NIS2 guideNIS2 action plan

A 30-day NIS2 action plan should create clarity, not fake completion.

No serious organization becomes fully NIS2-ready in 30 days from a cold start. But a lean team can create a strong first version of scope, ownership, policies, controls, incident workflow, supplier review, evidence, and management priorities.

Framework-Pro + IncidentAIUpdated August 2026
Key points

What to remember before you act.

  • Use 30 days to build a truthful baseline and first actions.
  • Do scope, ownership, policies, incidents, suppliers, and evidence together.
  • Avoid claiming compliance before controls are implemented and evidenced.
  • Management should review the output and approve priorities.
  • Aneo can support the documentation and incident-workflow parts of the plan.

Week 1: Scope, owners, and facts

01

Confirm scope assumptions

Review sectors, services, size, countries, group structure, suppliers, and customer pressure.

02

Assign owners

Name management, security, IT, supplier, privacy, legal, and incident-response owners.

03

Create the gap register

List unknowns, missing policies, missing evidence, weak controls, and urgent supplier questions.

Week 2: Policies and controls

01

Choose the structure

Use ISO 27001, NIST CSF, or another suitable structure to organize controls and policies.

02

Draft core policies

Prioritize information security, access control, incident response, supplier security, backup and recovery, vulnerability management, and awareness.

03

Map controls to owners

Each selected control should have an owner, implementation status, and evidence placeholder.

Week 3: Incident and supplier readiness

01

Define incident intake

Standardize Slack, email, web, alert, user, vendor, and customer intake into structured incident records.

02

Set escalation rules

Define when legal, privacy, management, customer, supplier, and authority reporting review is needed.

03

Review critical suppliers

Identify suppliers that can affect critical services, customer data, incident evidence, or continuity.

Week 4: Evidence, review, and next 90 days

01

Collect first evidence

Capture initial evidence for MFA, access reviews, backups, suppliers, training, vulnerabilities, and incidents.

02

Brief management

Present scope, risks, gaps, decisions needed, owners, and resource constraints.

03

Create the 90-day roadmap

Turn gaps into sequenced work with owners, dates, dependencies, and review points.

Where aneo helps the 30-day plan

Framework-Pro can accelerate policy drafts, framework selection, control mapping, and evidence placeholders. IncidentAI can help build a better incident workflow with structured tickets, summaries, timelines, and RCA drafts.

Both products should be used as decision-support and workflow tools. They do not replace legal advice, management accountability, implementation, or evidence review.

Quick FAQ

Can an organization become NIS2 compliant in 30 days?

Usually not from a cold start. A 30-day plan should create a truthful baseline, owners, first policies, incident workflow, supplier review, evidence index, and a 90-day roadmap.

What should the first week focus on?

Scope, services, countries, customer pressure, owners, and a gap register.

What should management review at day 30?

Scope assumptions, risks, implemented and missing controls, incident readiness, supplier gaps, evidence gaps, decisions needed, and the next 90-day plan.

How can aneo help?

Framework-Pro supports policy and control readiness. IncidentAI supports structured incident records, timelines, summaries, and RCA drafts.

Official sources used

These pages were used for factual grounding. aneo summarizes them in original wording and does not provide legal advice.

Knowledge Base

Continue your NIS2 readiness work.

Use the related resources below to turn this NIS2 question into a practical next step for your team.

Browse the full Knowledge Base
Next step

Start with the parts of NIS2 readiness your team can control now.

Use Framework-Pro for policy and control readiness, or book an IncidentAI demo for incident intake, triage, evidence, timelines, and RCA workflow support.