Compliance

NIS2 and backups: what Article 21 actually requires (and how to prove it)

Article 21 of the NIS2 directive mandates backup management and business continuity. Without documented restore testing, you are non-compliant. Here is what auditors expect and how to produce the evidence.

June 2026· 4 min read·fr

NIS2: "we take backups" is no longer enough

The NIS2 directive came into force with a transposition deadline of October 2024. It massively widens the scope of the original NIS directive: energy, transport, healthcare, but also postal services, waste management, food production, medical device manufacturing and digital providers. The general threshold: medium-sized businesses and above (50+ employees or €10M+ turnover), with some sectors in scope regardless of size.

If you're in scope — or a supplier to an entity that is — your backups are no longer just good practice. They're a legal obligation, with penalties attached.

What Article 21 says

Article 21 requires "appropriate and proportionate" cyber risk management measures, following an "all-hazards" approach. Among the minimum measures listed in paragraph 2, point (c) explicitly cites: business continuity, such as backup management and disaster recovery, and crisis management.

Three concrete implications:

  1. Backups must allow essential services to be restored within appropriate timeframes. That means defined RTOs/RPOs — and validated ones, not just declared ones.
  2. Backups must themselves be protected against ransomware and tampering.
  3. You must be able to prove it. Auditors expect evidence demonstrating that the organisation can restore its critical data without compromising its integrity.

The most common findings

NIS2 audit guides list recurring gaps that will sound familiar to many IT leaders:

  • backups exist, but the restore has never been tested;
  • RTOs and RPOs are written in the continuity plan, but never validated by a test;
  • no off-site or immutable copy, leaving backups exposed to ransomware;
  • policies on paper, but no evidence of execution (logs, test reports, timestamps).

That last point is the classic trap: having the policy without the evidence. In front of an auditor — or a regulator after an incident — a Word document describing the restore procedure is worth nothing without a trace of the tests actually performed.

What it costs not to do it

NIS2 penalties can reach €10M or 2% of worldwide turnover for essential entities (€7M or 1.4% for important entities). And NIS2 introduces direct accountability for management bodies: backup compliance is no longer an infra team topic, it's a board topic.

Turning the obligation into an automated routine

That's exactly the problem RestoreProof solves:

  • Scheduled restore tests (cron): every critical backup is restored in an ephemeral environment, on your infrastructure, at the frequency you define.
  • Functional validation, not just structural: the PostgreSQL/MySQL database is genuinely started and queried, expected files are checked, endpoints are tested.
  • Ed25519-signed evidence: every test produces a timestamped report cryptographically signed by your runner. That's a tamper-proof audit artefact, not a screenshot.
  • Data sovereignty: backup data and secrets never leave your infrastructure. Only the signed verdict is transmitted — which counts double in a NIS2 + GDPR context.

The result: instead of a painful annual exercise you keep postponing, you have a continuous history of restorability evidence, ready to present.

FAQ

Does NIS2 explicitly require restore testing? The directive requires "backup management and disaster recovery" (Art. 21(2)(c)) through appropriate and proportionate measures. Bodies such as ENISA, and audit guidance in general, treat regular, documented restore tests as the expected implementation of that requirement: an untested backup does not demonstrate recovery capability.

What backup evidence does a NIS2 auditor expect? Typically: the documented backup policy, RTOs/RPOs per critical asset, backup execution logs, and above all timestamped restore test reports comparing actual restore time against the defined objectives.

My company isn't in NIS2 scope — does this affect me? Possibly, indirectly: Article 21(2)(d) requires regulated entities to assess the security of their supply chain. If you supply an essential or important entity, you may be asked for assurances — including proof that your backups are restorable.


Sources to link: Directive (EU) 2022/2555, Article 21; ENISA implementation guidance; national transposition texts.

NIS2 backupNIS2 article 21NIS2 restore testingNIS2 backup compliancerestore evidence audit
Early access

Ready to prove your restores?

RestoreProof automates restore testing and produces cryptographically signed evidence — without your data ever leaving your infrastructure.