Skip to content
Knowledge base Updated: February 5, 2026

NIS2 deployment strategy: How to build a foundation of compliance and resilience in 90 days?

The NIS2 directive ushers in a new era in cyber security, setting ambitious goals for companies. The key to success is not to act haphazardly, but to adopt a well-thought-out strategy. In this article, we present a proven, practical roadmap for the first 90 days. It's a concrete roadmap that will he

The entry into force of the NIS2 directive is a watershed moment for European business. The new regulations set a high standard for digital resilience, requiring thousands of Polish companies to implement comprehensive security management programs. The enormity of the new responsibilities, from risk analysis to board training, presents a major strategic and organizational challenge. However, an effective approach to such a major transformation requires not a revolution, but a well-planned evolution.

The key to success is a methodical, phased approach that allows you to organize your activities and spread your efforts over time. Trying to complete all requirements at once is inefficient and leads to unnecessary chaos. Instead, it makes sense to adopt a project management-proven methodology of short, intensive sprints, each with a clearly defined goal and measurable results.

In this article, we present a ready-to-implement, practical roadmap for the first, crucial 90 days. We have divided the process into three 30-day stages, creating a clear roadmap. This is a professional approach that will allow you to take control of the process, define priorities and build a solid foundation for long-term compliance and real digital resilience for your organization.

Shortcuts

How to start implementing NIS2 and avoid chaos, i.e. who should become the “owner” of the project in the organization?

Any complex project, to be executed effectively, must have a single, clearly defined leader. NIS2 implementation is not a side task for the IT department, but a strategic program that requires central coordination, a mandate from the board of directors and clear accountability. Therefore, the absolute first step, even before any technical activities begin, is to formally designate ** an “owner” or sponsor of the NIS2 project**.

The most natural candidate for this role is **Chief Information Security Officer (CISO). ** or, in smaller organizations, the most senior manager responsible for IT. However, it is crucial that this person be given not only responsibility, but also adequate authority and visible support from the board. He or she must have the authority to enforce tasks from other departments, involve business and operations representatives in the project, and have real influence on budget decisions.

Appointing an “owner” of the project and formally announcing its role throughout the organization is a signal that the company is taking a serious and strategic approach to NIS2. It’s the first step in bringing order to the chaos and creating a clear decision-making structure for the entire program.

📚 Read the complete guide: IAM / Zero Trust: Zarządzanie tożsamością i dostępem - od podstaw do Zero Trust

What is the practical 30-day plan and how to conduct a key gap analysis during this time?

The first 30 days are the foundation-building phase. The goal is not yet to implement the technology, but to thoroughly understand the current state and plan the way forward. A key task during this period is to conduct a gap analysis of the directive’s key articles, especially Articles 21 (Risk Management) and 23 (Reporting).

Gap analysis is a process in which we systematically compare the current state of security, processes and documentation in our company with specific directive requirements. This involves conducting a series of workshops and interviews with key employees, as well as analyzing existing documentation and system configurations. The result is a detailed report that clearly shows in which areas the company is already compliant and which require urgent intervention.

This document is an invaluable strategic tool. It allows the creation of a prioritized list of tasks and provides an objective basis for developing a realistic roadmap and budget for the entire compliance program. This is the stage that turns uncertainty into a concrete action plan.

How to prepare the foundations of response, i.e., initial business continuity and incident response plans?

Knowing that NIS2 places great emphasis on responsiveness and business continuity, work on key documents should begin in the first phase. The idea is not to create perfect, 100-page procedures right away, but to prepare their first, working versions (drafts), which will become the basis for further work.

Within the first 30 days, the project team should, based on existing knowledge, develop a draft Incident Response Plan (IRP) and Business Continuity Plan (BCP). The initial composition of the response team should be defined, the primary channels of crisis communication should be identified, and the overall framework for dealing with an incident should be described.

Equally important is the preparation of initial templates for reporting incidents to the national CSIRT. Analyzing the reporting requirements (24h/72h deadlines) and creating a ready-to-fill form will significantly speed up the response once the first real incident has already happened.

How do you develop the key policies (risks, supply chain) required by NIS2 in a 30-60 day plan?

The second phase, spanning from day 30 to day 60 of the project, is the time to build the management and procedural framework. Based on the results of the gap analysis, the team proceeds to create or update key security policies explicitly required by the directive.

