Why the evidence matters before approval
Under NIS2, the management body approves the cybersecurity risk-management measures, oversees their implementation and must follow training. Those duties apply once the national requirements take effect for the organisation, whatever stage its programme has reached.
Without a clear understanding of scope, existing measures and material gaps, the management body may struggle to demonstrate informed approval and effective oversight. Supervisory authorities have inspection and information-gathering powers, and records of what leadership knew and decided can help demonstrate that oversight.
Five areas the evidence should cover
Some of this evidence may already exist internally, in which case leadership needs it brought together and tested.
- Scope
- Which entities and services fall within the NIS2 sectors, how each is likely to be classified, which national implementing requirements apply and when they take effect. Questions that need legal advice should be identified as open.
- Governance
- Whether an executive sponsor has the authority the programme needs, whether the management body understands its approval, oversight and training duties, and who will own compliance once the programme closes.
- Controls
- Where existing measures across the NIS2 risk-management areas are credible, where they are partial and where material gaps exist. An existing certification such as ISO 27001 can provide a starting point for this view, to the extent its scope covers the entities and services in question. This finding drives where the programme focuses and what it will cost.
- Incident reporting
- Whether the organisation can meet the applicable reporting deadlines. The general timetable requires an early warning without undue delay and within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report normally within one month of that notification. Gaps here may need action before the wider programme starts.
- Suppliers
- How the organisation assesses its direct suppliers' vulnerabilities, security practices and the quality of their products and services, and what its contracts currently require. Remediation can involve lengthy external dependencies, so identifying gaps early lets that work start sooner.
What leadership should receive before approving expenditure
The output should allow leadership to approve a programme with a clear view of what is known and what is assumed.
- Scope assessment
- The entities and services in scope, with unresolved legal questions identified.
- Immediate actions
- Work that cannot wait for the wider programme, such as gaps in incident reporting.
- Prioritised work
- The programme's priorities, with resource estimates and the material assumptions behind them.
- Ownership and delivery capacity
- Named executive owners for each area, and evidence that the work fits alongside existing commitments. Where delivery depends on technology, operations, procurement or legal teams, the plan should identify their agreed contribution and any competing priorities leadership must resolve.
- Confidence
- A clear distinction between verified findings and areas that need further investigation.
A short initial assessment, such as a five-day exercise, can support initial prioritisation where the organisation's structure allows it and evidence is accessible. Its findings should state their assumptions and confidence levels, and identify the follow-up work needed before cost estimates are firm.
Deciding what happens next
The assessment should recommend how to proceed. Depending on the findings, leadership may use any of these approaches, alone or in combination.
- Approve a defined programme
- Where scope, priorities and estimates are sufficiently supported to commit funding.
- Fund urgent work and further investigation
- Where material uncertainties remain, release limited funding for urgent remediation and for the work needed to resolve those uncertainties.
- Use existing teams
- Where the gaps are contained, address them through existing teams without a separate programme.
Whichever option is chosen, the funding proposal should identify which assumptions could materially change its cost or timetable, who will resolve them and when leadership will reconsider the estimate. Examples include unresolved scope questions, reliance on existing controls that have not been tested, supplier cooperation and competing demands on delivery teams.
Consider an organisation seeking funding for a new security monitoring platform. The assessment identifies an untested reporting process and unclear authority to notify. Leadership funds those immediate gaps and asks management to demonstrate what additional capability the platform would provide before approving the purchase.
Approval should also set a date for management to return with revised estimates, evidence of progress and decisions on the open questions. That review links the initial approval to continuing oversight.