NIS2Cyber Governance6-minute read·Marcin Pajdzik·June 2026

A NIS2 Programme Should Leave an Operating Model Behind

When a NIS2 programme closes, the steering committee stands down and the programme team disperses. The regulatory obligations continue: controls require ongoing verification and evidence, risk assessments require refreshing, the incident notification capability requires testing, and the management body needs reporting to exercise oversight. Each of these needs to be designed, owned and handed over before the programme closes.

For senior leaders whose organisations fall within the scope of NIS2, the question to ask of a running programme is whether it will deliver a compliance operating model alongside the remediation measures, with confirmed permanent ownership for each function in place before it closes.

NIS2 is a standing obligation

Supervisory authorities can require essential and important entities to produce evidence that their security measures are effective and current. That obligation is not tied to a programme cycle. An inspection, a targeted audit or a significant incident can trigger it at any point.

Where no adequate permanent mechanism exists, the compliance position starts to degrade from the point the programme closes. Risk assessments become stale and controls in place at programme close go unmonitored. Gaps carried at close lose their owners. Legal overlays fall behind national transpositions. The incident notification capability drifts as staff change and systems evolve, and supplier assurance lapses without review. A supervisory review conducted a year after programme close assesses the position as it stands at that point, and any drift accumulated in the intervening year becomes visible.

The operating model needs a named owner, the sustained compliance owner, identified during the programme rather than nominated at its close. This is typically the CISO, CRO or General Counsel, someone who already holds standing risk or compliance responsibilities and has the organisational standing to maintain access to the management body. The programme hands this person the compliance position formally, as a documented transfer of responsibility. From that point they coordinate the eight areas below, each of which sits with the function best placed to run it. Deterioration in any of them is escalated to the management body.

What the operating model must include

The compliance operating model covers eight areas, each with a named owner, the evidence it generates, and the cycle on which it is reviewed.

Governance and policy
Policies stay owned and current, and the legal overlay records how national law diverges in each jurisdiction. Management body resolutions, reporting records and training records all carry evidential weight.
Risk management
The risk register is maintained between reviews, control testing shows whether the measures work, and the resulting position reaches the management body through a defined reporting line.
Access control
Access to critical systems is granted, changed and removed through a controlled process, reviewed on a defined cycle, with a record of who approved what.
System security
Known vulnerabilities are fixed or formally accepted, systems are patched and monitored on a standing cycle, and each acceptance is dated and recorded.
Operational resilience
Critical services can be recovered within defined objectives, continuity and crisis arrangements name who decides and who communicates, and both are exercised on a set schedule.
Incident readiness
The capability to detect, classify, escalate and notify within the Article 23 deadlines is tested annually, and notification authority is named for any hour of the day.
Supply chain
Supplier risk is reassessed on a defined cycle under Article 21(2)(d), contractual obligations are enforced, and material changes are tracked between assessments.
Training and awareness
Training reaches general staff, specific roles, and the management body under Article 20(2), and each audience is evidenced in its own right.

The gap register runs across all eight, recording where the position stands. An annual review consolidates it for the management body.

Scoping for sustained compliance

The operating model should be a programme deliverable, scoped from the outset and built in parallel with the remediation workstreams. An organisation that defers this design to programme close will lack the governance attention and programme structure to produce an adequate result.

Article 20 requires the management body to approve the cybersecurity risk management measures and oversee their implementation on an ongoing basis. Extending that approval formally to the operating model is sound governance practice, applied in two steps. The proposed model is approved during programme design, so the programme builds against an approved blueprint rather than an assumed one. At programme close, the management body confirms that the model is operating, evidenced and transferred into business-as-usual operation, with permanent owners in place, rather than encountering it for the first time. The measures require ongoing oversight under Article 20, and maintaining equivalent oversight of the model is a practical mechanism through which the management body sustains that oversight of the underlying measures.

How this affects your organisation

For C-level executives in organisations within the scope of NIS2, a programme that closes the identified gaps but delivers no operating model has produced an incomplete result.

The management body's accountability under Article 20 does not stand down when the programme does. Ongoing oversight of cybersecurity risk management is a formal obligation. A management body that approved a programme plan without the operating model in scope has not given itself a credible basis for knowing how that oversight will continue once the programme ends.

Running a NIS2 programme and thinking about what sustained compliance looks like after it closes?

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.

NIS2 Frameworks

If this briefing is relevant to your organisation, these frameworks set out how to act on it, with a structured starting point and a programme approach designed to deliver sustained compliance.

NIS2 Diagnostic FrameworkHow to Run a NIS2 Programme