This is the moment for the formal writing and approval by the board of directors of such documents as the Risk Management Policy, the Supply Chain Security Policy, the Cryptography Use Policy, the Access Control Policy or the Secure Systems Development and Maintenance Policy.

Each of these policies must be a practical document and adapted to the realities of the organization. Their purpose is not only to meet a formal requirement, but to create clear and understandable policies that will be realistically applied by employees. The process of creating them should involve representatives of all departments affected by these policies.

How to plan and whom to include in mandatory training to comply with the directive?

The NIS2 directive explicitly requires regular cyber security training. In the second phase of the project, it is therefore necessary to create a detailed training plan and schedule for the coming year. This plan must include two key groups.

The first, and most important, is management. Dedicated, strategic workshops should be planned for the board of directors and key managers to help them understand their new personal responsibility and role in the risk management system.

The second group is all employees. A security awareness training program should be developed to fit different roles in the organization. The plan should specify the topics, format (e-learning, workshops) and frequency of training. At this stage, it is also crucial to establish the parameters of SLAs with key stakeholders, defining metrics and response times.

How to verify readiness in practice (60-90 days), i.e. why are “tabletop” tests and exercises so important?

The third phase of a project is when theory begins to be verified by practice. Having written plans and policies is one thing, but their real effectiveness is only revealed in action. Therefore, a period of 60 to 90 days should be devoted to the first controlled tests.

The most important element of this phase is to conduct the first “tabletop” exercise for the incident response team. This is a “dry” crisis simulation, during which the team, based on a plan created earlier, must run through a hypothetical attack scenario. This is the best way to verify that procedures are clear, roles are well defined, and communication is smooth.

In parallel, the first, technical security tests, such as vulnerability scans or, in more mature organizations, basic penetration tests for the most critical systems, should begin during this phase. The goal is to gather hard data on the real state of security.

NIS2 implementation plan: roadmap for the first 90 days

PhasePeriodKey ActivitiesResult
I. FoundationsDays 1-30Appoint a project leader. Conducting a gap analysis. Create draft IRP/BCP plans.Understand the current state and create a clear project roadmap.
II. StructureDays 31-60Develop and approve key policies. Create a training schedule for management and employees.Build a management and procedural framework for the compliance program.
III. VerificationDays 61-90Conducting the first “tabletop” exercise. Commencement of vulnerability testing. Implementation of the MFA.Practical verification of plans and implementation of the first key safeguards.

What key technologies, such as multi-factor authentication (MFA), should be implemented first?

Although the first 90 days are mainly organizational and planning work, the third phase should also begin to implement those technologies that give the greatest return on security investment with relatively low complexity. An absolute priority here is multi-factor authentication (MFA).

Implementing MFA for access to key systems, email and cloud services is one of the most effective ways to protect against attacks based on password theft. This is an action with huge security implications that should be implemented as soon as possible.

During this phase, it’s also a good idea to start working on implementing secure, encrypted communication channels for crisis teams and management. In the event of an attack that could compromise the company’s email, having an alternative, secure channel for communication (e.g., using Signal or a similar application) is absolutely key. At the end of this period, a cycle of regular reviews (KPIs, audits, lessons learned) of the entire program should also be established.

What is the European Cyber Security Competency Framework (ECSF) and how does it help structure roles?

Implementing a program as broad as NIS2 compliance requires the involvement of many people with different competencies. To effectively manage this human resource, it makes sense to use a ready-made, standardized framework, such as the European Cybersecurity Skills Framework (ECSF), developed by ENISA.

ECSF is a structured list of 12 key cybersecurity roles (e.g., SOC Analyst, Pentester, Risk Manager), with detailed descriptions of their tasks, responsibilities, and required skills and knowledge.

Using this framework as a reference is extremely helpful. It allows us to organize and formalize the roles in our existing team. We can map our employees’ tasks to standard profiles from ECSF, which immediately shows what competencies we have and what we lack.

How does role mapping to the ECSF build order and a clear accountability structure in the organization?

One of the biggest benefits of using ECSF is the introduction of organizational governance and transparency. When we assign each key task required by NIS2 (e.g., “risk analysis,” “incident response”) to a specific role from the framework and then to a specific employee, we create a clear and unquestionable accountability matrix (RACI).

