NIS2 is not something you pass with a one-off audit. For organisations in scope, it requires sustained digital resilience: processes that evolve, are tested and leave reliable evidence. National implementation, supervisory practice and sector rules differ across Member States, so the operational baseline below should be adapted to the country and sector that apply to you.

At PrivaLex Partners, we work with organisations that need to monitor their NIS2 status, update their risk assessment and prepare evidence for inspections. Organisations still confirming whether the Directive applies can review who needs to comply with NIS2.

What it means to maintain compliance under NIS2

Maintaining compliance means being able to demonstrate that your organisation actively manages technology risks, not just that policies exist. Controls, accountable people, decisions and records must work in practice. You should be able to respond to an inspection, incident or customer audit without improvising.

This does not mean every organisation needs the same calendar or toolset. NIS2 requires measures that are appropriate and proportionate to risk. The important point is that your method is documented, repeatable and updated when your services, systems, suppliers or threat environment change. Article 21 of the Directive sets out the risk-management areas that essential and important entities must address.

If you combine NIS2 with ISO 27001 certification or a GDPR audit, one coordinated security-management system reduces duplicate work. ISO 27001 can provide a useful structure, but it does not automatically demonstrate every NIS2 obligation.

How PrivaLex Can Help You Stay Compliant with NIS2

At PrivaLex, we help organisations build a NIS2 compliance programme that can withstand growth, incidents, customer scrutiny and regulatory inspection. Our work starts by confirming the organisation’s scope, relevant entities, critical services, technology dependencies and current control maturity. This gives the team a defensible baseline before implementation begins.

We then turn the applicable requirements into an operational plan. Rather than producing a generic gap report, we identify which actions matter most, who owns them, what evidence is needed and how progress should be reported to management. The output can include a risk register, treatment plan, supplier-risk process, incident-response workflow, evidence tracker and prioritised remediation roadmap.

A key part of NIS2 preparation is risk management. We facilitate workshops with technology, security, operations, legal and leadership teams to identify the threats that could affect network and information systems, critical services, customer data and business continuity. We help define risk criteria, treatment decisions, residual-risk acceptance and review triggers so the process remains active after the initial assessment.

We also help strengthen controls around access management, vulnerability mitigation, incident handling, backups, continuity, logging, secure development, employee training and supplier oversight. For critical vendors, we can help establish assessment criteria, security requirements, contractual expectations, evidence requests and review frequencies. This is particularly important where third-party services support essential systems or create concentration risk.

NIS2 places strong emphasis on management responsibility and ongoing oversight. We help create reporting that gives directors and senior leaders a useful view of security risk, open actions, incidents, supplier issues, overdue evidence and resource requirements. This allows leadership to make documented decisions rather than receiving technical updates without business context.

Incident readiness is another important area. We support the development and testing of incident procedures, escalation paths, roles, communication records and post-incident reviews. Tabletop exercises help teams identify gaps before a real event creates time pressure. We also help ensure that findings from incidents, audits, vulnerability assessments and supplier reviews feed back into the risk-treatment process.

Where other frameworks apply, we map shared controls into one operating programme. For example, a well-designed ISO 27001 ISMS can provide much of the governance, risk, control and evidence structure needed for NIS2, while NIS2 adds specific focus on supply-chain security, incident reporting, management accountability and sector obligations. We also align relevant GDPR, ENS or DORA requirements without losing the details that are unique to each framework.

Before an inspection, customer review or internal assurance exercise, we help organise the evidence pack: policies, risk records, supplier assessments, training logs, technical records, incident documentation, management-review minutes and corrective-action status. The objective is to ensure the organisation can demonstrate not only that controls exist, but that they are owned, operating and reviewed.

PrivaLex supports teams from early scope assessment through implementation, internal testing and ongoing maintenance. We help make NIS2 a practical security and resilience programme rather than a one-time compliance exercise.

What to have operating in 2026

Active ICT risk management

A risk assessment completed in 2024 is not enough if your systems, suppliers or business model have changed. Keep a living risk register that records the asset or service, risk scenario, owner, controls, treatment decision, residual risk, deadline and review date.

Review risks at planned intervals and whenever there is a material change, such as a new cloud service, acquisition, critical vulnerability, major incident, new supplier or regulatory development. Each high-priority risk should lead to a tracked treatment action and evidence that the action was completed. A structured ISO 27001 risk assessment helps make the register and treatment process auditable.

Incident notification and response

Your incident plan must answer four questions quickly: what counts as a significant incident, who declares it, who notifies the authority or CSIRT, and who coordinates the technical, legal and customer response.

Under Article 23, the general NIS2 sequence is an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, any intermediate report requested by the authority or CSIRT, and a final report no later than one month after the notification. If the incident is still ongoing, provide a progress report and submit the final report within one month of handling it. The exact channel and national procedure should be confirmed for your jurisdiction. 

Run at least one realistic tabletop exercise each year as a practical baseline, and after material changes where useful. Test the clock, escalation path, evidence preservation, supplier contacts, decision log and customer communications. Record the lessons learned and assign corrective actions.

Supplier oversight

Supply-chain security is an ongoing lifecycle, not only a clause in the first contract. Classify suppliers by criticality, assess them before onboarding, apply proportionate security and incident-notification terms, and keep an owner for each critical relationship.

For high-impact ICT suppliers, maintain a record of their service, data access, dependencies, assurance evidence, known risks, notification SLA, contingency arrangement and next review date. Reassess after a serious incident, a material change in service or ownership, or when their assurance evidence expires. Include termination and transition planning so an outage, breach or failed renewal does not leave the business without a viable service.

