NIS2 scoping analysis and the establishment of security governance
The client, which serves EU customers, had an unclear position with respect to NIS2. A scope analysis was carried out; the management-responsibility framework, the policy set, and the incident-reporting processes were established within a single programme.
Investment cannot be planned until the scope question is answered
The sector and size criteria had to be read together with the security undertakings in the customer contracts.
Management wanted a clear view of the personal-liability framework and the reporting expectations.
Our Approach
Keeping the commercial objective at the centre, we broke the legal risks down into measurable steps.
01 · Scope
The scope was determined on a reasoned basis through sector, size and service links.
02 · Policy Set
Risk-management and security policies were written in practical, workable language.
03 · Notification Framework
An incident-classification and tiered-notification flow was established.
Timeline
The main stages of the process.
Security governance owned by management
The company gained a governance model that knows its scope, keeps its policy set alive, and has established in advance who reports what the moment an incident occurs.
- A reasoned scope assessment
- Workable policy set
- A tiered incident-notification flow
- A management-reporting framework
Services Involved in This Matter
Planning a similar transaction? Explore the services we provided in this matter.
Related Areas of Expertise
The practice and focus areas engaged on this matter.
Sectors
The sectors in which we most frequently advise on matters of this kind.
Related Publications
Our insights and guides related to this matter.

Product compliance when selling into the EU: GPSR, accessibility, and the new packaging regime
The new preconditions for selling into the EU go beyond legal texts: a responsible person under the GPSR, an accessible store under the BFSG, packaging registration under LUCID/PPWR. A seller's-eye map of the 2024–2026 wave.
Read more →
Being a marketplace seller: 7 legal topics, from account suspension to the 1% withholding
Amazon, Etsy, Trendyol: the law of marketplace selling starts with the contract, continues with DSA verification and GPSR fields, and is tested by withholding and suspensions. 7 topics from the seller's perspective.
Read more →
E-commerce from Türkiye to the EU: VAT, OSS/IOSS and GDPR checklist
The three compliance layers of selling online to consumers in the EU: VAT registrations (OSS/IOSS), GDPR and consumer rules. A market-entry checklist for Turkish e-commerce companies.
Read more →The Team on This Matter
Our multilingual team handling the matter.
Related Matters
A selection of similar transactional and advisory matters.
Uninterrupted legal counsel for a multinational supplier
Retainer-based support across day-to-day commercial operations, contract management and compliance processes.
Designing corporate governance across group companies
Single-source management and documentation of general assembly, board and compliance processes.
Building a single compliance programme for KVKK and GDPR
Establishing the data inventory, document set, transfer mechanisms and breach plan of a group selling in two markets within a single programme.
First we clarify the commercial objective, risk appetite, timeline and decision-maker needs. Then we break the work down into legal analysis, document/contract structure and implementation steps, and manage the process through a single point of contact.
Owing to the legal profession's duty of confidentiality and client privacy, matters are anonymised. In a meeting, within the limits of confidentiality, we can describe our comparable experience more concretely.
In a brief preliminary meeting we take in the objective, existing documents, parties, time pressure and critical risks. We then clarify the scope, team, timeline and fee model.
To complete a similar matter with confidence.
Let us manage your process from start to finish with our experience in similar cases.


