Requirements5AI extractedStatus is derived from each row's mapping
Ref
Regulatory requirement
Interpretation AI
Status
Scope
Art. 21(2)(a)
Requirement
Essential and important entities shall take measures including policies on risk analysis and information system security.
Maintain a documented risk-analysis methodology and an information security policy approved by management.
Confidence 92%
Partial
Country-specific
FRIENLDE
›
Art. 21(2)(b)
Requirement
Measures shall include incident handling.
Operate an incident handling capability with detection, triage, response, and post-incident review.
Confidence 90%
Partial
Country-specific
FRIENLDE
›
Art. 23
Requirement
Entities shall notify, without undue delay, the CSIRT or competent authority of any incident having a significant impact (early warning within 24 hours).
Each country has its own notification route and clock — the 24h early warning must be wired to the right national CSIRT per entity.
Confidence 88%
Gap
Country-specific
FRIENLDE
›
Art. 21(2)(d)
Requirement
Measures shall include supply chain security, including security-related aspects of relationships with direct suppliers or service providers.
Assess and contractually bind the security posture of direct suppliers, with particular attention to ICT providers.
Confidence 87%
Gap
Country-specific
FRIENLDE
›
Art. 20
Requirement
Management bodies of essential and important entities shall approve the cybersecurity risk-management measures and oversee their implementation.
The board must formally approve and oversee cybersecurity measures; members may be liable for breaches.