Abstract blue network nodes receding into darkness, representing a phased NIS2 implementation timeline

NIS2 Implementation Timeline: 22, 32, or 44 Weeks — A 4-Phase Roadmap Sized to Your Headcount

Most NIS2 implementation plans fail on arithmetic, not on understanding. The team sizes the project against headcount — 180 people, call it six months — and discovers in month four that half the supplier questionnaires are unreturned, the board only meets quarterly, and the second site has an asset register nobody has started.

Effort under NIS2 scales with scope surface, not headcount: legal entities, sites, in-scope suppliers, operational technology estates, and approval layers. Two of those are latency-bound, and adding people to them changes nothing. What follows is a week budget per phase for three headcount bands, the twelve-month calendar that budget has to fit into, and the order to cut in when your runway is shorter than your plan.

Which Size Band Are You In — and Which Entity Class?

In plain terms: two separate tests decide your project. Your entity class (essential or important) decides which obligations and penalties apply; your size band decides how long the work takes. Conflating them is the most common scoping error in draft project plans.

Article 2(1) applies the Directive to entities “which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC”, or which exceed those ceilings, when they operate in an Annex I or Annex II sector [3]. Under the Commission’s SME definition, a small enterprise has fewer than 50 staff; a medium-sized one has fewer than 250 staff and either turnover at or below EUR 50 million or a balance sheet total at or below EUR 43 million [8].

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Plenty of mid-sized companies get the consequence backwards. Crossing 50 employees puts you out of the “small” category on headcount alone — turnover does not rescue you. But staying under 250 staff keeps you medium-sized, and Article 3(1) reserves essential status for entities that exceed the medium-sized ceilings in an Annex I sector; everything else of a type listed in Annex I or II “shall be considered to be important entities” [4]. So a 140-person logistics firm is almost always important, not essential — unless a size-independent route applies. Article 2(2) brings certain entities into scope regardless of size, including trust service providers, DNS service providers, providers of public electronic communications networks or services, and sole providers of a service critical to societal or economic activity [3]; Article 3(1) then classes qualified trust service providers, top-level domain name registries and DNS service providers as essential “regardless of their size” [4]. Our NIS2 scope guide and essential entity definition work through the edge cases.

Headcount band Usual entity class Scope-surface signals Plan length
50–100 Important (medium-sized, Annex I or II) One legal entity, 1–2 sites, under ~20 tier-1 suppliers, no OT, one approval layer 22 weeks
100–250 Important (medium-sized, Annex I or II) 1–2 legal entities, 2–5 sites, 20–60 tier-1 suppliers, limited OT, board plus a steering committee 32 weeks
250+ Essential if Annex I; important if Annex II Group structure, 5+ sites, 60+ tier-1 suppliers, OT or ICS estate, board plus committee plus local management 44 weeks

If your scope-surface signals sit a band above your headcount — a 90-person water utility with three treatment sites and an OT network, say — plan against the higher band. Headcount is the proxy; scope surface is the driver.

The Clocks You Cannot Move

In plain terms: four external deadlines run on their own schedule regardless of where your project has got to. Build the plan around them, not the other way round.

1. Registration is a rolling trigger, not a one-off date. Article 27 set 17 January 2025 for the digital-provider categories in the ENISA registry, with changes notified within three months [6]. National registration is separate and has its own trigger: Germany’s BSI requires registration “spätestens drei Monate, nachdem sie erstmals oder erneut NIS-2-betroffen sind” — within three months of first or renewed NIS2 affectedness [10] — and its scope page now states flatly that “die gesetzliche Registrierungsfrist ist bereits abgelaufen”, telling unregistered entities to register immediately [9]. A rolling trigger means growth or an acquisition can start your clock mid-project. Registration belongs in week one, not Phase 4.

2. Article 23 runs from day one of applicability. Significant incidents require an early warning “within 24 hours of becoming aware”, a fuller notification “within 72 hours”, and a final report “not later than one month after the submission of the incident notification” [5]. Nothing suspends that while you build your programme. A ransomware event in month two of a 44-week plan still starts a 24-hour clock against a team with no notification template and no decision owner — which is why a usable incident procedure has to land in Phase 2. Our incident reporting guide covers the three-stage mechanics.

3. Board approval is a fixed-cadence gate. Article 20(1) requires management bodies to approve the cybersecurity risk-management measures, oversee implementation, and bear responsibility for infringements; Article 20(2) requires their members to follow training on a regular basis [2]. A quarterly board gives you four approval slots in a twelve-month plan, and every one you miss costs a quarter. Schedule the approval dates first and build the phases backwards from them — see board governance obligations.