Resilience, vulnerability and access testing

Evidence of operational resilience should cover more than a policy. Maintain vulnerability management records, patching decisions, backup and recovery tests, access reviews, incident exercises and continuity-test results. Link findings to owners, remediation deadlines and verification evidence.

The right frequency depends on the service and risk. A useful approach is to review critical vulnerabilities and overdue corrective actions monthly, test recovery and incident arrangements periodically, and report material trends to management. What matters is that you can show what was tested, what failed, what changed and who approved remaining risk.

Governance, training and accountability

NIS2 is not only an IT responsibility. Management should approve the risk-management approach, receive regular information about material risks and incidents, allocate resources, decide on unacceptable residual risks and review whether the programme remains effective. Keep minutes and decision records.

Training should be role-based. Board and management members need enough understanding to oversee cybersecurity risk; privileged users, engineering teams, procurement and customer-facing staff need training relevant to their decisions and escalation responsibilities. Keep attendance and completion records, then use incident and exercise results to improve the programme.

A practical maintenance cadence

This is an example of operating cadence, not a universal legal deadline. Adapt it to your size, sector and national rules.

  1. Monthly: review critical vulnerabilities, overdue risk-treatment actions, key supplier alerts and access-management exceptions.
  2. Quarterly: update material risks, review security KPIs, reassess critical suppliers, report to management and track corrective actions.
  3. At least annually: refresh policies and training, complete an incident or continuity exercise, review the asset and supplier inventory, and perform a formal management review.
  4. When triggered: reassess after a significant incident, major system or supplier change, acquisition, new service, material threat change or relevant regulatory update.

Use one action log for all of these activities. It should show the finding, owner, deadline, status, evidence and approval. This creates a direct line from risk to action to proof.

What to have ready for an inspection

An authority or customer should be able to follow the evidence chain without reconstructing it from email. Keep these records controlled, current and easy to retrieve:

  • Approved cybersecurity policies, governance roles and management-review minutes.
  • Asset, service and critical-supplier inventories, with owners and dependencies.
  • Risk register, treatment plan, accepted residual risks and corrective-action log.
  • Incident plan, notification contacts, incident records, table-top minutes and lessons learned.
  • Vulnerability, patching, access-review, backup and recovery-test evidence.
  • Supplier due-diligence records, contracts, security schedules, notification SLAs and reassessments.
  • Training plan, completion records and role-specific awareness material.

The goal is not to produce a pile of documents. It is to demonstrate traceability: a risk prompted a proportionate measure; the measure has an owner; it was tested; and any remaining risk was consciously accepted.

4 common mistakes that undermine NIS2 compliance

  1. Leaving the risk assessment in 2024. A stale register does not reflect new services, suppliers or threats. Schedule reviews and record every material change.
  2. Treating the 24-hour early warning as the entire reporting process. Test the 72-hour notification, evidence collection, authority requests and final-report workflow as well.
  3. Signing supplier contracts without ongoing oversight. Security clauses matter, but so do criticality, assurance evidence, incident SLAs, reassessment and exit planning.
  4. Leaving management outside the programme. If decisions, resources, training and residual-risk acceptance are not visible at management level, the programme is difficult to sustain or defend.

Conclusion

Staying compliant with NIS2 is a continuous management discipline, not a document-preparation exercise. Keep risks, suppliers, incidents, training and resilience testing connected to clear owners and evidence. A practical cadence, tested reporting process and visible management involvement will make the programme more resilient, easier to inspect and easier to adapt as your business changes.

Schedule a strategic session with PrivaLex to review your current NIS2 operating model and prioritise the gaps that matter most.

Frequently Asked Questions (FAQs)

It means being able to demonstrate on an ongoing basis that your organisation actively manages ICT risks, that you have operational controls and processes, traceability and evidence (documentation, records, simulation minutes), and that you can respond to inspections or incidents without improvising.

NIS2 is not a one-off project: it requires sustained resilience and periodic review of risks, notification, suppliers, resilience and governance.

You need: active ICT risk management (updated and reviewed register); incident notification processes within 24 hours (procedure, roles, rehearsals); ICT supplier oversight (contracts with security clauses, monitoring); resilience testing (simulations, continuity, evidence); and governance and accountability (management involved, identifiable person coordinating compliance).

All documented and demonstrable.

Competent authorities in each Member State can request evidence, carry out inspections (on site or in writing), audit processes and apply sanctions in case of non-compliance. To be prepared, keep documentation and evidence organised, traceability between risks and measures, and clear accountable persons and processes.

The risk assessment should be reviewed at least periodically (e.g. annually) and when relevant changes occur. Simulations and resilience tests should be recurrent.

Documentation (policies, procedures, contracts) should be up to date when systems, suppliers or regulation change. There is no single calendar: what matters is that compliance is continuous and demonstrable.

Yes. PrivaLex offers ongoing support for organisations in scope of NIS2: monitoring of compliance status, updating the risk assessment, preparing documented simulations, reviewing ICT supplier contracts, managing evidence and support during inspection processes.

We help you build a structure that can withstand audits, incidents and growth.

Next step

Your next step

Staying compliant with NIS2 in 2026 is not about having “done the homework” the previous year. It is an operational commitment that must be embedded in the security culture of the organisation.

If your organisation is already subject to NIS2 and you have not reviewed your status in recent months, now is the time. Schedule a strategic session with PrivaLex and we can review your current compliance or preparation for an inspection.


Free checklist
Do you know what’s standing between you and ISO 27001 certification?
Download our readiness checklist and find out which controls you already have in place and where your real gaps lie, before you start the process.
Download Free Checklist