NIS2 readiness in 90 days: an indicative plan

How essential and important entities build governance, controls and evidence without a certification marathon – as orientation, not a legal deadline.

NIS2 demands demonstrable security governance, not a software list. The 90 days below are an indicative work plan for orientation. They are not a statutory deadline. Which duties and dates apply to your organization depends on your classification and the national transposition and belongs in a review by qualified legal counsel.

Days 1–30: inventory

Days 31–60: build controls

Days 61–90: evidence

What auditors want to see

A control catalogue with named ownership instead of a shared inbox, a notification-path map with time limits, and evidence that exercises took place.

What fails

A certification marathon before the first audit. Better: become controllable, then prove it. The evidence chain is the outcome, not the starting point. It cannot promise a successful audit.