NIS2 compliance steps should not begin with a policy template or a last-minute evidence chase. They should begin with a clear answer to a more useful question: where does your organisation face cyber risk, and who is responsible for reducing it? NIS2 raises expectations for governance, incident readiness and demonstrable risk management. The organisations that make progress fastest treat it as an ongoing improvement programme, not a one-off certification exercise.
The Directive applies differently according to your sector, size, services and the national legislation in the EU Member State where you operate. That makes legal and regulatory advice important when confirming scope. Once you know it applies, the practical work is consistent: understand your position, improve what matters most, and prove that the work is happening.
The NIS2 compliance steps that create control
1. Confirm your scope and obligations
Start by establishing whether your organisation is within scope, whether it may be classified as an essential or important entity, and which national rules apply. NIS2 covers a broader range of sectors than its predecessor, including areas such as energy, transport, health, digital infrastructure, managed services, manufacturing and public administration.
Do not rely only on headcount or turnover thresholds. Some organisations can be included because of their role, criticality or the services they provide. Map the legal entities, countries of operation, regulated services and key dependencies. Record the result, the assumptions behind it and the person responsible for keeping it current.
This step prevents a common problem: spending months implementing controls without knowing the reporting duties, supervisory approach or sector-specific requirements that apply to your business.
2. Give management clear accountability
NIS2 places responsibility with management bodies. Senior leaders are expected to approve and oversee cyber risk-management measures, understand the organisation’s exposure and receive appropriate training. Cybersecurity cannot sit solely with IT while the board receives a once-a-year compliance update.
Set a clear governance rhythm. Management should receive concise reporting on material risks, overdue actions, significant incidents, supplier exposure and the effectiveness of improvement activity. They do not need every technical detail. They do need enough information to challenge priorities, make decisions and demonstrate oversight.
Assign named owners for the programme, each major risk area and every remediation action. Shared responsibility often means no responsibility when an incident occurs or an auditor asks for proof. Accountability works when it is visible, realistic and reviewed.
3. Build an honest view of your current posture
A gap assessment is useful only when it reflects how the organisation actually operates. Compare existing controls, policies, technical measures and working practices against the NIS2 risk-management requirements and relevant national guidance.
Look beyond written documentation. A policy stating that backups are tested is not evidence that recovery works. A supplier assessment process is not effective if business teams can appoint critical providers without using it. Ask for operational evidence: configuration records, test results, access reviews, training completion, incident exercises, supplier assessments and management decisions.
Assessments should also identify dependencies. Many cyber risks sit across Microsoft 365, identity systems, cloud services, outsourced IT and business applications. Understanding how these services support critical operations gives you a more meaningful view than a checklist of isolated controls.
4. Prioritise risks before writing a long action plan
NIS2 expects proportionate measures, not identical controls in every organisation. The right order depends on your critical services, threat exposure, existing maturity and ability to recover. A small provider with weak identity controls and no tested incident process should not begin by rewriting every policy.
Prioritise actions that reduce material risk and improve your ability to respond. For many organisations, this means strengthening identity and access management, multi-factor authentication, vulnerability management, backups and recovery, logging, incident response, staff awareness and supplier controls.
Give each action an owner, target date, expected outcome and evidence requirement. Be specific. “Improve patching” is vague. “Apply critical security updates to internet-facing systems within the agreed timeframe, with monthly exception review” is measurable. This creates a plan that teams can deliver and leaders can track.
Put the NIS2 compliance steps into daily practice
5. Establish workable incident management and reporting
NIS2 introduces strict incident-reporting expectations. In general, significant incidents may require an early warning within 24 hours, a notification within 72 hours and a final report within one month. National implementation may add detail, define thresholds differently or set further duties, so your process must reflect the rules that apply to you.
The practical challenge is deciding quickly whether an event is significant, who has authority to escalate it and how to assemble accurate information without disrupting response work. Create a tested incident process that covers technical containment, business impact assessment, internal escalation, regulator communication, customer communication and post-incident learning.
Run tabletop exercises with IT, senior management, legal, communications and operational teams. A plan that has not been rehearsed is a set of assumptions. Exercises expose missing contacts, unclear decision rights and dependencies that only become visible under pressure.
6. Control third-party and supply-chain risk
Your cyber resilience is affected by the suppliers who host data, manage systems, provide software or support essential business processes. NIS2 expects organisations to consider supply-chain security, including vulnerabilities associated with direct suppliers and service providers.
Start with the suppliers that matter most to continuity, sensitive information and critical services. Understand what they access, what data they hold, where they operate, their security commitments, their incident-notification obligations and your options if they fail. Contract language matters, but so does ongoing assurance.
Avoid treating supplier reviews as a procurement form completed once. Reassess critical providers when services change, incidents occur, contracts renew or new intelligence changes the risk picture. For smaller organisations, this may mean a focused review of a manageable number of key suppliers rather than an unworkable programme covering every low-risk vendor.
7. Turn evidence into a continuous process
Compliance becomes difficult when evidence is scattered across inboxes, shared drives and spreadsheets. It becomes harder still when nobody knows whether that evidence is current. Build a simple evidence model around each requirement: what proves the control operates, who provides it, how often it is collected and who reviews it.
Automated collection can reduce manual effort for areas such as identity configuration, device posture and security settings. It should not replace judgement. A technical signal may show that a setting is enabled, but people still need to decide whether it addresses the relevant risk and whether exceptions are acceptable.
Cyber Fundamentals AI can bring assessments, mapped requirements, evidence, remediation actions and reporting into one workspace. This helps teams see what is missing, assign the next action and show progress without duplicating work across NIS2, Cyber Essentials, Cyber Fundamentals and ISO 27001-aligned controls.
8. Measure improvement and keep reviewing
NIS2 compliance is not complete when a gap assessment is signed off. Systems change, suppliers change, threats change and evidence expires. Set a regular review cycle for risks, controls, actions and reporting. The frequency should reflect the importance of the service and the pace of change, not an arbitrary annual date.
Useful measures include the percentage of critical actions completed on time, overdue high-risk findings, backup recovery test outcomes, incident exercise results, privileged-access review completion and the status of evidence for key controls. Use these measures to identify trends, not merely to create green dashboards.
For boards and senior leaders, report the direction of travel: the most significant risks, what has improved, what remains exposed, decisions needed and confidence in recovery. For technical teams, retain the detailed findings and actions needed to make that progress real.
The goal is not to produce more compliance paperwork. It is to make informed cyber risk decisions, improve the safeguards that protect critical services and retain credible evidence that the organisation is doing what it says. Start with a current view of your posture, assign the next actions to named people and keep the evidence moving with the work. That is how NIS2 becomes manageable and resilience becomes visible.
