NIS2 demands demonstrable security governance, not a software list. The 90 days below are an indicative work plan for orientation. They are not a statutory deadline. Which duties and dates apply to your organization depends on your classification and the national transposition and belongs in a review by qualified legal counsel.
Days 1–30: inventory
- Record the assets, systems and services that are critical to operations.
- List suppliers and dependencies, especially IT and cloud services.
- Clarify notification paths: who detects, who decides, who reports?
Days 31–60: build controls
- Assign a named owner per control.
- Keep a risk register with ratings and measures.
- Describe the incident process and align notification paths with the directive's reporting deadlines (the directive provides, among other things, for an early warning within 24 hours; the national transposition is what counts).
Days 61–90: evidence
- Review logging and define retention.
- Run an exercise and record protocol, participants and lessons.
- Document a management review.
What auditors want to see
A control catalogue with named ownership instead of a shared inbox, a notification-path map with time limits, and evidence that exercises took place.
What fails
A certification marathon before the first audit. Better: become controllable, then prove it. The evidence chain is the outcome, not the starting point. It cannot promise a successful audit.