NIS26-minute read·Marcin Pajdzik·December 2025

What Leadership Needs to Know Before Funding a NIS2 Programme

Leadership that approves a NIS2 programme without knowing which entities are in scope, which measures already exist and where the material gaps lie risks funding work in the wrong places and missing work that matters.

Before substantial funding is committed, the executive team should assemble evidence on scope, governance, controls, incident reporting and suppliers, and propose priorities, funding and ownership. The board should scrutinise material exposure, the adequacy of the proposed response and unresolved assumptions. Urgent remediation should continue while those uncertainties are resolved.

Why the evidence matters before approval

Under NIS2, the management body approves the cybersecurity risk-management measures, oversees their implementation and must follow training. Those duties apply once the national requirements take effect for the organisation, whatever stage its programme has reached.

Without a clear understanding of scope, existing measures and material gaps, the management body may struggle to demonstrate informed approval and effective oversight. Supervisory authorities have inspection and information-gathering powers, and records of what leadership knew and decided can help demonstrate that oversight.

Five areas the evidence should cover

Some of this evidence may already exist internally, in which case leadership needs it brought together and tested.

Scope
Which entities and services fall within the NIS2 sectors, how each is likely to be classified, which national implementing requirements apply and when they take effect. Questions that need legal advice should be identified as open.
Governance
Whether an executive sponsor has the authority the programme needs, whether the management body understands its approval, oversight and training duties, and who will own compliance once the programme closes.
Controls
Where existing measures across the NIS2 risk-management areas are credible, where they are partial and where material gaps exist. An existing certification such as ISO 27001 can provide a starting point for this view, to the extent its scope covers the entities and services in question. This finding drives where the programme focuses and what it will cost.
Incident reporting
Whether the organisation can meet the applicable reporting deadlines. The general timetable requires an early warning without undue delay and within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report normally within one month of that notification. Gaps here may need action before the wider programme starts.
Suppliers
How the organisation assesses its direct suppliers' vulnerabilities, security practices and the quality of their products and services, and what its contracts currently require. Remediation can involve lengthy external dependencies, so identifying gaps early lets that work start sooner.

What leadership should receive before approving expenditure

The output should allow leadership to approve a programme with a clear view of what is known and what is assumed.

Scope assessment
The entities and services in scope, with unresolved legal questions identified.
Immediate actions
Work that cannot wait for the wider programme, such as gaps in incident reporting.
Prioritised work
The programme's priorities, with resource estimates and the material assumptions behind them.
Ownership and delivery capacity
Named executive owners for each area, and evidence that the work fits alongside existing commitments. Where delivery depends on technology, operations, procurement or legal teams, the plan should identify their agreed contribution and any competing priorities leadership must resolve.
Confidence
A clear distinction between verified findings and areas that need further investigation.

A short initial assessment, such as a five-day exercise, can support initial prioritisation where the organisation's structure allows it and evidence is accessible. Its findings should state their assumptions and confidence levels, and identify the follow-up work needed before cost estimates are firm.

Deciding what happens next

The assessment should recommend how to proceed. Depending on the findings, leadership may use any of these approaches, alone or in combination.

Approve a defined programme
Where scope, priorities and estimates are sufficiently supported to commit funding.
Fund urgent work and further investigation
Where material uncertainties remain, release limited funding for urgent remediation and for the work needed to resolve those uncertainties.
Use existing teams
Where the gaps are contained, address them through existing teams without a separate programme.

Whichever option is chosen, the funding proposal should identify which assumptions could materially change its cost or timetable, who will resolve them and when leadership will reconsider the estimate. Examples include unresolved scope questions, reliance on existing controls that have not been tested, supplier cooperation and competing demands on delivery teams.

Consider an organisation seeking funding for a new security monitoring platform. The assessment identifies an untested reporting process and unclear authority to notify. Leadership funds those immediate gaps and asks management to demonstrate what additional capability the platform would provide before approving the purchase.

Approval should also set a date for management to return with revised estimates, evidence of progress and decisions on the open questions. That review links the initial approval to continuing oversight.

How this affects your organisation

For leadership preparing to approve a NIS2 programme, evidence on scope, existing measures and material gaps shapes whether the investment reaches the right work. Where that evidence already exists internally, it needs to be brought together and tested before approval.

Urgent remediation, particularly in incident reporting, should continue while uncertainties are resolved. A record of what leadership knew and decided at approval, followed by a scheduled review, gives the management body a basis for demonstrating its oversight.

If you are preparing to approve a NIS2 programme, I can help establish the evidence leadership needs before committing funding.

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.

NIS2 Frameworks

If this briefing is relevant to your organisation, these frameworks set out how to act on it, with a structured starting point and a programme approach designed to deliver sustained compliance.

NIS2 Diagnostic FrameworkHow to Run a NIS2 Programme