial
Art. 21(f) Cyber hygiene & training Policies and procedures for evaluating effectiveness of measures, including basic cyber hygiene and cybersecurity training Exercise completion demonstrates active cybersecurity training activity; Facilitator Certification (CTEP) evidence of qualified facilitation; AI Coaching tips reinforce hygiene practices during exercises Supporting
Art. 21(g) Cryptography policies Policies on the use of cryptography and encryption Scenarios referencing encrypted communication channels and data-at-rest protections exercise cryptography-adjacent procedures; limited direct coverage Partial
Art. 21(h) Human resources security & access control HR security policies, access control, asset management Insider threat and privilege escalation scenarios exercise access control response procedures; AAR flags access management gaps identified during exercises Supporting
Art. 21(i) Multi-factor authentication Use of MFA or continuous authentication for access to network and information systems Authentication bypass scenarios test detection of MFA circumvention; limited direct coverage of MFA policy enforcement Partial
Art. 20 Governance — Management oversight Management bodies must approve cybersecurity risk management measures, oversee their implementation, and attend cybersecurity training Executive-level scenario participants, AI AAR addressed to management, exercise history demonstrating consistent programme, Compliance Dashboard for board-level reporting Supporting
Platform Capabilities

How Skyhigh Supports Your NIS2 Programme

Three core capabilities work together to deliver, document, and evidence your Article 21(b) and 21(c) obligations.

🎲
Article 21(b) · 21(c)

Structured Exercise Execution

Live Session mode provides a real-time, multi-participant exercise environment. All steps, responses, and host actions are timestamped — creating an auditable record of your incident handling test.

  • Participant join record with timestamps
  • Step-by-step scenario walkthrough log
  • Session duration and completion metadata
  • Scored participant responses (optional)
📋
Article 21(b) · 21(c) · 20

AI-Generated After Action Report

Immediately after each exercise, Skyhigh's AI generates a structured AAR documenting gaps, recommendations, and NIS2 Article 21 control references — in the language your team worked in.

  • Structured gap analysis with severity ratings
  • NIS2 Article 21 control references per gap
  • Corrective action recommendations
  • Multilingual output (EN/FR/PT/ES)
📄
All Article 21 Measures

Compliance Evidence Package

The Compliance Dashboard generates per-framework NIS2 evidence packages — a 6-page audit PDF covering exercise log, Article 21 controls coverage, gap analysis, remediation plan, and attestation.

  • Exercise date, scope, and participants record
  • NIS2 Article 21 controls coverage map
  • Identified gaps and remediation timeline
  • Attestation page for competent authority files
Scenario Library

NIS2-Relevant Scenarios Across Essential & Important Sectors

Six high-fidelity scenarios covering the most regulated NIS2 sectors — ready to run without customisation, with AI facilitator briefing included.

Healthcare & Hospitals
Essential Entity
Hospital BMS Ransomware Attack

Ransomware propagates through a hospital's Building Management System, affecting HVAC, access control, and medical gas pressure monitoring. Tests Art. 21(b)(c) incident and continuity response.

Art. 21(b) Art. 21(c) Art. 21(d)
Energy — Electricity
Essential Entity
Power Grid Cascading Failure

A coordinated cyberattack targets multiple substations simultaneously, triggering cascading grid failures. Exercises Art. 21(b) incident response and cross-authority communication under Art. 23.

Art. 21(b) Art. 23 Art. 21(c)
Water & Wastewater
Essential Entity
Water Treatment SCADA Intrusion

An attacker gains access to a municipal water treatment SCADA system and begins altering chemical dosing setpoints. Tests detection, containment, and public authority notification under NIS2 Art. 23.

Art. 21(b) Art. 23 Art. 21(e)
Banking & Finance
Essential Entity
Banking SWIFT Network Disruption

A sophisticated threat actor compromises SWIFT messaging infrastructure, threatening transaction integrity and regulatory notification timelines. Exercises DORA/NIS2 dual obligations and Art. 21(b) response.

Art. 21(b) DORA Art. 23
Transport & Logistics
Important Entity
Port Logistics Platform Disruption

Ransomware strikes a port's logistics management platform, halting container tracking and creating cross-border supply chain disruption. Tests Art. 21(b)(c) and supply chain notification obligations.

Art. 21(b) Art. 21(d) Art. 21(c)
Multi-Sector
Essential & Important
Cross-Border Supply Chain Attack

A trusted software vendor used across multiple EU Member State entities is compromised, requiring coordinated cross-border response. Tests Art. 21(d) supply chain obligations and Art. 23 notification flows.

Art. 21(d) Art. 23 Art. 21(b)

Plus 59 additional scenarios across Pharma, Chemical, Manufacturing, Oil & Gas, and more. Browse the full library →

Evidence Artifacts

Audit-Ready Documentation for Competent Authorities

Every Skyhigh exercise generates four categories of compliance evidence supporting NIS2 Article 21 demonstration requirements and competent authority reporting.

📋
After Action Report (AAR)

AI-generated PDF with gap analysis, corrective actions, and NIS2 Article 21 references. Available in EN, FR, PT, ES within minutes of exercise completion.

Art. 21(b) · Art. 21(c)
📈
NIS2 Evidence Package

6-page per-framework audit PDF: exercise log, Article 21 controls map, gap analysis, remediation timeline, and attestation page for competent authority files.

All Article 21 Measures
🕑
Session Activity Transcript

Timestamped record of all participant responses and exercise activity demonstrating real team engagement — relevant to Art. 20 management participation evidence.

Art. 20 Governance
🔗
Gap Remediation Tracking

Identified exercise gaps are automatically pushed to ServiceNow or Jira as remediation tickets — creating a documented corrective action trail for Article 21 implementation evidence.

Art. 21 Implementation

Explore the Full Regulatory Toolkit Library

Skyhigh exercise evidence maps to multiple frameworks simultaneously. One exercise program — complete regulatory coverage.

Ready to Exercise Your NIS2 Incident Response Plans?

Start with 3 free exercises in your working language — no credit card required. Or speak with our EU compliance team about building a structured NIS2 exercise programme.

Also explore: NIST CSF 2.0 Toolkit  ·  IEC 62443 Toolkit  ·  NERC CIP Toolkit