4. Your member state’s clock may differ from Brussels’. Transposition was due by 17 October 2024; the Commission sent letters of formal notice to 23 Member States in November 2024 [14], and on 8 July 2026 referred Ireland, Spain, France and the Netherlands to the Court of Justice, requesting “a lump sum and daily penalties until notification of complete transposition” [15]. National evidence obligations then vary sharply, and one is widely misreported: Germany’s three-year audit cycle under § 39 BSIG applies to Betreiber kritischer Anlagen — critical installation operators — not to every besonders wichtige Einrichtung. The statute sets the first evidence date at “frühestens drei Jahre nachdem sie erstmals … als ein Betreiber einer kritischen Anlage gelten”, then every three years, via security audits, tests or certifications [11]. Check your national instrument before anchoring a plan to a three-year horizon you may not have.

The consequence of drifting sits in Article 34: fines of “a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover” for essential entities, and EUR 7 000 000 or 1,4 % for important entities, whichever is higher [7]. Our penalties breakdown covers how supervisory authorities escalate.

The Four Phases and What Each One Produces

In plain terms: a phase is not a period of activity — it is a named deliverable that a supervisory authority could ask to see. Define phases by output, and “we’re 60% through Phase 2” stops being a guess.

Phase Core question Article 21(2) letters engaged Deliverable that closes it
1. Scoping and gap What is in scope, and how far short are we? Sets the 21(1) proportionality basis Signed scope statement, entity classification, registration filed, scored gap register
2. Foundation documentation What are our rules, and who approved them? (a) risk analysis · (b) incident handling · (c) business continuity · (g) training · (i) HR, access, asset management Board-approved policy set, risk assessment and treatment plan, working incident procedure
3. Technical controls Does the technology match the paper? (d) supply chain · (e) acquisition, development, maintenance and vulnerability handling · (h) cryptography · (j) multi-factor authentication Deployed controls with configuration evidence, completed tier-1 supplier assessments
4. Audit-readiness Can we prove it worked? (f) effectiveness assessment, plus tested (b) and (c) Internal audit report, continuity exercise report, management review minutes, evidence pack

The ten measures in Article 21(2) are not a checklist worked left to right. Measure (b) incident handling has a documentary component in Phase 2 and a tested component in Phase 4, while supply chain security under (d) is almost entirely Phase 3 because it depends on third parties responding to you [1]. Splitting each measure across the phase where its evidence is actually generated is what makes the schedule honest.

For Phase 3 and Phase 4 evidence, ENISA’s technical implementation guidance on Implementing Regulation (EU) 2024/2690 organises the requirements into 13 areas with worked evidence examples [13]. It is formally addressed to the digital-infrastructure and digital-provider sectors that Regulation covers, and ENISA states it “is not a legally binding document”, advising entities to consult national authorities first. Used as an evidence template rather than a compliance standard, it is the most detailed public reference available — see our guide to the implementing regulation.

Week Allocation by Headcount: 22, 32, or 44 Weeks

In plain terms: here is the week budget. Treat it as a planning heuristic drawn from implementation practice, not a legal requirement — the Directive sets no implementation duration at all.

Phase 50–100 employees 100–250 employees 250+ employees
1. Scoping and gap 4 weeks 6 weeks 8 weeks
2. Foundation documentation 6 weeks 9 weeks 12 weeks
3. Technical controls 8 weeks 11 weeks 16 weeks
4. Audit-readiness 4 weeks 6 weeks 8 weeks
Total 22 weeks 32 weeks 44 weeks

Notice the shape. Headcount rises roughly fivefold from the bottom band to the top, but plan length only doubles — the signature of a project containing two different kinds of work.

Effort-bound work scales with money and people. Writing 30 policies instead of 15, deploying MFA across 400 accounts instead of 80, collecting configuration evidence from five sites instead of one — all of it compresses if you add a consultant or a second internal owner. That is most of Phase 2 and much of Phase 4.

Latency-bound work does not compress at all. Three items dominate:

  • Supplier response turnaround. Article 21(3) requires entities to take into account “the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers” [1] — a per-supplier assessment cycle. In practice a tier-1 questionnaire comes back in two to six weeks, and sending sixty at once makes no single one return faster. Chasing non-responders is the most under-budgeted line in Phase 3. See supplier due diligence.
  • Approval cadence. An Article 20(1) approval needs a meeting [2]. A group with a board, a risk committee and local managing directors has three sequential approval layers, each on its own calendar — typically two to four weeks per layer, and hiring does not change that.
  • External scheduling. Penetration tests, certification bodies and external auditors book out weeks ahead. Phase 4 is largely waiting, punctuated by short bursts of work.

That is why a 400-person group cannot triple its project team and finish in 22 weeks: roughly a third of the critical path is calendar, not labour. It also shows where extra budget genuinely helps — external writing support collapses Phase 2 and barely touches Phase 3.

Article 21(1) supports calibrating the effort itself, not just the schedule. Measures must be “appropriate and proportionate”, assessed against “the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity” [1]. A leaner programme at a 60-person important entity is not a shortcut around the Directive — it is the proportionality the Directive contemplates, and it still has to be documented and defensible.

Size drives outcomes, not just schedules. ENISA’s NIS360 2026 assessment found progress “remains uneven both across and within sectors”, attributing that to skills shortages, sector characteristics and organisational size, with seven sectors — health, railway, maritime, ICT service management, space, public administrations, and drinking and waste water — in a risk zone where maturity lags criticality [12].

Fitting the Plan Into a Twelve-Month Calendar

In plain terms: a year is 52 weeks on paper and about 48 in practice. Subtract the summer and year-end freezes before you claim you have slack.

Band Plan length Nominal slack in 52 weeks Slack after freezes and approval gates Sequencing verdict
50–100 22 weeks 30 weeks ~24 weeks Fully sequential. Absorbs one complete re-plan without missing the year.
100–250 32 weeks 20 weeks ~14 weeks Sequential, but Phase 1 must start in Q1 or Phase 4 lands in the year-end freeze.
250+ 44 weeks 8 weeks ~2–4 weeks Does not fit sequentially. Phases 2 and 3 must overlap from month four.

That last row is what most twelve-month roadmaps quietly skip. For a 250+ entity, a strictly sequential four-phase plan consumes the entire year with no meaningful buffer — one delayed board approval, or one supplier assessment round that has to be re-run, and audit-readiness slips into the following year. Large entities have to start Phase 3 while Phase 2 is still in draft, writing the technical control policies against the risk assessment’s interim output and accepting one round of rework.

Concretely, for the 250+ band: scoping and registration in months 1–2, gap register scored by the end of month 2; documentation drafting months 3–5, with the first board approval slot booked for month 5; technical control deployment starting month 4 in parallel and running to month 9; supplier assessments launched in month 4 so the slowest responders still land before month 9; internal audit and continuity exercise in months 10–11; management review and evidence pack in month 12. The deliberate overlap in months 4–5 is where the eight weeks of nominal slack actually come from.

If your runway is 90 days rather than a year, the sequencing changes completely — our 90-day SME plan covers that compressed case, and the 30/60/90/180-day roadmap sets out the same four phases as checkpoint gates rather than a calendar. That checkpoint version reaches audit-readiness by day 180 for a mid-market entity while this model budgets 32 weeks because checkpoint models measure working time and this one measures elapsed time, waiting included. Use the checkpoint view to brief a board; use the elapsed view to commit to a date.

Milestone Checkpoints: Evidence, Owner, and Gate Criteria

In plain terms: a milestone you cannot fail is not a milestone. Each gate below has a named artefact and a pass test.

Gate Evidence artefact Owner Pass test
End of Phase 1 Scope statement, entity classification memo, registration confirmation Compliance officer Every in-scope legal entity, site and service is named, and the national registration is filed or evidenced as not yet triggered
Phase 1 exit Scored gap register CISO or IT lead All ten Article 21(2) measures scored, each gap has an owner and a target phase
Mid-Phase 2 Incident handling procedure with 24h/72h/1-month decision points CISO or IT lead A named person can be reached out of hours and knows who files the early warning
End of Phase 2 Board resolution approving the measures, plus training records Management body Minuted approval under Article 20(1); management-body training logged under Article 20(2)
End of Phase 3 Control configuration evidence and tier-1 supplier assessment results CISO or IT lead, with Procurement Every critical supplier is either assessed or on a documented, dated chase list
End of Phase 4 Internal audit report, continuity exercise report, management review minutes Compliance officer Findings raised, corrective actions assigned with dates, review minuted

Two roles carry the schedule risk. The compliance officer owns the gates a supervisory authority opens with — scope, registration, and the management review. The CISO or IT lead owns the gate most likely to slip, because Phase 3 depends on outsiders. Boards should ask about the supplier chase list by name: it is the earliest reliable signal that a twelve-month plan will miss. Our audit readiness guide details what supervisors request first.

When Your Runway Is Shorter Than the Plan

In plain terms: if you have six months and a 44-week plan, cut in this order — and document every deferral.

Never cut these. Registration, because it carries its own statutory trigger [10]. A working Article 23 notification path, because the 24-hour clock does not wait for your project [5]. Management-body approval and training, because Article 20(1) places responsibility for the entity’s infringements on the management body itself [2]. And the risk assessment, because every other measure has to be proportionate to something.

Compress these. Documentation depth — a lean, accurate policy set beats an elaborate one nobody follows, and expands later. Supplier assessment breadth — Article 21(3) is explicitly risk-based, so assessing genuinely critical tier-1 suppliers first and scheduling the rest is a defensible reading [1], provided the selection criteria are written down.

Defer these, with a dated plan. The effectiveness measurement cycle under 21(2)(f), the full continuity exercise, and the internal audit. Article 21(4) requires an entity that finds it does not comply to take “all necessary, appropriate and proportionate corrective measures” without undue delay [1]. A written, time-bound remediation plan you are visibly executing is a materially better position than a half-finished programme nobody documented — though it is not the same thing as compliance, and a supervisory authority may still act.

One caution on the compressed route: this reads a risk-based provision, it is not a safe harbour, and where a national implementation is stricter than the Directive’s baseline the national text governs. Start your own analysis from a scored gap register rather than from this article — our five-phase gap analysis sets out the scoring method.

Frequently Asked Questions

Does NIS2 set a deadline for having the measures in place?
No. The Directive sets a transposition deadline for Member States — 17 October 2024 [14] — plus dated obligations for registration and incident reporting, but prescribes no implementation period for the Article 21 measures themselves. The obligations apply from the point your national law makes you an in-scope entity. The 22/32/44-week model is a planning tool, not a grace period.

Is 22 weeks realistic for a 60-person company with no existing certification?
Yes, when the scope surface genuinely matches the band: one legal entity, one or two sites, a manageable tier-1 supplier list, no OT, and a decision-maker who can approve without a committee. No, if the company has never run a risk assessment and has nobody able to own the work internally for at least two days a week.

We already hold ISO 27001. How much does that cut?
Most of Phase 2 and part of Phase 4, since the policy set, risk methodology, internal audit function and management review already exist and need mapping rather than authoring. In practice the total tends to come down by roughly a third — but Phase 3 barely moves, because supplier response times and MFA rollout are unaffected by certification. Our ISO 27001 and NIS2 guide covers the mapping.

When exactly do we have to register?
It depends on your Member State. Article 27 set 17 January 2025 for the ENISA registry categories [6]; national registration runs separately. Germany requires it within three months of first or renewed NIS2 affectedness, and the BSI reports the statutory deadline as already expired [9]. Check your national instrument; our NIS2 regulatory timeline has the EU-level dates.

Can we be fined while implementation is still in progress?
Supervisory and fining powers attach to the obligations, not to your project status. Article 34 sets the ceilings — EUR 10 000 000 or 2 % of worldwide annual turnover for essential entities, EUR 7 000 000 or 1,4 % for important entities, whichever is higher [7]. Whether an authority acts mid-programme is a matter of national enforcement practice, and practice differs considerably between Member States.

Key Takeaways

  • Size band and entity class are different tests. Crossing 50 staff makes you medium-sized; only exceeding the medium-sized ceilings in an Annex I sector makes you essential [4].
  • Budget 22 weeks at 50–100 employees, 32 at 100–250, and 44 at 250+, split roughly 4/6/8, 6/9/12, 8/11/16 and 4/6/8 across scoping, documentation, technical controls and audit-readiness.
  • Plan length doubles while headcount rises fivefold, because supplier turnaround, approval cadence and external scheduling are latency-bound and do not respond to extra staffing.
  • A 250+ entity cannot fit a sequential four-phase plan into twelve months. Overlap Phases 2 and 3 from month four and accept one round of rework.
  • Registration, the Article 23 notification path, board approval and the risk assessment are never the things to cut. Effectiveness measurement, the continuity exercise and the internal audit can be deferred against a dated, written plan.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. Article 21 — Cybersecurity risk-management measures, Directive (EU) 2022/2555.
  2. Article 20 — Governance, Directive (EU) 2022/2555.
  3. Article 2 — Scope, Directive (EU) 2022/2555.
  4. Article 3 — Essential and important entities, Directive (EU) 2022/2555.
  5. Article 23 — Reporting obligations, Directive (EU) 2022/2555.
  6. Article 27 — Registry of entities, Directive (EU) 2022/2555.
  7. Article 34 — General conditions for imposing administrative fines, Directive (EU) 2022/2555.
  8. SME definition, European Commission (Recommendation 2003/361/EC thresholds).
  9. NIS-2-regulierte Unternehmen, Bundesamt für Sicherheit in der Informationstechnik (BSI).
  10. NIS-2-Pflichten, Bundesamt für Sicherheit in der Informationstechnik (BSI).
  11. § 39 BSIG — Nachweispflichten, gesetze-im-internet.de.
  12. NIS360 2026: maturity and criticality of NIS critical sectors, ENISA.
  13. Supporting NIS2 implementation through actionable guidance, ENISA.
  14. Commission calls on 23 Member States to fully transpose the NIS2 Directive, European Commission.
  15. Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice, European Commission, 8 July 2026.
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: