Above the enumerated list in Article 21(2) sits a duty to size the whole programme correctly. Measures must be technical, operational and organisational together, must protect both the network and information systems and the physical environment those systems sit in, and must aim at preventing or minimising incident impact on the recipients of the entity's services and on other services downstream. Proportionality is defined rather than left open: the entity weighs the state of the art, relevant European and international standards where they apply, and the cost of implementation against its own degree of exposure to risk, its size, and the likelihood and severity of incidents including their societal and economic impact. The auditable artefact is therefore the reasoning, not just the control set. An entity that deployed a generic baseline can satisfy Article 21(2) point by point and still fail this paragraph, because nothing shows the level of security chosen was appropriate to the risks it actually faces.
NIS2 Directive Art.21.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.