All briefings
NIS2Regulation

Answering the NIS2 scope question before you commit to a programme

By Marcin Pajdzik ·

Scope decisions shape every later stage of a NIS2 programme. A gap assessment run against the wrong scope can produce findings that map to the wrong obligations, and controls built across the wrong systems may protect only part of the organisation. Either error can stay hidden until a supervisor or an incident tests where the boundary was drawn.

Before deciding what NIS2 requires it to do, a board needs answers to three narrower questions. Which of our legal entities are in scope, and under which national law? Do we have the governance to run a programme of this size? Where are the gaps that matter most? A five-day diagnostic gives the board an evidenced starting position for authorising mobilisation, further assessment and urgent action.

A decision the board cannot delegate

NIS2 makes the management body accountable. Its members approve the cybersecurity risk management measures, oversee their implementation, undergo training, and can be held liable for the entity's infringements of those measures. The board's approval of a programme creates a clear entry in the governance record a supervisor may ask to see, and that record is strongest when it shows specific, dated decisions taken on clear information.

Three risks that start before delivery

Each of the following can take root before delivery work starts.

The first is scope settled by assumption. Group structures can put different entities in scope in different Member States, national transpositions differ materially, and competent authorities can designate entities the headline criteria would miss. The obligation attaches to the legal entity that provides the service, which may be an operating subsidiary. A group that applies one country's answer everywhere risks spending where the law does not require it, or leaving an in-scope entity exposed.

The second is sponsorship that exists in name. A programme that crosses legal, procurement, operations and finance needs a sponsor with authority over all of them and the time to use it. Without one, the programme can fall to the security function, which may hold no authority over procurement contracts, legal positions or budgets, and the work that depends on those functions can stall.

The third is readiness that exists on paper. Where procedures are approved without the capability behind them being exercised, the first real test of the early warning, due without undue delay and within 24 hours of becoming aware of a significant incident, can be a live incident, possibly out of hours, with a decision chain nobody has rehearsed. Supplier work carries a similar timing risk. Renegotiating security terms with a major technology supplier can take several months, depending on the supplier's position and the contract cycle, so a programme that starts this work late can reach its close date with those contracts still open.

Each is easier to address at the start, before the plan and the budget are built around it.

Building a provisional scope position

Consider an illustrative group operating across several Member States. A holding company owns a food producer, a retailer selling its own products online and a shared IT services company.

An initial review identifies the food production business as provisionally in scope. The holding company and the retailer appear outside scope based on their activities. The shared IT company needs further legal review to establish its position and the applicable jurisdiction.

The board can then commission targeted legal confirmation, prioritise the exposed business and decide how shared IT dependencies affect the programme. Each unresolved question has an owner and a next step. The diagnostic gives the board this form of answer, setting out what is known, what remains uncertain and what to authorise next.

Five days is a deliberate constraint

Five days is long enough to establish a provisional position on evidence and short enough to run inside a live organisation. The days need not be consecutive, and each participant needs a few focused hours. A senior facilitator independent of the functions being assessed leads the document review, structured interviews and working sessions.

The five days rest on preparation that starts earlier. At least five working days before the first session, the organisation receives a document request covering its group structure and entity data, board and governance papers, policies and risk records, continuity plans, incident history and its most significant supplier contracts. The facilitating team reviews that material in advance, so the sessions test how arrangements work in practice. Where a requested document does not exist, its absence is recorded as a finding.

Scope comes first, because everything else is measured against it. Where several entities in several Member States are in scope, leadership agrees where the diagnostic goes deep, and the others become named programme priorities. Governance follows, because later decisions in the programme need someone with the authority to take them. Controls, incident readiness and supplier exposure come next, with incident notification tested through a realistic scenario against the organisation's actual monitoring, people and contacts. The final day brings the findings together.

What the diagnostic delivers

The findings are presented at a readout, and the engagement delivers six outputs.

  • A provisional scope statement and jurisdiction map, with assumptions recorded for legal confirmation
  • A governance readiness assessment covering sponsorship and management body engagement
  • A maturity map across the ten areas of required security measures
  • An incident notification capability assessment
  • A supply chain exposure map identifying critical supplier dependencies and gaps in contractual security responsibilities
  • A programme readiness brief of no more than four pages for the management body, covering resourcing, sequencing and immediate actions

Each output feeds mobilisation directly. The provisional scope becomes the brief for legal advice in each Member State, and the maturity map becomes the starting point for the full gap assessment.

Four decisions for the executive

The diagnostic closes with four decisions for the executive to take and the management body to approve.

  1. Scope. Whether to accept the provisional scope as the working basis, and who commissions the legal confirmation it needs in each jurisdiction.
  2. Sponsorship. Who sponsors the programme, confirmed by name and with the accountability accepted.
  3. Programme. Whether to authorise mobilisation and the full gap assessment. The readout indicates the dedicated resource the programme will need and which workstreams should start first. The full programme budget follows that assessment and the design of the target state, with a timeline that depends on existing security maturity, supply chain complexity and the number of Member States involved.
  4. Immediate action. Which gaps, such as a missing notification capability, to close now ahead of the wider programme.

Funding the next stage

The diagnostic gives the board a basis for funding the next stage. Mobilisation and the full gap assessment then develop the basis for the wider programme investment.

The NIS2 Readiness Diagnostic is a fixed scope, five-day engagement that gives the management body a provisional scope position and an evidenced view of its readiness. Scope before commitment describes a diagnostic for a multinational logistics group. To discuss one for your organisation, request a diagnostic.

References

  • Directive (EU) 2022/2555 of the European Parliament and of the Council on measures for a high common level of cybersecurity across the Union (NIS2 Directive), Official Journal L 333, 27 December 2022.
  • Commission Recommendation 2003/361/EC concerning the definition of micro, small and medium-sized enterprises.
Start the conversation

Facing this in your organisation?

Talk to us

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.