Features Pricing Our AI AI Project Plan Generator
Industries Internal projects Use Cases Case Studies
Blog Knowledge library Comparisons PM Templates Free Tools Integrations AI Project Management API & Developers
Login Get started free
Example project plan

Project plan for a NIS2 implementation

With NIS2, risk management, incident reporting and supply chain security become mandatory for far more companies — and management is personally liable. This plan shows the implementation in a mid-sized machinery manufacturer with 350 employees.

No sign-up · opens instantly · 30 Weeks · 10 Phases · 83 Tasks · Budget approx. €378,000

This is how the plan looks in PathHub — click through the tabs or tick off tasks.

app.pathhub.ai/try?example=nis2-enOpen live
Example plan

NIS2 Cybersecurity Compliance and Operational Resilience Implementation

This project will implement NIS2 requirements for a mid-sized machinery manufacturer with 350 employees, covering authority registration, governance, cybersecurity risk management, incident reporting, supply chain security, and workforce training. The work must align regulatory obligations with operational realities in both IT and production/OT environments. Security controls and process changes will be introduced in a way that protects manufacturing continuity and minimizes disruption. The project also establishes the evidence base and operating cadence needed for ongoing compliance.

Total Progress0%
30Weeks
0/10Phases
0/83Tasks
€378,000Budget
AI Recommendations KIAI Chat KIAI Tools KI

Phases

1

Phase 1: Applicability, Scope and Project Mobilization

Pending · 3W · 0/5
CISO / IT Security Manager
0

This phase confirms the manufacturer’s NIS2 applicability, defines the legal and operational scope, and establishes the governance needed to deliver the 12-month implementation. It also aligns management, IT, production, legal, and external parties on objectives, decision rights, and constraints.

Timeline

Timeline 10 PhasesStart: Oct 1, 2026
Phase / Task
Oct 2026
Nov 2026
Dec 2026
Jan 2027
Feb 2027
Mar 2027
Apr 2027
W 1Oct 1
W 4Oct 22
W 7Nov 12
W 10Dec 3
W 13Dec 24
W 16Jan 14
W 19Feb 4
W 22Feb 25
W 25Mar 18
W 28Apr 8
Applicability, Scope and Project MobilizationOct 1 – Oct 21 · 3 wk · 0/5
Applicability, Scope and Project Mobilization
Current-State Assessment and Gap AnalysisOct 22 – Nov 25 · 5 wk · 0/9
Current-State Assessment and Gap Analysis
Governance Design and Authority RegistrationOct 29 – Nov 25 · 4 wk · 0/7
Governance Design and Authority Registration
Cybersecurity Risk Management FrameworkNov 26 – Jan 6 · 6 wk · 0/9
Cybersecurity Risk Management Framework
IT/OT Security Controls and Remediation RoadmapDec 17 – Feb 10 · 8 wk · 0/13
IT/OT Security Controls and Remediation Roadmap
Incident Detection, Response and ReportingDec 24 – Feb 3 · 6 wk · 0/9
Incident Detection, Response and Reporting
Supply Chain Security and Supplier ManagementDec 31 – Feb 3 · 5 wk · 0/8
Supply Chain Security and Supplier Management
Management, Workforce and Role-Based TrainingJan 7 – Feb 3 · 4 wk · 0/6
Management, Workforce and Role-Based Training
Testing, Exercises and Compliance ValidationFeb 11 – Mar 24 · 6 wk · 0/10
Testing, Exercises and Compliance Validation
Remediation Closeout and Operational HandoverMar 25 – Apr 28 · 5 wk · 0/7
Remediation Closeout and Operational Handover
PlannedIn progressCompletedBlockedMilestones

