INDEPENDENT NIS2 RESOURCEGovernance · Resilience · ImplementationEU framework / national application
AN INDEPENDENT FIELD GUIDE / NIS2 DIRECTIVE
GOVERNANCE
RISK
RESILIENCE

Cyber resilience is a leadership decision.

NIS2 connects critical services, cybersecurity measures, incident reporting and management accountability. Understand who may be in scope, then organise the work across teams.

Professionals reviewing operations at a critical infrastructure facility
01 / THE OPERATING CONTEXTServices, systems and people are part of one resilience picture.
The NIS2 briefing18 sectors in the EU frameworkEssential and important entitiesNational implementation mattersRead overview ↗
01 / SCOPE

Start with the organisation, not the acronym.

Sector is only one part of the question. Entity type, size, exceptions, establishment and national law all shape the analysis.

How to assess scope ↗
02 / ACCOUNTABILITY

Resilience has to be owned.

Connect management decisions to the services at risk, the measures in operation and the evidence of review.

Responsibility map connecting management, services, measures and evidence around programme ownership
An original working model for organising responsibilities. It is not a legal classification.
01

Management

Make approvals, oversight and training visible.

02

Services

Understand what the organisation needs to keep running.

03

Measures

Assign owners to risk management and incident preparation.

04

Evidence

Keep decisions, tests and follow-up in a usable record.

Explore management responsibility ↗
04 / INCIDENT PREPAREDNESS

Know the reporting path before the clock starts.

Article 23 describes staged notification for significant incidents. Confirm the applicable national channel and the circumstances of the event.

A24 hours

Early warning

After awareness of a significant incident, subject to the Directive’s conditions.

B72 hours

Incident notification

An initial assessment updates the early warning where applicable.

COne month

Final report

Generally measured after notification; Article 23 gives the detail and exceptions.

Understand the timeline
05 / IMPLEMENTATION

Move from interpretation to operation.

A practical route gives every phase an owner and an output. A generic checklist alone cannot establish compliance.

01

Scope

Map entities and services

02

Assess

Review risks and measures

03

Prioritise

Assign decisions and owners

04

Operate

Test, document and review

Open implementation guide ↗