A NIS2 compliance programme starts with a scope assessment. Organisations should review their sector, services in the EU, company size, affiliated entities, and critical operations. The Commission states that NIS2 introduces risk-management and incident-reporting requirements for entities in more sectors and, as a rule, for medium-sized and large entities in critical areas [4]. The final determination depends on national implementing legislation.
The second stage is the service and asset inventory. Critical business processes, supporting systems, data flows, and external providers should be identified. The purpose is not merely to count devices; it is to understand which services could be disrupted and what the consequences would be.
The third stage is the control framework. Access management, backups, multifactor authentication, vulnerability management, secure development, incident response, business continuity, and supply-chain controls should be designed together. Supplier security evidence should be complemented by contractual terms on incident notification, subcontractors, and service continuity.
The fourth stage is incident reporting. Roles and timelines should be defined from detection and triage to management escalation and communication with the competent authority. The CSIRT network and EU-CyCLONe support information exchange and coordinated management of large-scale incidents [4]. Internal procedures should align with these external coordination structures.
The final stage is measurement. Metrics such as critical-vulnerability age, asset-inventory accuracy, exercise results, supplier-assessment coverage, and response time should reach senior management. NIS2 compliance is not a static folder of policies; it is a cycle of testing, reporting, remediation, and improvement.