NIS2 Directive
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

NIS2 Directive Art.21.4: Take corrective measures without undue delay on finding that the measures are not met

When an entity finds that it does not comply with the measures required by Article 21(2), it must take all necessary, appropriate and proportionate corrective measures without undue delay. The duty is self-triggering, which is what makes it demanding: it attaches on the entity's own discovery, not on a regulator's finding, so the internal assurance work required by Article 21(2)(f) feeds straight into it. What an auditor should be able to see is the path from a known gap to corrective action within a defensible time, with proportionality applied to the urgency rather than used as a reason to defer. A finding register carrying long-overdue items with no interim mitigation is the direct evidence of failure against this paragraph.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 38 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 3 controls

  • C5-COM-03 Internal audits of the information security management system
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures
  • C5-SP-03 Exceptions from Existing Policies and Instructions

CIS Controls v8 · 3 controls

  • CIS-18.3 Remediate Penetration Test Findings
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.7 Remediate Detected Vulnerabilities

ISO 27001:2022 · 3 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 3 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.8 Management of technical vulnerabilities
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked

NIST SP 800-53 Rev 5 · 3 controls

PCI DSS 4.0 · 3 controls

  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 6.2.3.1 6.2.3.1 Manual code review independence and approval

APRA CPS 234 · 2 controls

  • CPS234-28 Escalation of Unremediated Testing Deficiencies
  • CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days

CMMC 2.0 · 2 controls

FedRAMP High · 2 controls

  • CA-5 Plan of Action and Milestones
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))

FedRAMP Moderate · 2 controls

  • CA-5 Plan of Action and Milestones
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))

NIST SP 800-171 Rev 3 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)

DORA · 1 control

  • DORA-Art.50 Administrative penalties and remedial measures

EU AI Act · 1 control

GDPR · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.21.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 38 it maps to, and the evidence behind each claim, over MCP and REST.