Appearance
Operationalizing in Modulos
NIS2 implementation is most effective when organization-level governance (OFF-15) and AI-service execution (MFF-15) are run as one operating model.
Recommended project structure
Most teams use:
- one organization project for OFF-15 governance requirements
- one or more AI-application projects for MFF-15 execution and evidence
Where in Modulos
Project → Settings → Frameworks: addOFF-15andMFF-15to relevant projectsProject → Requirements: track requirement fulfillment and ownershipProject → Requirements → Filters: useNIS2 Scopetags to isolate conditional duties that need a scoping decisionProject → Controls: execute mapped controls and collect review outcomesProject → Evidence: store authority notices, reports, and supporting artifacts
How to handle applicability without a questionnaire
The current NIS2 framework does not rely on a dedicated descoping questionnaire.
Use this operating pattern instead:
- Determine base NIS2 scope with
ORF-333toORF-335. - Filter the requirement set by the
NIS2 Scopetags. - Read the Applicability section in each tagged requirement.
- Decide whether the duty is in scope or out of scope for the project.
- Record the reason and supporting evidence in the requirement review and attached evidence.
This makes the scoping decision explicit and reviewable even though it is not yet automated.
A sequence that works
- Determine NIS2 scope and entity classification (
ORF-333toORF-335). - Review the conditional requirements using the
NIS2 Scopetags (ORF-349,ORF-355toORF-359,MRF-291,MRF-292). - Establish management accountability and Article 21 measure governance (
ORF-336toORF-348). - Activate AI-service technical measures (
MRF-275toMRF-285). - Implement staged incident-reporting workflows (
ORF-350toORF-354;MRF-286toMRF-290). - Maintain supervisory, authority-facing, and special-case duties where applicable (
ORF-358toORF-360;MRF-291,MRF-292).
Evidence package baseline
A defensible NIS2 package usually includes:
- scope and classification decisions with approvals
- requirement-level scoping notes for any tagged duty treated as out of scope
- governance policy and management-body oversight records
- incident classification matrix and reporting runbook
- executed 24-hour and 72-hour reporting evidence, or tested simulations
- implementing-act applicability assessment and update log, where relevant
Related pages
NIS2 overview
Framework structure and coverage model
Scope and applicability
Entity scope, manual applicability handling, and NIS2 Scope tags
Incident reporting and communications
Staged reporting duties and evidence workflow
Disclaimer
This page is for general informational purposes and does not constitute legal advice.