Skip to content
Back to the knowledge base

1

Risk analysis and security policy

2026-08-10

Cbw art. 21, third paragraph, opening (a) · NIS-2 art. 21(2)(a) · Cbb art. 6 and 7

Every organisation in scope of the Cybersecurity Act starts with two basics: an approved security policy and a way to assess risk. Without those two, nobody knows where the organisation is heading or which risks it knowingly accepts.

What this means in practice

Your board approves a security policy with a date and version number, assigns roles and authorities so no task is left unowned, and sets up a working security cycle in which the policy is reviewed periodically. You also record a risk management policy: which method you use, when a risk is acceptable, and which security requirements follow from it.

Why this is in the law

Without an approved policy and a risk method, a supervisor has no starting point to judge your other measures — the other nine measure families build on this one.

Measures in this family

  • MC-01 — Approved security policy for your IT
  • MC-02 — Roles, authorities and separation of duties
  • MC-03 — A working security cycle (management system)
  • MC-04 — Risk management policy with method and acceptance limits
  • MC-05 — Risk analysis, risk overview and security requirements

Sources

Also worth reading

Not sure yet whether this applies to you? Take the free scope check.

Take the free scope check