NIS2Cyber Governance5-minute read·Marcin Pajdzik·February 2026

The Scope Decision Behind a Credible NIS2 Programme

A programme scoped too broadly cannot be delivered in time. One scoped too narrowly produces gaps that surface during supervisory inspection rather than during the programme. Both result from the same mistake: treating regulatory scope as programme scope rather than as its starting point.

For a management body approving a NIS2 programme, scope is the first substantive decision. It determines cost, timeline and the credibility of the compliance position the programme will produce.

The two scope questions

Regulatory scope and programme scope must be answered separately. Regulatory scope establishes which entities are in scope, which services qualify, and whether the organisation is classified as essential or important under NIS2. Programme scope is a different question: what does the programme actually need to do, at what scale, over what timeline, given the current security position.

The regulatory determination confirms what obligations apply and which entities carry them. The gap between current security maturity and those obligations, and what a proportionate programme looks like given the enforcement position, are questions a gap assessment answers.

What determines the size of the programme

Three inputs shape the size and structure of a NIS2 programme. The first is the gap between current security maturity and what NIS2 requires. A mature organisation with established controls across most areas will have a narrower programme than one building from a lower baseline. The gap assessment is the document the sizing decision rests on.

The second input is the number of in-scope entities and whether they share a security baseline. An organisation with multiple legal entities in scope may run a single programme or may need separate treatment for entities with materially different risk profiles, operating environments or applicable national implementations.

The third is the enforcement position in the relevant Member States. National transposition status and supervisory activity vary by jurisdiction. A programme running eighteen months may be adequate where active supervision has not yet begun, and too slow where enforcement is already under way.

The design principle for workstreams

The most common workstream design mistake is organising work around the organisation's internal structure: IT, legal, HR, operations. That approach produces activity in each function without producing an integrated compliance position. The connection between work done and the obligation it addresses remains unclear, and the programme cannot demonstrate where it has closed a gap.

Each workstream should produce three things: a coherent capability, the evidence that it operates, and named ownership for delivering it and for sustaining it after the programme closes. A workstream that produces activity without those outputs does not advance the compliance position.

Workstreams are organised around operational ownership: who in the organisation is best placed to build and sustain each area. That structure does not mirror the way the obligations are written, so the programme needs a separate mapping that traces each obligation to the workstream, capability and evidence that satisfy it. The gap register tracks findings against those obligations through to closure, and the management body receives a consolidated view drawn from it.

How this affects your organisation

If your organisation is scoping a NIS2 programme, the order matters. The regulatory determination and the programme perimeter come first, because an assessment conducted against the wrong boundary produces findings that do not map to the obligations that apply. The assessment then sizes the work, and the delivery plan should not go for approval, at whatever level the organisation's governance structure places it, until that assessment is complete.

The test to put to the programme team is whether every material finding has a named delivery owner, a named owner for sustaining it after the programme closes, evidence of the outcome where it is closed, and visible treatment where it remains open.

Working through how to scope and structure a NIS2 programme for your organisation?

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.

NIS2 Frameworks

If this briefing is relevant to your organisation, these frameworks set out how to act on it, with a structured starting point and a programme approach designed to deliver sustained compliance.

NIS2 Diagnostic FrameworkHow to Run a NIS2 Programme