NIS2Cyber Governance6-minute read·Marcin Pajdzik·March 2026

The Governance Foundations of a NIS2 Programme

NIS2 places substantive, ongoing obligations on the management body. Building a compliance position that meets them requires a governed programme, with a mandate, a defined scope and formal close conditions. Organisations that treat NIS2 as a list of controls to check off will find the position they have built is difficult to demonstrate and harder to sustain.

For senior leaders whose organisations fall within the scope of NIS2, the question is whether the programme they are sponsoring will leave a compliance capability that keeps working after it closes. The answer depends on how the programme is designed from the outset.

Why Article 20 shapes how a programme is scoped

Article 20 of NIS2 requires the management body to approve the organisation's cybersecurity risk management measures and oversee their implementation. Oversight is continuing, so a point-in-time remediation exercise cannot by itself satisfy it.

What follows from that is a matter of governance practice rather than statutory wording. Material changes to the measures should return to the management body for further approval. A management body that can produce dated approvals, a record of the reporting it received during delivery, and evidence that the approved controls are still maintained and reviewed after close is in a position to show how it discharged its approval and oversight responsibilities. One that cannot is relying on assertion.

Supervisory scrutiny is not confined to the moment a programme closes. It can arise through inspection, audit, an incident, or an indication of non-compliance, depending on whether the entity is classified as essential or important and on the applicable national law. An organisation that has completed a compliance project but built no mechanism for maintaining what it produced, and no reporting structure to keep the management body informed, will struggle to show that oversight continued. The programme's scope must account for what happens after it closes from the point it begins.

What distinguishes a governed programme

Five elements make a programme governed rather than merely active.

Programme mandate
A formally documented mandate is approved at management body level, establishing who holds programme authority, what decisions require management body approval, and what the governance forums are. Without it, the programme cannot make the decisions that arise across twelve to twenty-four months of delivery.
Gap register
The gap register records what the assessment found against the obligations applying in each jurisdiction, each finding owned and tracked to closure. It is the source from which the management body receives a consolidated view of the compliance position, and it carries into business-as-usual operation as the ongoing status record.
Target operating model
The design of the target compliance state is approved before delivery begins, specifying what each control looks like when complete, who owns it afterwards, and how it is evidenced and reviewed. Cross-checked against the full set of applicable obligations, it also shows that none has been left without a named owner.
Named workstream ownership
Each workstream has a named lead and defined close conditions across the full range of Article 21(2) obligations. A workstream does not close until its deliverables are built, evidenced, and confirmed as ready for named permanent owners to sustain.
Closure and handover record
Closure is formally documented, covering the incident notification exercise result and the closure report presented to the management body, with the sustained compliance owner confirmed in post before the programme stands down.

What the management body should ask before approving a programme

Four questions determine whether a programme brief will produce an adequate outcome. First, does a gap register exist that records findings against the obligations applying in each relevant jurisdiction, or is the programme scoped to a generic framework? The gap register is the foundation on which every delivery decision rests.

Second, is the target operating model a named programme deliverable, scoped and resourced before delivery begins, or is it deferred to programme close? A model assembled under pressure at the end of a long programme rarely receives the governance attention it requires.

Third, does each workstream have a named permanent owner confirmed before the workstream closes? Ownership that is not confirmed before handover is not ownership. Fourth, is the programme closure report to the management body a formal deliverable with defined approval conditions? Without formal management body sign-off on the outcome, the governance record of the programme is left incomplete.

How this affects your organisation

For senior leaders in organisations within the scope of NIS2, the programme brief presented for approval is the point at which the compliance position is shaped. A brief that scopes only to remediation, without a gap register, a target operating model, and named permanent ownership, is unlikely to leave a position the management body can stand behind.

Article 20 accountability applies to what exists after the programme closes. The management body is accountable for the approval it gives and the oversight it exercises, which is why the adequacy of the brief it approves is itself a governance decision.

To discuss how to structure a NIS2 programme that will leave an adequate compliance position, book a 20-minute advisory call.

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.

NIS2 Frameworks

If this briefing is relevant to your organisation, these frameworks set out how to act on it, with a structured starting point and a programme approach designed to deliver sustained compliance.

NIS2 Diagnostic FrameworkHow to Run a NIS2 Programme