The two scope questions
Regulatory scope and programme scope must be answered separately. Regulatory scope establishes which entities are in scope, which services qualify, and whether the organisation is classified as essential or important under NIS2. Programme scope is a different question: what does the programme actually need to do, at what scale, over what timeline, given the current security position.
The regulatory determination confirms what obligations apply and which entities carry them. The gap between current security maturity and those obligations, and what a proportionate programme looks like given the enforcement position, are questions a gap assessment answers.
What determines the size of the programme
Three inputs shape the size and structure of a NIS2 programme. The first is the gap between current security maturity and what NIS2 requires. A mature organisation with established controls across most areas will have a narrower programme than one building from a lower baseline. The gap assessment is the document the sizing decision rests on.
The second input is the number of in-scope entities and whether they share a security baseline. An organisation with multiple legal entities in scope may run a single programme or may need separate treatment for entities with materially different risk profiles, operating environments or applicable national implementations.
The third is the enforcement position in the relevant Member States. National transposition status and supervisory activity vary by jurisdiction. A programme running eighteen months may be adequate where active supervision has not yet begun, and too slow where enforcement is already under way.
The design principle for workstreams
The most common workstream design mistake is organising work around the organisation's internal structure: IT, legal, HR, operations. That approach produces activity in each function without producing an integrated compliance position. The connection between work done and the obligation it addresses remains unclear, and the programme cannot demonstrate where it has closed a gap.
Each workstream should produce three things: a coherent capability, the evidence that it operates, and named ownership for delivering it and for sustaining it after the programme closes. A workstream that produces activity without those outputs does not advance the compliance position.
Workstreams are organised around operational ownership: who in the organisation is best placed to build and sustain each area. That structure does not mirror the way the obligations are written, so the programme needs a separate mapping that traces each obligation to the workstream, capability and evidence that satisfy it. The gap register tracks findings against those obligations through to closure, and the management body receives a consolidated view drawn from it.