NIS2 is a standing obligation
Supervisory authorities can require essential and important entities to produce evidence that their security measures are effective and current. That obligation is not tied to a programme cycle. An inspection, a targeted audit or a significant incident can trigger it at any point.
Where no adequate permanent mechanism exists, the compliance position starts to degrade from the point the programme closes. Risk assessments become stale and controls in place at programme close go unmonitored. Gaps carried at close lose their owners. Legal overlays fall behind national transpositions. The incident notification capability drifts as staff change and systems evolve, and supplier assurance lapses without review. A supervisory review conducted a year after programme close assesses the position as it stands at that point, and any drift accumulated in the intervening year becomes visible.
The operating model needs a named owner, the sustained compliance owner, identified during the programme rather than nominated at its close. This is typically the CISO, CRO or General Counsel, someone who already holds standing risk or compliance responsibilities and has the organisational standing to maintain access to the management body. The programme hands this person the compliance position formally, as a documented transfer of responsibility. From that point they coordinate the eight areas below, each of which sits with the function best placed to run it. Deterioration in any of them is escalated to the management body.
What the operating model must include
The compliance operating model covers eight areas, each with a named owner, the evidence it generates, and the cycle on which it is reviewed.
- Governance and policy
- Policies stay owned and current, and the legal overlay records how national law diverges in each jurisdiction. Management body resolutions, reporting records and training records all carry evidential weight.
- Risk management
- The risk register is maintained between reviews, control testing shows whether the measures work, and the resulting position reaches the management body through a defined reporting line.
- Access control
- Access to critical systems is granted, changed and removed through a controlled process, reviewed on a defined cycle, with a record of who approved what.
- System security
- Known vulnerabilities are fixed or formally accepted, systems are patched and monitored on a standing cycle, and each acceptance is dated and recorded.
- Operational resilience
- Critical services can be recovered within defined objectives, continuity and crisis arrangements name who decides and who communicates, and both are exercised on a set schedule.
- Incident readiness
- The capability to detect, classify, escalate and notify within the Article 23 deadlines is tested annually, and notification authority is named for any hour of the day.
- Supply chain
- Supplier risk is reassessed on a defined cycle under Article 21(2)(d), contractual obligations are enforced, and material changes are tracked between assessments.
- Training and awareness
- Training reaches general staff, specific roles, and the management body under Article 20(2), and each audience is evidenced in its own right.
The gap register runs across all eight, recording where the position stands. An annual review consolidates it for the management body.
Scoping for sustained compliance
The operating model should be a programme deliverable, scoped from the outset and built in parallel with the remediation workstreams. An organisation that defers this design to programme close will lack the governance attention and programme structure to produce an adequate result.
Article 20 requires the management body to approve the cybersecurity risk management measures and oversee their implementation on an ongoing basis. Extending that approval formally to the operating model is sound governance practice, applied in two steps. The proposed model is approved during programme design, so the programme builds against an approved blueprint rather than an assumed one. At programme close, the management body confirms that the model is operating, evidenced and transferred into business-as-usual operation, with permanent owners in place, rather than encountering it for the first time. The measures require ongoing oversight under Article 20, and maintaining equivalent oversight of the model is a practical mechanism through which the management body sustains that oversight of the underlying measures.