Compliance · NIS2

NIS2 scoping analysis and the establishment of security governance

The client, which serves EU customers, had an unclear position with respect to NIS2. A scope analysis was carried out; the management-responsibility framework, the policy set, and the incident-reporting processes were established within a single programme.

ScopeNIS2scope + governance
LanguagesTR·DE·ENWorking languages
Practice AreaSingle programmescope + policy + reporting
SectorTechnologyB2B service
At a Glance
Our RoleCorporate advisor
Matter TypeNIS2 scope and governance
Client ProfileTechnology company serving the EU
Counterparty / StakeholderEU customers and the regulatory framework
Working LanguagesTurkish · German · English
StatusCompleted · Anonymised matter
01 · Situation

Investment cannot be planned until the scope question is answered

The sector and size criteria had to be read together with the security undertakings in the customer contracts.

Management wanted a clear view of the personal-liability framework and the reporting expectations.

02

Our Approach

Keeping the commercial objective at the centre, we broke the legal risks down into measurable steps.

01 · Scope

The scope was determined on a reasoned basis through sector, size and service links.

02 · Policy Set

Risk-management and security policies were written in practical, workable language.

03 · Notification Framework

An incident-classification and tiered-notification flow was established.

03

Timeline

The main stages of the process.

1AnalysisScope determinationThe NIS2 position was substantiated.
2DesignGovernanceRoles and management reporting were established.
3SetupPolicy and processThe sets were tested through a drill.
4TransferMonitoringAn annual-review routine was left in place.
04 · Outcome

Security governance owned by management

The company gained a governance model that knows its scope, keeps its policy set alive, and has established in advance who reports what the moment an incident occurs.

  • A reasoned scope assessment
  • Workable policy set
  • A tiered incident-notification flow
  • A management-reporting framework
06

Related Areas of Expertise

The practice and focus areas engaged on this matter.

Related Regional DeskData & Cybersecurity DeskIntegrated advice spanning multiple jurisdictions in KVKK and GDPR compliance, cross-border data transfer, and cyber incident response.See the regional desk
09

The Team on This Matter

Our multilingual team handling the matter.

First we clarify the commercial objective, risk appetite, timeline and decision-maker needs. Then we break the work down into legal analysis, document/contract structure and implementation steps, and manage the process through a single point of contact.

Owing to the legal profession's duty of confidentiality and client privacy, matters are anonymised. In a meeting, within the limits of confidentiality, we can describe our comparable experience more concretely.

In a brief preliminary meeting we take in the objective, existing documents, parties, time pressure and critical risks. We then clarify the scope, team, timeline and fee model.

Track Record

To complete a similar matter with confidence.

Let us manage your process from start to finish with our experience in similar cases.