All case studies
Cyber ResilienceSupply Chain & Logistics

Scope before commitment: a NIS2 diagnostic across a multinational logistics group

EU-headquartered, multinational logistics client · EU · Five days

Executive Summary

A multinational logistics group, headquartered in the EU with operations across multiple Member States, needed to establish whether it was in scope for NIS2, and if so, what a compliance programme would need to address, before committing to that investment. With entities spanning several jurisdictions and business lines, the group could not assume a single, uniform answer applied across every part of the business.

The group engaged Epitechnic for a five-day NIS2 Readiness Diagnostic. Day 1 identified that multiple legal entities within the group met the NIS2 sector and size criteria, across more than one Member State, so the diagnostic team and senior leadership agreed a group-level approach: assessing governance and controls at group level, with the entities carrying the most significant exposure examined in depth. Day 2 assessed whether the governance conditions, sponsorship, management body engagement, a credible sustained compliance owner, existed for a programme to succeed. Day 3 mapped maturity across the ten Article 21(2) domains. Day 4 tested the group's incident notification capability against the Article 23 timelines and reviewed its supply chain exposure. Day 5 synthesised the findings into a programme readiness brief for the management body.

The result was a defensible provisional scope position, an honest picture of where the group's governance and controls stood, and a clear, prioritised basis for the management body to decide whether and how to proceed to a full programme, before any larger investment was committed.

Business Challenge

A logistics group operating across multiple EU Member States faces a NIS2 scope question that is rarely simple. Different entities may sit in different sectors, meet different size thresholds, and fall under different national transpositions of the Directive, each with its own competent authority and supervisory expectations. Committing to a compliance programme without first resolving that picture risks building the wrong programme: either under-scoped, leaving genuine obligations unaddressed, or over-built, spending on entities and controls the actual legal position doesn't require.

The governance dimension carries its own risk. NIS2 places direct obligations on the management body, and a programme sponsored without genuine authority, or without the board's engaged oversight, tends to stall exactly when it meets organisational resistance. Left unaddressed, the group would be making a significant compliance investment decision without a clear, evidenced view of its actual exposure or its readiness to govern the work that would follow.

Success Criteria

  • A defensible provisional scope position across the group's entities, by sector, jurisdiction, and classification
  • An honest assessment of governance readiness against the management body's obligations
  • A maturity map across the ten Article 21(2) domains, identifying where the most significant gaps sit
  • An assessment of incident notification capability against the regulatory timelines
  • A view of supply chain exposure for the group's most significant supplier relationships
  • A programme readiness brief the management body could act on

Epitechnic Approach

Epitechnic ran the diagnostic exactly as designed: a five-day structured engagement, not a compliance opinion or a full gap assessment, producing a clear, honest picture of where the group stood. Because Day 1 identified multiple in-scope entities across several Member States, the diagnostic team and the group's senior leadership agreed, before Day 2 began, on a group-level approach: assess governance and controls at group level, and examine the entities carrying the most significant exposure in depth, with the remainder scoped for the full programme rather than covered shallowly across all of them.

Every finding was tied to evidence, document review checked against structured interviews, not documentation alone, and every output was built to feed directly into the programme decisions the management body would need to make.

Solution

Scope and jurisdiction

The group had never established a defensible, group-wide view of which entities were in scope for NIS2, across which sectors, and under which national laws. Epitechnic decided to establish provisional scope entity by entity, rather than assume the group's corporate structure mapped cleanly onto a single answer.

A scope position that hasn't been tested against the actual legal entity structure and service catalogue is not a position an organisation can commit a programme against with confidence. The result was a provisional scope statement identifying the in-scope entities, their likely classification, and the jurisdictions and competent authorities involved, along with an explicit log of the assumptions and uncertainties still requiring legal confirmation.

Governance readiness

The group had not tested whether the specific governance conditions, a genuinely authorised sponsor, an engaged management body, a credible sustained compliance owner, were actually in place. Epitechnic decided to assess governance readiness directly against the management body's Article 20 obligations, rather than assume good intentions were sufficient.

A programme sponsored without real authority, or governed by a board that has not genuinely engaged with its oversight obligation, tends to lose momentum the first time it meets resistance. The result was an honest governance readiness assessment, identifying which conditions were in place and which needed to be established before a programme could be governed adequately.

Control maturity and readiness

The group had no structured, group-wide view of where its security controls stood against the ten Article 21(2) domains, or of its actual capability to meet the incident notification timelines and manage supply chain risk. Epitechnic decided to map maturity across all ten domains, test incident capability against a realistic scenario, and assess supply chain exposure for the most significant supplier relationships, rather than rely on the group's own self-assessment of its controls.

A domain rated as "in place" on paper is only meaningful if it would hold up to a genuine incident or supervisory scrutiny; the diagnostic tests for that distinction directly. The result was a maturity map showing where credible arrangements existed, where they were partial, and where material gaps remained, prioritised by regulatory risk rather than treated as a uniform checklist.

Outcomes

Governance improvements: An honest governance readiness assessment, giving the management body a clear view of what needed to change before a programme could be governed adequately.

Risk reduction: A defensible provisional scope position and a prioritised maturity map, replacing an untested assumption of compliance with an evidenced picture of actual exposure.

Executive benefits: A programme readiness brief written specifically for the management body, giving it the basis to decide whether to proceed, and what to prioritise, before committing to a full programme investment.

Decision-making improvements: Programme decisions, scope, sponsorship, sequencing, made on a five-day evidence base rather than on assumption or internal confidence alone.

Why It Worked

The engagement worked because it answered the questions a NIS2 programme decision actually depends on, scope, governance readiness, and where the real gaps sit, before the group committed to the investment a full programme requires. Testing governance conditions directly, rather than assuming they existed, meant the resulting programme recommendation was grounded in whether the organisation could actually govern the work, not just whether it needed to be done.

Client Testimonial

[Client testimonial to be added]

Key Takeaways

Challenge: A multinational logistics group needed to establish its NIS2 exposure and readiness across multiple EU entities before committing to a full compliance programme.

Approach: A five-day diagnostic established provisional scope, tested governance readiness against the management body's obligations, mapped control maturity, and assessed incident and supply chain readiness.

Outcomes: A defensible scope position, an honest governance and control picture, and a programme readiness brief giving the management body a clear basis for its next decision.

Lessons: Establishing scope and governance readiness before committing to a full programme prevents both under-scoping a genuine obligation and over-building a programme the actual legal position doesn't require.

Start the conversation

Facing a similar situation?

Talk to us

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.