Prepare scope on an entity-by-entity basis
Corporate groups often approach NIS2 either entirely centrally or entirely locally. Neither model is sufficient on its own. Activities, size criteria, legal form, locations and critical services should be structured for each relevant entity.
A factual scope review creates the evidence base for subsequent legal assessment. Group membership alone does not establish applicability and cannot replace qualified case-specific advice.
- Legal entities, activities and relevant sectors
- Workforce and financial criteria under the applicable assessment logic
- Critical services, recipients and cross-border dependencies
Connect group governance with local accountability
Central security functions can provide minimum requirements, methods and platforms. Each management body still needs a defensible view of its entity’s risk, decisions and unresolved deviations.
A RACI chart is not enough. For material controls, the model should identify who delivers the service, who governs effectiveness, who provides evidence and who approves exceptions.
Map shared services and dependencies
Shared identity, networks, cloud platforms, SOC services, backups and suppliers commonly affect several entities. A central control can protect many businesses, while a failure can expose them at the same time.
The operating model should connect service delivery, control ownership, service objectives, escalation and evidence provision in one dependency view.
Structure controls, exceptions and evidence
A common control baseline reduces duplicated work when it does not become an inflexible one-size-fits-all model. Local exceptions require an owner, rationale, compensating measures and a review date.
Evidence should come from stable processes and systems wherever possible. Screenshots assembled immediately before an assessment are not a sustainable operating model.
- Common control objectives with entity-level implementation evidence
- Versioned exception and risk decisions
- Reusable evidence sources with confirmed ownership
Organise group-wide reporting and incident processes
Management reporting should distinguish group exposure, local risk and entity-specific decisions. Aggregation must not conceal materially different situations.
Notification routes, escalation thresholds, accountability and information hand-offs should be agreed before an incident. Factual readiness and legal assessment remain separate workstreams.
Service boundary
Support covers factual scope preparation, governance, control mapping, roadmaps and evidence structures. It does not constitute a binding legal applicability assessment, legal advice or a regulatory determination.