- Meaning
- Technical, operational and organisational measures
- Examples
- Encryption, access rights, training
- Origin
- GDPR, fits NIS2 as well
- Related
- Controls
- Updated
- June 2026
- Editorial team
- Compliance Compass
What are TOMs?
Technical and organisational measures (TOMs) bring together all the protective measures of an organisation: technical ones (encryption, MFA), organisational ones (roles, Security policies, training) and operational ones (monitoring, maintenance). They are security put into practice. The wording comes from Article 32 of the GDPR; in international standards the same measures are called Controls – in substance the two mean the same thing.
The three dimensions
- Technical: encryption, firewalls, backups, MFA, logging.
- Organisational: roles, policies, training, contracts with service providers.
- Operational: day-to-day running, monitoring, maintenance, regular testing.
Technical versus organisational measures
The dividing line is simple. Technical measures work through technology, organisational ones through rules and people. Where one of them fails on its own, the other side catches the damage – which is why Article 32 of the GDPR and Article 21 of NIS2 both call for both columns, not only one.
| Technical measures | Organisational measures |
|---|---|
| Disk and transport encryption (TLS, VPN) | Permission concept with documented roles |
| Multi-factor authentication (MFA) for administrative accounts | Training and awareness sessions for staff |
| Firewalls and network segmentation | Data processing agreements with service providers |
| Backups with tested restores | Contingency and reporting process (24 h / 72 h / 1 month) |
| Logging and tamper protection for logs | Regular review and approval of the Security policies |
TOMs and controls
In substance TOMs are almost identical to the Controls of the international standards world, for example Annex A of ISO 27001. TOMs is simply the short collective name for them. If you document your measures cleanly once, you can use the same evidence for data protection and for cybersecurity instead of maintaining two separate catalogues.
TOMs under the GDPR and NIS2
The term comes from Article 32 of the GDPR, but it fits the NIS2 Directive just as well: both require appropriate technical and organisational measures to protect data and systems. The level of the sanction depends on the classification. Article 34 of NIS2 sets minimum fine ceilings of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts. Whether your entity also has to register, in what form and by when, follows from the national law that transposes the directive.
An example: An energy supplier keeps one central TOM overview. For data protection it serves as evidence under Article 32 of the GDPR; in a NIS2 inspection the same list – extended by the reporting chain of 24 hours for the early warning, 72 hours for the update and one month for the final report – is submitted as proof of its risk management, so that it can show the competent authority without gaps which measure addresses which concrete risk. One list is enough for both.
What do you need to do?
- Bring the existing measures from data protection and IT together in a single TOM overview.
- Assign every measure to a concrete risk and to a responsible role holder.
- Close the gaps between the technical and the organisational column – both sides belong in the documentation.
- Test the effectiveness of the backups, the MFA and the reporting process at least once a year, do not only describe them.
- If you have not done so yet, check the registration rules of the authority responsible for you and keep the TOM overview ready for inspection.
Further reading: GDPR Article 32 (EUR-Lex)
Frequently asked questions
What does TOMs stand for?
TOMs stands for technical, operational and organisational measures that protect information and systems. Technical measures include encryption, firewalls and multi-factor authentication (MFA); organisational ones cover roles, policies and training as well as contracts with service providers. Operational measures cover day-to-day running, that is monitoring, maintenance and regular testing. Together, TOMs are security put into practice.
Where are TOMs required?
The wording comes from Article 32 of the GDPR, which requires technical and organisational measures for data protection. Article 21 of the NIS2 Directive asks for the same in substance: appropriate measures to protect network and information systems. Article 34 sets minimum fine ceilings for infringements of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.
What is the difference between TOMs and controls?
In substance there is hardly any difference between TOMs and controls. TOMs is the collective short form for the technical and organisational measures of Article 32 of the GDPR; controls is the term used in standards such as ISO 27001 and its Annex A. Both mean concrete protective measures derived from the risk analysis. If you document your measures cleanly once, you can use the same evidence for data protection and for cybersecurity.