Everyone in the organization knows “who is responsible for what.” This eliminates chaos, competency disputes and the “no man’s land” problem we have discussed in previous articles. For the management, such a structured map of roles and responsibilities demonstrates organizational maturity and a professional approach to program management.

Moreover, ECSF provides a common, standardized language. Instead of talking about “our IT security officer,” we can talk about a person in the role of “Security Administrator,” whose tasks are clearly defined and understood throughout the industry.

Insourcing or outsourcing in NIS2? How does the ECSF framework help you make the right decision?

No organization, even the largest, can have all the necessary competencies internally. The ECSF is an excellent tool for strategically deciding which roles and tasks we want to and can perform with in-house forces**(insourcing**), and which will be more efficient to outsource to an external, specialized partner**(outsourcing**).

Once we have mapped all the tasks required by NIS2 to roles from ECSF, we can conduct an analysis. Do we have a person on the team who is competent to perform the role of “SOC Analyst”? If not, is it more profitable to try to hire her and build the team from scratch, or is it better to buy this competency as a service from an external provider (SOC as a Service)?

ECSF allows this discussion to be guided by data and precisely defined competency profiles, rather than general hunches. It’s a strategic tool for optimizing resources and budgets.

How to use the ECSF for effective staff planning, recruitment and team development?

The ECSF framework is also a powerful tool for HR and managers responsible for staff development. Once we know what roles and competencies we need, we can plan HR activities in a much more effective way.

First, recruitment. We can create much more precise job descriptions, directly referring to the tasks and required skills defined in the ECSF. Second, development planning (upskilling and reskilling). By comparing the competency profile of current employees with the target profiles from the ECSF, we can identify gaps and design dedicated training paths to acquire the missing skills.

This allows for strategic building of internal competencies and succession planning. Instead of haphazard training, we create a coherent development program that is directly linked to the organization’s real needs as a result of NIS2 requirements.

Why are organizations using the ECSF better prepared for audits and inspections by regulators?

In the event of a post-incident inspection, the regulator will certainly verify that the company had adequate human resources and competence to manage safety. Having a documented organizational structure, based on a recognized European standard such as the ECSF, is extremely strong evidence of due diligence.

This shows the auditors that the organization has approached the subject in a systematic and professional manner. It proves that roles and responsibilities have been clearly defined and that the required competencies have been mapped and provided - whether by internal employees or external partners.

Such documentation is much more convincing than general assertions that “we have a team of experts.” This is concrete, standards-based evidence that significantly strengthens the company’s position in dialogue with the regulator.

How can nFlo support you in the methodical implementation of NIS2 - from the 90-day plan to team building?

At nFlo, we specialize in transforming complex regulatory requirements, such as NIS2, into practical and manageable implementation programs. Our methodology is based on a proven, phased approach that allows our clients to achieve compliance in an orderly and stress-free manner. We guide you by the hand through the entire 90-day plan described above: we start with a comprehensive gap analysis, which becomes the foundation for the entire strategy. Then, together with your team, we develop the necessary policies and plans that are 100% tailored to your realities. A key part of our offering is also support in the organizational area. We help map roles and responsibilities using the ECSF framework, identify competency gaps and advise on strategic insourcing and outsourcing decisions. Our goal is not just to help you achieve compliance “on paper,” but to build real, lasting resilience, based on a solid foundation of technology, process and, most importantly, people.

What ninety days will not close

A phased plan of this kind covers what an organisation can do with its own hands: diagnosis, policies, initial response and continuity plans, training, and the first technical measures. It is a realistic scope for a quarter and worth committing to.

One obligation will not fit inside it, and saying so at the outset prevents a missed milestone from reading as failure. Supply chain security depends on other companies agreeing to things: assessing suppliers, then getting security terms into contracts, each with its own legal department and calendar. Some counterparties need months before they can sign what you need. Starting that stream on day one, in parallel with everything else, and reporting it separately from the ninety-day plan is how a NIS2 compliance programme keeps its schedule honest.

Learn key terms related to this article in our cybersecurity glossary:

  • Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
  • SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
  • Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
  • Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
  • NIS2 — NIS2 (Network and Information Security Directive 2) is an EU directive…

Learn More

Explore related articles in our knowledge base:


Explore Our Services

Need cybersecurity support? Check out:


See also:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist