Abstract blue network rings representing a three-horizon NIS2 long-term compliance programme

NIS2 Long-Term Compliance Programme: 3 Horizons, 36 Months, and the Year-2 Shift From Project to Run Cost

Most NIS2 programmes are built to end. They are scoped as a project, funded as a project, and staffed with contractors who leave when the gap analysis closes. Then Year 2 arrives, the budget line reverts to business-as-usual, and the obligations do not move an inch.

The Directive does not describe a project. Article 21(1) pegs your required measures to the state-of-the-art — a baseline that rises without asking you. Article 21(4) makes correction a standing duty. And Article 40 puts the Commission itself on a 36-month review cycle. Those three clauses are why a compliance programme has horizons rather than an end date, and they are what this guide plans against.

Does This Apply to You, and Has Your Programme Actually Ended?

In plain terms: if you are an essential or important entity, you never finish. You reach a defensible floor, and then you are expected to hold it while the floor moves. This guide is for the stage after go-live — the 24 months almost nobody budgets for.

Member States had to adopt NIS2 measures by 17 October 2024 and apply them from 18 October 2024 [1]. That date set the clock running; it did not stop it.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Where you are What this guide gives you Start at
Scoping or pre-go-live The cost shape you should commit to now, so Year 2 is not a surprise Horizon 1, then the cost section
Just passed go-live (0-12 months) Exit criteria for Horizon 1 and what Horizon 2 actually contains Horizon 2
Second year, budget under pressure The integration moves that cut cost without cutting controls Horizon 2 and the failure modes
Mature programme, asked to justify itself Certification pathways and the value case beyond avoided fines Horizon 3
Not currently in scope Scope is not static — national authorities can add sectors [2] Horizon 3 scope-drift note

The 36-Month Clock Is in Article 40, Not in a Consultant’s Deck

Three-horizon models are standard consulting furniture, and they are usually arbitrary. Here they are not. NIS2 contains three separate clocks that run at different speeds, and each one governs a different kind of work.

Article 40 sets the outer boundary. Verbatim: “By 17 October 2027 and every 36 months thereafter, the Commission shall review the functioning of this Directive, and report to the European Parliament and to the Council.” The review must “in particular assess the relevance of the size of the entities concerned, and the sectors, subsectors and types of entity referred to in Annexes I and II”, and it “shall be accompanied, where necessary, by a legislative proposal” [1]. A 36-month plan is not a nice round number. It is one full turn of the legislator’s own cycle — the interval after which your scope, your entity class, and your obligations can all legitimately change.

Article 21(1) makes the floor move underneath you. Measures must be “appropriate and proportionate”, determined “taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation” [1]. State-of-the-art is a moving reference, not a fixed one. The control set that was proportionate in 2025 is evidence of nothing in 2028 unless you re-tested it against a newer baseline. This is the clause that makes “we implemented NIS2” a meaningless sentence after about eighteen months.

Article 21(4) makes correction continuous. An entity that “finds that it does not comply” must take “without undue delay, all necessary, appropriate and proportionate corrective measures” [1]. Note the trigger: it is finding, not being told. A programme with no mechanism for finding its own failures is not merely under-managed — it leaves the trigger for its own corrective duty with very little to fire on.

Clause What it fixes What it means for your plan
Art. 40 — review 17 Oct 2027, then every 36 months Plan in 36-month horizons; assume scope may change at each turn
Art. 21(1) — state-of-the-art Nothing. It floats. Re-test proportionality annually; a 2025 control set is not 2028 evidence
Art. 21(4) — corrective measures Nothing. Continuous. You must fund a detection capability, not just a remediation budget
Art. 24(2) — certification Delegated acts “shall include an implementation period” Any future mandatory certification arrives with a runway — watch for it in Horizon 3
Art. 20(2) — training Management-body training required; staff training encouraged “on a regular basis” A recurring annual cost, not a launch expense

Map those clocks onto a plan and the horizons fall out on their own.

Horizon 1 (Months 0-12): Reach the Floor and Leave Evidence

Horizon 1 has one job: produce a defensible documented position on all ten Article 21(2) measures, with dated evidence that someone approved it. Not “be secure” — be demonstrable.

The detailed sequencing of this year is a separate problem, and we have covered it at length: the phase-by-phase plan sized to headcount lives in the NIS2 implementation timeline, the honest floor is counted in minimum viable compliance, and the starting diagnostic is the gap analysis. What matters here is Horizon 1’s exit condition, because that is what most programmes never define — and a horizon without an exit condition runs forever on Year 1 money.

You have left Horizon 1 when all four of these are true:

  1. Every measure in Article 21(2)(a)-(j) has a named owner and a document with a date on it.
  2. The management body has formally approved the measures, per Article 20(1), and the minute records it [1].
  3. You can produce the evidence for any one measure within one working day, without asking a contractor.
  4. You have a written method for assessing effectiveness — Article 21(2)(f) — that is scheduled, not aspirational.

Point 3 is the one that quietly fails. If the only person who can find your risk treatment plan is billing you a day rate, you have bought a deliverable rather than a capability — and Horizon 2 will cost you twice.

Horizon 2 (Months 12-24): Remove the Duplication, Not the Controls

Horizon 2 is where programmes die, and the cause is usually financial rather than technical. The project money is gone, the obligations are identical, and the instinct is to cut controls. The better move is to cut duplication instead — because much of what a Year-1 compliance programme built already existed somewhere else in the business under a different name.

The economics leave little room. Across the EU, cybersecurity budgets account for 9% of total IT budgets, and cybersecurity staff now represent 10.6% of total IT full-time equivalents — “the lowest proportion observed to date”, according to ENISA’s 2025 NIS Investments study of 1,080 organisations [3]. Most organisations will not get a bigger team in Year 2. They get the same team and a wider obligation, which makes efficiency the main available lever.

Here is where the duplication usually sits. Each row is a function that already runs a process a compliance programme often rebuilds from scratch:

Function What it already runs The NIS2 duplicate to retire The merge
IT operations Change management, patch cycles, asset inventory A parallel “compliance asset register” maintained by hand Make the CMDB the single asset source; compliance reads it rather than re-keying it
Legal / contracts Contract review, clause libraries, renewal calendar A separate supplier security questionnaire chased by the security team Put Article 21(2)(d) clauses into the standard contract template so they ship by default
Procurement Vendor onboarding, due diligence, approved-supplier list A standalone supplier criticality spreadsheet Add the security tier as a field in onboarding — see supplier due diligence
HR Induction, mandatory training, leaver process, records An awareness platform with its own separate reporting line Fold Article 20(2) training into the existing mandatory-training record — see training requirements
Internal audit / risk An annual audit plan and a corporate risk register A security-only risk register nobody outside security reads Feed cyber risks into the corporate register using the same scoring scale

Two cautions, because this move can be done badly. First, integration means the process merges while the evidence stays separable — an authority asking under Article 21(2) wants your security records, not a tour of HR’s learning management system. Second, retiring a duplicate is only safe when the surviving process has an owner who knows it now carries a regulatory obligation. Absorbing a control into a function that does not know it inherited it is how a control disappears.

Horizon 2 is also when the maturity conversation becomes real. Broadly, Horizon 1 moves you from ad-hoc to defined; Horizon 2 is the climb from defined to managed — the point where you measure rather than assert. The level-by-level detail, and how to score yourself, is set out separately in our NIS2 maturity assessment. What belongs here is the budget consequence: “managed” tends to cost less per year than “defined” only after the duplication is gone.

Horizon 3 (Months 24-36): Make It Worth More Than the Fine You Avoided

By Horizon 3 the defensive case is exhausted. You have not been fined, which proves little, and a board that has funded compliance for three years will reasonably ask what else it bought. Three answers hold up.

Certification becomes available — and it is not ready yet. This matters for planning, because the pathway many entities will eventually use does not currently exist. Ireland’s NCSC, which holds the role of Lead Competent Authority for entities without a sectoral regulator, has joined the Cyber Fundamentals Framework (CyFun) as a scheme co-owner and states plainly that “a national certification system will take 18-24 months to establish due to the need for legal agreements, resourcing, and accreditation infrastructure. In the meantime, entities are encouraged to use the framework internally and begin preparations” [2]. Read that as a scheduling instruction: the internal work that makes certification cheap later is Horizon 2 work, and the certification itself is a Horizon 3 event. CyFun is built on the NIST Cybersecurity Framework and assesses organisations at maturity levels, which is why the maturity climb in Horizon 2 converts into certification readiness rather than being a parallel exercise.

Mandatory certification may arrive with a runway. Article 24(2) empowers the Commission to adopt delegated acts specifying categories of entities required to use certified ICT products, services or processes, and those acts “shall be adopted where insufficient levels of cybersecurity have been identified and shall include an implementation period” [1]. That implementation period is your warning shot — but only if someone is watching for it. Our certification schemes roadmap tracks what is actually in flight.

Scope drift is a real Horizon 3 risk. The Article 40 review explicitly assesses “the relevance of the size of the entities concerned, and the sectors, subsectors and types of entity” in Annexes I and II [1], and at national level authorities can extend coverage — NCSC Ireland notes the Irish government “holds the authority to include additional sectors or subsectors” [2]. A group that is only partly in scope today should assume the boundary can move at the 2027 review, and should avoid building a programme that only works for the entities currently captured.

The commercial answer is the one boards understand fastest: a mature programme lets you answer a customer’s supplier security questionnaire in days instead of weeks, and lets you impose the same discipline on your own suppliers. ENISA records supply-chain and third-party compromise as the second most cited future concern, at 47% [3]. Your customers are running that assessment on you already.

What Three Horizons Cost, and Why Year 2 Is the Budget That Gets Cut

The awkward property of a NIS2 programme is that its cost shape and its obligation shape are different. Cost is front-loaded; obligation is flat. Most of what goes wrong in Year 2 comes from budgeting as if the two curves matched.

The shift is from a project cost model to an operational one. Year 1 buys artefacts — policies, a gap analysis, an architecture. Years 2 and 3 buy recurrence: the effectiveness assessment under Article 21(2)(f), the recurring management-body and staff training under Article 20(2), the re-test of proportionality against a moved state-of-the-art under Article 21(1) [1]. None of those are capital items, and none of them stop.

The table below is a planning model, not a market survey. It shows how each delivery approach tends to distribute a five-year total, so you can test your own numbers against the shape. Percentages are of that approach’s own five-year total, and they are deliberately relative because absolute figures depend on your size and sector. For euro anchors, see our 2026 compliance budget breakdown and the day-rate benchmarks in choosing a consultant.

Approach Yr 1 Yr 2 Yr 3 Yr 4-5 Where the risk sits
Consultant-led ~35% ~20% ~15% ~30% Cost decays slowly: each annual cycle is re-purchased at day rates, and knowledge leaves with the contract
In-house ~30% ~20% ~17% ~33% Often cheapest at five years, slowest to Year 1 evidence, and exposed to a single hire leaving
Hybrid (buy structure, run internally) ~40% ~15% ~15% ~30% Highest Year 1, lowest Year 2 — specialists are bought only for the parts that need one

The pattern that matters is not which row is cheapest overall — at five years they converge more than vendors on any side admit. It is Year 2. The consultant-led model’s Year 2 is a repeat purchase; the hybrid model’s Year 2 is the cheapest year in the table, because the structure was bought once and the running is internal. That column is where the five-year totals separate, and it is the column nobody presents to a board in Year 1.

Two honest caveats. These proportions are a planning heuristic for structuring a budget conversation, not measured market data — treat them as a shape to argue with, not a quote. And an in-house model is only cheaper if the person exists: ENISA records 76% of organisations struggling to attract and 71% to retain cybersecurity professionals, rising to 94% and 90% among SMEs [3]. An in-house plan that assumes a hire you cannot make is a consultant-led plan with a worse start date.

Four Ways a Long Programme Dies Before the Next Audit

These are failure modes rather than mistakes: each is individually rational, and each is visible early if you know the signal.

1. Compliance theatre. The programme produces documents that describe controls nobody operates. The pattern shows up in the aggregate data: 70% of organisations name regulatory compliance as their main cybersecurity investment driver, yet 30% have not conducted a cybersecurity assessment in the past 12 months and 28% take more than three months to patch critical vulnerabilities [3]. Spend driven by compliance, sitting alongside unassessed and slowly-patched estates, is what theatre looks like at population scale. First signal: your policy set is current and your last effectiveness assessment is undated.

2. Consultant dependency that never unwinds. ENISA’s headline finding for 2025 is investment “shifting from people to technology and services”, with spending “increasingly focused on technology and outsourcing rather than internal cybersecurity teams” [3]. Outsourcing is a legitimate delivery choice; dependency is what happens when nobody internally can explain why a control exists. First signal: no one on staff can answer an authority’s question about a measure without forwarding it.

3. Policy without process. The document exists and the recurring activity it describes has never run once. Article 21(2)(f) requires “policies and procedures to assess the effectiveness of cybersecurity risk-management measures” [1] — and a procedure that has never executed produces no evidence. It also weakens the Article 21(4) trigger: corrective measures follow from finding a non-compliance, and a programme with no working detection mechanism has little chance of finding one. First signal: a policy whose review date has passed with no record of the review.

4. The single-owner programme. Everything routes through one person, so the programme’s capability is that person’s calendar. This one has a specific legal edge: Article 20(1) places approval, oversight and liability on the management body, not on the security lead [1]. A programme with one owner sits awkwardly against the accountability the Directive actually assigns. First signal: the board’s only cyber input is one person’s verbal update. Fixing the structure is its own subject — see programme governance.

Success Criteria by Horizon

Set these before the horizon starts. A criterion agreed afterwards is a description, not a target.

Horizon Evidence that must exist Question the board can answer Cost signal
1 (0-12 mo) All ten Art. 21(2) measures documented, owned and dated; management-body approval minuted “What have we implemented, and who approved it?” Peak spend; heavy external share
2 (12-24 mo) At least one completed effectiveness assessment; duplicate processes retired, each with a named surviving owner “Is it working, and what did we stop paying for twice?” Sharpest fall; external share should drop
3 (24-36 mo) Certification readiness assessed; proportionality re-tested against current state-of-the-art; scope re-checked against the Art. 40 review “What does this buy us beyond not being fined?” Flat run-rate; spend is recurring, not project

Turning the middle column into numbers you can track monthly is a separate build — the indicator set is in our compliance monitoring dashboard, and the annual review cadence is covered in continuous improvement.