Budget

Budget: €378,000
Internal Personnel · €154,300External Consulting and Assurance · €122,300Software and Security Infrastructure · €55,000Management Training and Workforce Awareness · €28,000Supplier Assurance and Operational Workshops · €18,400
Internal Personnel€154,300
ItemQtyUnit priceTotal
Cybersecurity Program Manager35 Person days€900€31,500
CISO / IT Security Manager50 Person days€950€47,500
IT Infrastructure and Application Owners35 Person days€750€26,250
OT / Production Engineering Specialists30 Person days€800€24,000
Legal, Compliance and Data Protection Officer18 Person days€850€15,300
Procurement, HR, Business Continuity and Quality Support15 Person days€650€9,750
External Consulting and Assurance€122,300
ItemQtyUnit priceTotal
NIS2 Applicability, Legal Interpretation and Authority Registration Consultant18 Person days€1,200€21,600
IT/OT Current-State Assessment and Risk Analysis Consultant35 Person days€1,100€38,500
Incident Response and Regulatory Reporting Consultant22 Person days€1,150€25,300
Supply Chain Cybersecurity Consultant18 Person days€1,050€18,900
Independent NIS2 Readiness Review and Compliance Assurance15 Person days€1,200€18,000
Software and Security Infrastructure€55,000
ItemQtyUnit priceTotal
GRC, Risk Register and Compliance Evidence Platform12 Person days€1,000€12,000
OT Asset Discovery and Network Visibility License1 Flat rate€14,000€14,000
MFA and Privileged Access Management Licenses350 Person days€50€17,500
Immutable Backup and Recovery Enhancement1 Flat rate€8,000€8,000
SIEM and Centralized Security Logging Onboarding1 Flat rate€3,500€3,500
Management Training and Workforce Awareness€28,000
ItemQtyUnit priceTotal
Management Board Cybersecurity Accountability Workshops16 Person days€375€6,000
Role-Based IT, OT, Incident Response and Procurement Training80 Person days€150€12,000
Organization-Wide Security Awareness E-Learning350 Person days€20€7,000
Training Administration, Completion Tracking and Communications Materials1 Flat rate€3,000€3,000
Supplier Assurance and Operational Workshops€18,400
ItemQtyUnit priceTotal
Critical Supplier Cybersecurity Assessments12 Person days€800€9,600
Supplier Contract and Security-Requirement Workshops16 Person days€250€4,000
On-Site IT/OT and Production Security Workshops4 Person days€1,200€4,800

Risks

High

Incorrect NIS2 Applicability or Registration Scope

If the national transposition law or competent authority confirms a different sector classification, entity size threshold, registration scope, or reporting channel after Week 3, the project may implement the wrong obligations or miss a required registration deadline.

Countermeasure: Legal, Compliance and the DPO, supported by the CISO, will issue a documented applicability opinion and obtain authority clarification by Week 3; the project charter and registration data will be formally reapproved by Management by Week 8.
High

Incomplete IT/OT Asset and Dependency Inventory

If undocumented PLCs, HMIs, engineering workstations, legacy operating systems, remote-access routes, or production dependencies remain unidentified by the end of Week 8, the risk assessment and remediation plan will exclude critical manufacturing assets.

Countermeasure: IT Infrastructure and OT/Production Engineering will perform passive discovery, owner interviews, and production-dependency mapping, with Plant Management validating the inventory by Week 8 and revalidating it before Week 25 testing.
High

Production Disruption During Security Remediation

If segmentation, patching, MFA, endpoint monitoring, or authentication changes are deployed without plant testing and rollback procedures before Week 19, manufacturing availability, safety, or validated production processes could be affected.

Countermeasure: OT/Production Engineering and Plant Management will approve a controlled change process, test changes in a representative environment, schedule maintenance windows, and document rollback procedures before each production deployment, with priority controls completed by Week 19.
High

Ransomware or Malware Propagation into Production

If IT/OT segmentation, privileged-access controls, remote-access restrictions, endpoint protection, or offline backup restoration are not validated by Week 19, malware could spread from corporate IT or suppliers into production systems and cause extended downtime.

Countermeasure: IT Infrastructure Owners and OT Engineering will implement segmented network zones, MFA for remote and privileged access, controlled jump hosts, and offline or immutable backups by Week 19; recovery restoration will be tested during Phase 9 by Week 25.
High

Failure to Meet Incident Reporting Timelines

If an incident remains unassigned, evidence is unavailable, or a supplier does not notify the company promptly, the organization may fail to issue an early warning within 24 hours or an incident notification within 72 hours of becoming aware of a significant incident.

Countermeasure: The Incident Response Team and SOC/MSSP will establish a 24/7 escalation roster, severity criteria, authority-reporting templates, evidence-preservation procedures, and legal review steps by Week 18; a timed reporting exercise will be completed by Week 25.
High

Insufficient Supplier Visibility and Contractual Leverage

If critical automation, software, maintenance, logistics, or remote-support suppliers are not classified and assessed by Week 18, or refuse updated cybersecurity and incident-notification clauses, material third-party exposure may remain unmanaged.

Countermeasure: Procurement and Supplier Quality Management will identify critical suppliers by Week 16, complete priority assessments and contract negotiations by Week 18, restrict non-compliant remote access, and obtain Management-approved risk acceptance or alternative supplier controls before Week 25.
High

Unsupported Legacy OT Systems and Vulnerability Exposure

If legacy controllers, industrial PCs, or vendor-supported-but-unpatchable systems are identified during Phase 5 without compensating controls by Week 19, exploitable vulnerabilities may remain in production networks.

Countermeasure: The CISO, OT Engineering, and Plant Management will create a vulnerability exception register by Week 14, apply network isolation, allowlisting, restricted administration, virtual patching, and enhanced monitoring by Week 19, and document replacement or residual-risk decisions by Week 30.
Medium

Management Accountability and Training Non-Compliance

If the management body has not completed NIS2 cybersecurity training or formally approved risk acceptance, policies, and funding by Week 18, the organization may lack evidence of required management oversight and accountability.

Countermeasure: The Managing Director and HR/Learning & Development will schedule management training by Week 15, achieve completion by Week 18, and obtain documented approvals for the risk methodology, priority residual risks, and security program by Week 30.
Medium

Insufficient Resources, Budget, or Audit Evidence

If remediation effort exceeds the EUR 420,000 budget, internal security capacity is unavailable, or operating evidence is not captured as controls are implemented by Week 25, priority gaps may remain open and the company may be unable to demonstrate compliance.

Countermeasure: The CISO and Project Manager will maintain a weekly risk, budget, and evidence dashboard from Week 4, engage an MSSP or specialist support by Week 8 where required, preserve the EUR 42,000 reserve for approved exceptions, and complete an evidence review before Week 30.

Stakeholders

MB

Management board/Managing Director

Owns NIS2 accountability, risk acceptance, funding, and formal approval of the security program

Involve: Phase 1
CO

CISO or IT Security Manager

Leads implementation, defines controls, manages the risk register, and coordinates evidence

Involve: Phase 1
II

IT Infrastructure and Application Owners

Provide inventories and implement technical controls for identity, monitoring, backup, and vulnerability processes

Involve: Phase 2
OP

OT/Production Engineering and Plant Management

Protect manufacturing continuity, assess industrial dependencies, and approve operational changes

Involve: Phase 2
LC

Legal, Compliance and Data Protection Officer

Interprets NIS2 obligations, reviews policies and contracts, and supports authority communications

Involve: Phase 1
IR

Incident Response Team, SOC or Managed Security Service Provider

Defines detection, escalation, containment, evidence preservation, and reporting capabilities

Involve: Phase 2
PA

Procurement and Supplier Quality Management

Implements supplier classification, due diligence, contractual requirements, and ongoing supplier assurance

Involve: Phase 2
HA

HR and Learning & Development

Coordinates management training, role-based training, completion tracking, and employee communications

Involve: Phase 3
BC

Business Continuity, Quality and Risk Management

Aligns cybersecurity controls with continuity, recovery, quality management, and operational risk processes

Involve: Phase 2
WC

Works council or employee representatives, if applicable

Reviews workforce-impacting monitoring, training, and process changes where required by local employment law

Involve: Phase 3
CN

Competent national authority and external assurance specialists

Provide registration guidance, clarify reporting expectations, and independently validate readiness where needed

Involve: Phase 1

Compliance

Mandatory

Determine whether the machinery manufacturer is within scope of the applicable national NIS2 legislation, document the legal basis, identify the competent authority, and complete required entity registration or notification.

Legal, Compliance and Data Protection Officer; Managing Director; CISO Weeks 1–8, with updates when national guidance changes
Mandatory

Establish and operate cybersecurity risk-management measures covering governance, asset and risk management, access control, vulnerability handling, incident prevention, business continuity, backups, crisis management, and recovery for IT and OT environments.

CISO; IT Infrastructure Owners; OT/Production Engineering; Business Continuity and Risk Management Design Weeks 4–14; implementation Weeks 12–30; ongoing thereafter
Mandatory

Implement significant-incident reporting processes supporting an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month where required by the applicable NIS2 regime.

Incident Response Team; SOC/MSSP; Legal and Compliance Design Weeks 13–18; exercise and validation Weeks 20–25; ongoing thereafter
Mandatory

Maintain an incident response capability with escalation ownership, evidence preservation, authority contacts, reporting templates, forensic readiness, and tested communication procedures.

Incident Response Team; SOC/MSSP; CISO Weeks 13–25; ongoing thereafter
Mandatory

Ensure the management body approves the cybersecurity program, receives appropriate training, oversees risk decisions, and formally accepts or funds residual risks.

Managing Director; Management Board; HR/Learning & Development Training and approvals Weeks 15–18; formal closeout by Week 30; ongoing oversight
Optional

Use an industrial cybersecurity framework such as IEC 62443 for OT zoning, conduits, secure remote access, system hardening, and lifecycle controls, and align the information-security management system with ISO/IEC 27001 where proportionate.

CISO; OT/Production Engineering; IT Infrastructure Owners Design Weeks 4–14; implementation and validation Weeks 12–30

Milestones

  1. Week 3

    Approved NIS2 applicability decision, project charter, scope statement, governance structure, and 12-month implementation plan

    Depends on: Phase 1 completion
  2. Week 8

    Management-approved current-state assessment, validated IT/OT inventory, NIS2 gap register, and prioritized remediation backlog

    Depends on: Phase 2 completion
  3. Week 8

    NIS2 registration submitted or accepted, management accountability charter approved, governance forums established, and evidence repository operational

    Depends on: Phase 3 completion
  4. Week 14

    Approved NIS2 risk methodology, populated risk register, prioritized treatment plan, and documented risk acceptance process

    Depends on: Phase 4 completion
  5. Week 18

    Approved incident response framework, playbooks, escalation roster, authority reporting templates, and tested evidence-preservation process

    Depends on: Phase 6 completion
  6. Week 18

    Critical supplier register, completed priority supplier assessments, updated contract clauses, controlled supplier access, and ongoing supplier assurance process

    Depends on: Phase 7 completion
  7. Week 18

    Management training completed, role-based courses delivered, workforce awareness launched, and auditable completion records available

    Depends on: Phase 8 completion
  8. Week 19

    Priority IT/OT controls deployed or formally risk-accepted, with tested change records, updated diagrams, implementation evidence, and residual-risk decisions

    Depends on: Phase 5 completion
  9. Week 25

    Completed exercises and technical tests, validated reporting timelines, independent readiness review, and approved final remediation backlog

    Depends on: Phase 9 completion
  10. Week 30

    Priority gaps closed or approved, policies and risks formally approved, complete evidence pack delivered, operational owners assigned, and continuous NIS2 compliance calendar activated

    Depends on: Phase 10 completion

How this plan was created

This plan was created by PathHub AI from a single description: “Implement the NIS2 requirements in a mid-sized machinery manufacturer with 350 employees: registration with the authority, risk management, incident reporting processes, supply chain security and management training within 12 months.” — without company context. With your departments, approval processes and compliance requirements it becomes much more precise.

Frequently asked questions

How long does a NIS2 implementation take?
In the example plan, a NIS2 implementation takes 30 weeks in 10 phases, of which 5 phases partly run in parallel. The actual duration depends on company size, starting point and available resources — with your company context PathHub adjusts the schedule accordingly.
What does a NIS2 implementation cost?
The example plan estimates about €378,000, split into 23 budget line items with quantity and unit price. The largest items are Internal Personnel, External Consulting and Assurance. This is an AI estimate as a starting point, not a quote.
What are the risks of a NIS2 implementation?
The plan lists 9 risks with countermeasures. Rated highest: Incorrect NIS2 Applicability or Registration Scope; Incomplete IT/OT Asset and Dependency Inventory; Production Disruption During Security Remediation.
Who needs to be involved in a NIS2 implementation?
Among others, the plan includes these people: Management board/Managing Director, CISO or IT Security Manager, IT Infrastructure and Application Owners, OT/Production Engineering and Plant Management, Legal, Compliance and Data Protection Officer, Incident Response Team, SOC or Managed Security Service Provider. For each role it states why and from when to involve them.
Can I adapt the plan to my company?
Yes. Open the plan in PathHub without signing up, adjust phases and tasks or describe your own initiative — with company context (departments, approval processes, works council, compliance requirements) every further plan gets more precise.

More project plan examples

Adapt this plan to your company

Open the plan in PathHub — no sign-up. Or describe your own initiative and get a complete plan in minutes.

Open plan →