NIS2Cyber Governance5-minute read·Marcin Pajdzik·July 2026

Governing the NIS2 Gaps That Remain at Programme Close

A NIS2 programme may reach its planned end date with some findings still open. Supplier negotiations can take longer than expected, technical remediation may depend on wider investment, and new gaps can emerge while delivery is under way. Extending the programme until every issue disappears may be impractical because the obligations, systems and risk environment continue to change.

For the management body and programme sponsor, the close decision therefore depends on the governance of the remaining gaps. The organisation needs to know what remains unresolved, the exposure it creates, who will remediate it and how progress will remain visible after the programme structure stands down.

Deferral is a governance decision

A deferred finding remains an open compliance issue. Recording a risk acceptance does not satisfy the underlying obligation, establish compliance or constrain a competent authority's response. It records that the organisation understands the position and has made an authorised decision about how it will be managed for a defined period.

This distinction matters at programme close. A finding supported by a documented rationale, interim mitigation, accountable owner and committed remediation date remains governed. One that leaves the programme because time or budget has run out becomes an unmanaged gap, even if the programme reports it as deferred.

What a defensible decision contains

Every deferred finding should leave the programme with a decision record covering six things.

The precise gap
The record identifies what remains incomplete, the obligation involved, and the entities, services or jurisdictions affected. A broad description prevents decision-makers from understanding the exposure they are being asked to accept.
The reason for deferral
The record states why remediation could not be completed within the programme, and why carrying the exposure for the stated period is acceptable.
The remaining exposure
The decision explains the regulatory and operational consequences of leaving the gap open, including the potential effect on critical services and the organisation's ability to demonstrate its compliance position.
Interim treatment
Temporary measures reduce the exposure while full remediation is pending. Where none is available, that fact is made explicit because it changes the decision being taken.
Ownership and timing
A named owner carries the finding into business-as-usual operation with a funded remediation approach, milestones and a target completion date. The date is a governance commitment.
Approval and review
The record identifies who approved the deferral, when the position will be reviewed and where a delay or material change must be escalated.

Approval follows the significance of the gap

The programme mandate should define which deferrals the steering committee can approve and which require escalation. Every deferral is a risk acceptance, and the approval level should follow its consequence. A finding with limited legal or service impact can sit within the committee's authority. A material gap affecting legal compliance, a critical service or significant cyber risk warrants management body visibility and, where the governance framework requires it, approval.

Article 20 requires the management body to approve the organisation's cybersecurity risk management measures and oversee their implementation. It does not prescribe an internal approval route for every programme finding. Effective oversight nevertheless requires the management body to receive the material position. It cannot assess the adequacy of the measures while significant known limitations remain outside its view.

An acceptance has an expiry date

The decision remains valid only within the conditions on which it was made. If the remediation deadline passes, the finding must be closed, escalated or reassessed and approved again at the appropriate level. Allowing the date to pass without action converts a controlled deferral into an unmanaged compliance gap.

The gap register therefore continues beyond programme close. The sustained compliance owner tracks deferred findings, challenges overdue remediation and keeps material items visible through management body reporting. Each finding remains open until remediation is complete and supported by evidence.

How this affects your organisation

Before approving programme close, ask whether every material finding is either evidenced as closed or governed as an open obligation. For each open item, the decision record should show the reason for deferral, the remaining exposure, interim treatment, accountable owner, committed completion date and escalation route.

A programme can close with formally deferred work. The close decision is credible when the organisation can show what remains open, why, under whose authority, until when, and how each finding will be tracked, challenged, escalated and ultimately closed.

Preparing to close a NIS2 programme with findings still open?

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.

NIS2 Frameworks

If this briefing is relevant to your organisation, these frameworks set out how to act on it, with a structured starting point and a programme approach designed to deliver sustained compliance.

NIS2 Diagnostic FrameworkHow to Run a NIS2 Programme