The classic trap
Recital 81 introduces the proportionality principle for cybersecurity measures: neither under-investment nor over-engineering. In practice, the ILR sanctions two opposite drifts: the entity that invokes proportionality to do nothing ('we are only an important entity'), and the one that deploys a 24/7 SOC without having documented why its risk justifies it. Without a formalised risk analysis that justifies each measure against state-of-the-art and cost, you are exposed from both sides.
The proportionality test the ILR will expect
For each measure of article 21(2) NIS 2, you must be able to answer four opposable questions:
- Risk addressed: which concrete threat scenario (ransomware, supply chain, denial of service) does this measure mitigate, with what likelihood and measured impact?
- State of the art: which recognised standard (ISO 27001:2022, ENISA, NIST CSF 2.0, BSI IT-Grundschutz) recommends this measure for your sector and size?
- Implementation cost: what is the cost (CAPEX, OPEX, FTE) compared to the cost of the avoided incident and the entity's revenue?
- Documented decision: who arbitrated inclusion or exclusion of the measure, on what basis, and when will the decision be reassessed?
How Luxgap automates this risk
Our Luxgap Proportionality Engine turns the abstract principle of recital 81 into a decision matrix opposable to the ILR, automatically generated from your actual risk profile. The tool combines your asset mapping (pulled from Active Directory, Microsoft Defender, CrowdStrike, Wazuh, Azure Sentinel), your exposure (continuous external scan, ENISA threat intel and ILR CTI) and your financial profile (revenue, headcount, annex I or II sector) to compute, measure by measure of article 21(2), a justified proportionality score.
- Calculates for each risk-management measure a cost-benefit score based on your real exposure and benchmarks it against ENISA and ISO 27001:2022 sector baselines.
- Detects under-sized measures (high risk, weak or absent control) and over-sized measures (cost disproportionate to residual risk).
- Automatically generates the Statement of Applicability compliant with ISO 27001 annex A, with written justification for every inclusion or exclusion.
- Continuously reassesses the score and alerts on Teams or email whenever a change (new critical asset, CVSS > 8 vulnerability, new ENISA standard) challenges proportionality.
- Produces a time-stamped, cryptographically sealed PDF dossier, opposable to the ILR during an inspection, demonstrating that each measure trade-off was documented, dated and signed.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS brick depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual asset mapping, with a free 48h white audit to measure the alignment of your current measures with the NIS 2 proportionality principle.