What to Do Next, by Role

  • CISO / security manager: write the Horizon 1 exit condition down this month, even if you passed it a year ago. Then check for the four failure signals above — the undated effectiveness assessment is usually the first one you find.
  • Compliance officer: build the integration matrix for your own organisation before the Year 2 budget round, not after. “We removed three duplicate processes” is a defensible answer to a cut; “we reduced controls” is not.
  • Board member / director: ask one question at the next review — “when did we last test whether these measures work, and what changed as a result?” Article 20(1) makes oversight your obligation, and that question tests it directly. The board presentation format structures the rest.
  • SME owner without a security team: set Horizon 3 aside for now. Your task is Horizon 1’s four exit criteria plus one scheduled annual review — and getting the recurring costs into the operating budget rather than treating them as a one-off.

Frequently Asked Questions

Does NIS2 require a three-year compliance programme?
No. The Directive prescribes no programme structure at all. The three-horizon model here is a planning device built on real clauses: Article 40’s 36-month Commission review cycle, Article 21(1)’s moving state-of-the-art baseline, and Article 21(4)’s continuous corrective duty [1]. You are obliged to meet the measures on an ongoing basis; how you phase that work is your choice.

When does the first Commission review happen, and does it affect me?
By 17 October 2027, and every 36 months after that. It assesses whether the entity sizes, sectors and subsectors in Annexes I and II are still right, and can be accompanied by a legislative proposal [1]. It does not change your obligations by itself, but it is the scheduled moment at which scope can shift — which is why a plan that only works for your current entity classification is fragile.

Is in-house always cheaper than consultants over five years?
Usually, but not reliably, and not for the reason people assume. The five-year totals converge more than either side tends to claim; the separation happens in Year 2, when a consultant-led model re-purchases the annual cycle. The in-house case also depends on a hire you may not be able to make — 76% of organisations report difficulty attracting cybersecurity professionals, rising to 94% among SMEs [3].

Can I get NIS2 certified?
Not through a single EU-wide NIS2 certificate today. Article 24 lets Member States require certified ICT products and services under European schemes, and empowers the Commission to make that mandatory for defined categories via delegated acts that “shall include an implementation period” [1]. Nationally, schemes are still being stood up: NCSC Ireland estimates 18-24 months to establish a national certification system and advises entities to use the CyFun framework internally in the meantime [2].

How much should we budget annually after Year 1?
There is no regulatory figure, and any single number would be misleading. The useful benchmark is ENISA’s: cybersecurity budgets average 9% of total IT budgets across surveyed EU organisations, with cybersecurity staff at 10.6% of IT FTEs [3]. The more important budgeting decision is structural: move the recurring items — effectiveness assessment, training, proportionality re-testing — into operating cost, so they are not re-argued each year as new projects.

What if we cut the programme budget in Year 2?
The obligations do not scale with your budget. Article 21(1) does allow cost of implementation to be weighed in judging proportionality, alongside your exposure, size, and the likelihood and severity of incidents [1] — so cost is a legitimate factor, not an excuse the law ignores. What it does not support is silently dropping a measure. If a cut changes what you can operate, re-run the proportionality assessment and document the reasoning, so the decision is a recorded judgement rather than an unexplained gap.

Key Takeaways

  • The 36-month horizon is not arbitrary: Article 40 puts the Commission on a review cycle of “17 October 2027 and every 36 months thereafter”, and that review can reach your sector and size classification.
  • Article 21(1)’s “state-of-the-art” reference means the compliance floor rises on its own. A control set is evidence only for as long as it has been re-tested.
  • Horizon 1 needs a written exit condition. Without one, Year 1 funding and Year 1 assumptions run indefinitely.
  • Horizon 2’s job is removing duplication across IT, legal, procurement, HR and internal audit — not removing controls. At 9% of IT budget and 10.6% of IT headcount, efficiency is the main lever available.
  • Year 2 is where five-year totals actually separate, because that is when a consultant-led model re-purchases the annual cycle.
  • The four failure modes — theatre, dependency, policy without process, single ownership — each have an early signal. The undated effectiveness assessment is the most common first sighting.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. Directive (EU) 2022/2555 (NIS2) — EUR-Lex, Official Journal. Articles 20, 21, 24, 25, 40 and 41.
  2. NIS2 Frequently Asked Questions — National Cyber Security Centre (NCSC) Ireland, national competent authority.
  3. NIS Investments 2025 — ENISA, European Union Agency for Cybersecurity (6th edition; 1,080 respondents).
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: