Thirty days will not make you compliant with NIS2. It will make you defensible — registered, able to meet the reporting clocks, with management approval on record and a documented plan for the gaps. For an organisation that has just discovered it is in scope, that is the right goal, and the order below matters more than the speed.
The sequencing principle: do the things that are binary and independently enforceable first. You either registered or you did not. You either filed inside 24 hours or you did not. Those cannot be graded on a curve. The ten security measures can be — a partially implemented measure with a dated plan behind it reads very differently from an absent one.
Week 1 — Status, jurisdiction and registration
- Confirm whether you are essential or important. Sector plus size drives it. The distinction changes supervision intensity — proactive for essential, reactive for important — rather than the measures themselves.
- Determine which member state supervises you, and whether you have establishments in several. Transposition is national, so the detail of your obligations follows the country, not the directive text.
- Register with the competent authority. This is a separate duty from the security measures and is enforceable on its own. It is also the single cheapest item on this list, which is why leaving it undone is so hard to explain afterwards.
- Identify the services and systems in scope. NIS2 reaches the network and information systems your in-scope services depend on — not a scope you get to draw narrowly, as you might for a certification.
- If you concluded you are out of scope, write down the reasoning and the date. Customers in scope will ask, and contractual flow-down will reach you regardless.
Week 2 — The reporting clock
This is the obligation that breaks unprepared teams, because it runs on wall-clock time and does not care that it is a Saturday.
- Early warning within 24 hours of becoming aware of a significant incident. Build the process to file early with partial information and supplement later. Teams that wait for a complete picture miss the deadline every time.
- Notification within 72 hours with an initial assessment, and a final report within one month.
- Define "significant" in advance and record the definition. If the judgement is improvised during an incident, it will be made slowly and by the wrong person.
- Name who can authorise a filing out of hours, and their deputy. Put the authority contact details in the incident runbook, not in someone's inbox.
- Run one tabletop against the 24-hour clock. Measure how long it takes to reach a decision, not how well the discussion goes.
The early warning is a heads-up, not an analysis. Treating it as requiring a finished investigation is the most common — and most avoidable — way to breach it.
Track NIS2 measures and evidence in one place
GRC Copilot maps the ten NIS2 measures onto controls you already operate, and keeps the evidence trail for each.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Week 3 — Management accountability
NIS2 attaches consequences to management personally, which is why it is being taken more seriously than its predecessor. Discharging the duty is cheap; failing to is not.
- Table the cybersecurity risk measures for formal board approval and minute it. Approval that is asserted but not minuted is, for supervisory purposes, approval that did not happen.
- Run management training and keep the attendance record. This is explicitly checkable.
- Give the board a standing agenda item for the measures and their effectiveness, so the approval is a process rather than a one-off.
- Members can be held personally liable for breaches of these duties, and in serious cases authorities can temporarily bar individuals from management functions. That is usually enough to get the diary slot.
Week 4 — Evidence the ten measures, honestly
Walk the list and mark each measure red, amber or green with the evidence you actually hold today:
- Risk analysis and information system security policies.
- Incident handling.
- Business continuity, backup management and crisis management.
- Supply chain security, including direct suppliers.
- Security in acquisition, development and maintenance, including vulnerability handling and disclosure.
- Policies to assess the effectiveness of the measures.
- Basic cyber hygiene and security training.
- Cryptography and encryption policy.
- Human resources security, access control and asset management.
- Multi-factor authentication, secured communications and secured emergency communications.
For every amber and red, write one line: what is missing, who owns it, and the target date. A supervisor meeting an organisation with a candid gap register and dated remediation plan is in a very different conversation from one meeting a claim of full compliance that falls apart under questioning.
What day 31 looks like
Registered. A reporting process that has been rehearsed against the clock. Board approval minuted and training done. A measure-by-measure gap register with owners and dates. The remaining work is real, but it is now scheduled work rather than undiscovered risk — and that is the difference the first month can actually make.
Frequently asked questions
Is 30 days enough to become NIS2 compliant?
No, unless you were already close. It is enough to complete the binary duties, remove the worst exposure, and turn unknown gaps into a dated plan — which is what a supervisor engaging with a late starter is realistically looking for.
We are already ISO 27001 certified. Does that shorten this?
Considerably. Most of the ten measures will already be evidenced. Focus weeks 1 to 3 — registration, reporting mechanics and management approval — because those are the parts certification does not give you.
What if our member state has not finished transposing?
Prepare against the directive. National implementations vary in detail such as thresholds and reporting channels, but the ten measures and the reporting clocks are the common core, and late transposition is not a defence once the national law lands.
Do we need to register in every member state where we operate?
It depends on where you are established and which services you provide. Certain digital providers are handled under a main-establishment rule. Resolve this in week 1 with local advice rather than assuming a single registration covers the group.
Key takeaways
- Do the binary duties first: registration and the reporting clock cannot be partially satisfied.
- File the 24-hour early warning with partial information and supplement it.
- Minuted board approval and management training discharge a personally liable duty for almost no cost.
- A candid gap register with owners and dates beats an overstated claim of compliance.