Which IT systems, components and processes at your organisation fall under NIS2 and the BSIG — and how to define the scope precisely.
The technical scope of NIS2 covers all systems, components and processes that your organisation uses to deliver its services and that process information technically. Four criteria must be met simultaneously.
A functional whole made up of technical and software-based parts
Individual parts that form part of a larger system
Workflows in which IT is used to handle data
The most common misconception in practice: organisations limit the scope to the IT department. NIS2, however, covers all systems used to deliver the regulated service — regardless of where they are operated.
A clearly defined scope boundary is the prerequisite for a robust gap analysis and efficient resource planning. Draw the scope too widely and you waste budget — draw it too narrowly and you risk compliance gaps.
Which of your organisation's services are NIS2-relevant? The starting point is classification as an important or especially important entity under the BSIG.
Record all IT systems, components and processes that contribute directly or indirectly to delivering these services — including cloud and external service providers.
For every element in scope: assess availability, integrity and confidentiality. The result feeds directly into the risk analysis under § 30 (1) BSIG.
We help you define the technical scope in a legally sound way and link it directly to the risk analysis.
Request Consultation Now