NIS2 Governance · 7 min

NIS2 across corporate groups: separating scope, accountability and evidence

A group-wide security model does not remove entity-level obligations. NIS2 readiness needs clear accountability, dependencies and evidence.

Prepare scope on an entity-by-entity basis

Corporate groups often approach NIS2 either entirely centrally or entirely locally. Neither model is sufficient on its own. Activities, size criteria, legal form, locations and critical services should be structured for each relevant entity.

A factual scope review creates the evidence base for subsequent legal assessment. Group membership alone does not establish applicability and cannot replace qualified case-specific advice.

  • Legal entities, activities and relevant sectors
  • Workforce and financial criteria under the applicable assessment logic
  • Critical services, recipients and cross-border dependencies

Connect group governance with local accountability

Central security functions can provide minimum requirements, methods and platforms. Each management body still needs a defensible view of its entity’s risk, decisions and unresolved deviations.

A RACI chart is not enough. For material controls, the model should identify who delivers the service, who governs effectiveness, who provides evidence and who approves exceptions.

Map shared services and dependencies

Shared identity, networks, cloud platforms, SOC services, backups and suppliers commonly affect several entities. A central control can protect many businesses, while a failure can expose them at the same time.

The operating model should connect service delivery, control ownership, service objectives, escalation and evidence provision in one dependency view.

Structure controls, exceptions and evidence

A common control baseline reduces duplicated work when it does not become an inflexible one-size-fits-all model. Local exceptions require an owner, rationale, compensating measures and a review date.

Evidence should come from stable processes and systems wherever possible. Screenshots assembled immediately before an assessment are not a sustainable operating model.

  • Common control objectives with entity-level implementation evidence
  • Versioned exception and risk decisions
  • Reusable evidence sources with confirmed ownership

Organise group-wide reporting and incident processes

Management reporting should distinguish group exposure, local risk and entity-specific decisions. Aggregation must not conceal materially different situations.

Notification routes, escalation thresholds, accountability and information hand-offs should be agreed before an incident. Factual readiness and legal assessment remain separate workstreams.

Service boundary

Support covers factual scope preparation, governance, control mapping, roadmaps and evidence structures. It does not constitute a binding legal applicability assessment, legal advice or a regulatory determination.

Primary sources and further reading

Related executive perspectives

Continue with the next decision.

Two related perspectives connect this question to the wider leadership and delivery model.

From perspective to decision

What does this mean for your organisation?

A first conversation frames scope, urgency and the next sensible step.

Discuss your situation