Week 1: Scope, owners, and facts
Confirm scope assumptions
Review sectors, services, size, countries, group structure, suppliers, and customer pressure.
Assign owners
Name management, security, IT, supplier, privacy, legal, and incident-response owners.
Create the gap register
List unknowns, missing policies, missing evidence, weak controls, and urgent supplier questions.
Week 2: Policies and controls
Choose the structure
Use ISO 27001, NIST CSF, or another suitable structure to organize controls and policies.
Draft core policies
Prioritize information security, access control, incident response, supplier security, backup and recovery, vulnerability management, and awareness.
Map controls to owners
Each selected control should have an owner, implementation status, and evidence placeholder.
Week 3: Incident and supplier readiness
Define incident intake
Standardize Slack, email, web, alert, user, vendor, and customer intake into structured incident records.
Set escalation rules
Define when legal, privacy, management, customer, supplier, and authority reporting review is needed.
Review critical suppliers
Identify suppliers that can affect critical services, customer data, incident evidence, or continuity.
Week 4: Evidence, review, and next 90 days
Collect first evidence
Capture initial evidence for MFA, access reviews, backups, suppliers, training, vulnerabilities, and incidents.
Brief management
Present scope, risks, gaps, decisions needed, owners, and resource constraints.
Create the 90-day roadmap
Turn gaps into sequenced work with owners, dates, dependencies, and review points.
Where aneo helps the 30-day plan
Framework-Pro can accelerate policy drafts, framework selection, control mapping, and evidence placeholders. IncidentAI can help build a better incident workflow with structured tickets, summaries, timelines, and RCA drafts.
Both products should be used as decision-support and workflow tools. They do not replace legal advice, management accountability, implementation, or evidence review.
Quick FAQ
Can an organization become NIS2 compliant in 30 days?
Usually not from a cold start. A 30-day plan should create a truthful baseline, owners, first policies, incident workflow, supplier review, evidence index, and a 90-day roadmap.
What should the first week focus on?
Scope, services, countries, customer pressure, owners, and a gap register.
What should management review at day 30?
Scope assumptions, risks, implemented and missing controls, incident readiness, supplier gaps, evidence gaps, decisions needed, and the next 90-day plan.
How can aneo help?
Framework-Pro supports policy and control readiness. IncidentAI supports structured incident records, timelines, summaries, and RCA drafts.
Official sources used
These pages were used for factual grounding. aneo summarizes them in original wording and does not provide legal advice.
