Compliance project management for NIS2: from delivery to compliance
The Project Manager’s role has changed forever. Compliance project management for NIS2 now demands a capability that five years ago was optional: knowing how to deliver projects not only on time and budget, but with full regulatory compliance. Most classic methodologies do not incorporate compliance as a core axis of the project, and that leaves many teams exposed to penalties, delays and reputational damage. In this article we analyse how to evolve from the classic “delivery” to the compliance project management that NIS2, DORA and the EU AI Act demand. When the regulatory scope is critical —as in banking— the role of the DORA consultant in banking is key to articulating the compliance programme.
Compliance project management for NIS2: why it is different
This approach is not simply about adding a legal checklist at the end of the project. It is a complete transformation of how a project with technology components and regulatory impact is planned, executed and closed.
Compliance project management for NIS2: the traditional approach is no longer enough
Moreover, for decades the success of an IT project was measured by the classic triangle: scope, time and cost. Many Project Managers still operate with this mindset, adding compliance as an appendix at closing. They discover too late that their deliverable does not meet the security, resilience or documentation requirements the regulation demands.
Compliance as an axis, not an annex
On the other hand, the NIS2 directive has raised cybersecurity requirements to management obligations, with significant penalties and personal responsibility for executives. For this reason, compliance must be integrated into every sprint, every milestone and every deliverable, not added at the end.
Compliance project management for NIS2: the PM’s new triangle
This model transforms the classic triangle into a tetrahedron where compliance is the fundamental fourth dimension.
Compliance project management for NIS2: the four dimensions
Every project decision is now evaluated on four axes: scope (what is delivered), time (when), cost (how much) and compliance (which regulations apply and how it is demonstrated). The PM must understand not only management methodologies but also the regulatory frameworks affecting their project.
Competences of the modern PM
Because of this, the 2026 Project Manager needs regulatory literacy: knowing the scope of NIS2, the requirements of DORA, the obligations of the EU AI Act and the intersection points with the GDPR. It is not about becoming a lawyer, but about being able to translate legal requirements into project requirements.
Compliance project management for NIS2: integration into the life cycle
Undoubtedly, this approach must be present from the first phase of the project through to closing and operation.
Compliance project management for NIS2: initial regulatory assessment
For this reason, every project with significant technology components must start with a regulatory assessment: which regulations apply? what risk level does the system have? what specific obligations does it generate? This assessment conditions the subsequent planning and must be updated if the scope changes.
Planning phase: critical non-functional requirements
Moreover, the compliance requirements translate into specific non-functional requirements: traceability, auditability, resilience, incident notification, third-party management. These requirements enter the backlog with the same priority as functional requirements, not afterwards.
Execution phase: integration into the sprints
On the other hand, each sprint or iteration must include compliance tasks: validations, technical documentation, updates to the processing register, resilience tests. Finally, skipping these tasks generates a “compliance debt” as dangerous as technical debt, and with far more serious legal consequences.
Closing phase: evidence and audit
Finally, the project closing must include a package of evidence demonstrating compliance: records, tests, certifications, active incident response plans. When the audit comes (internal, external or regulatory), the material is ready without needing to reconstruct it under pressure.
Compliance project management for NIS2: third-party and supply-chain management
On the other hand, one of the most demanding aspects of this approach is managing the third parties involved in the project.
Contractual supervision
In this context, NIS2 and DORA require active supervision of critical providers. Contracts with technology providers must include specific clauses: cybersecurity service levels, incident notification obligations, right of audit and subcontracting requirements.
Continuous, not one-off, assessment
Supervision is not carried out once at the start of the contract. There must be a continuous review process: annual questionnaires, joint incident response tests, review of certifications and assessment of the provider’s financial health. Because of this, the PM needs third-party tools that automate this supervision in projects with multiple providers.
Compliance project management for NIS2: metrics and reporting
Finally, this approach requires specific metrics that go beyond the traditional project KPIs.
Compliance KPIs
Modern dashboards include indicators such as: percentage of controls implemented vs planned, average time to close audit findings, resilience test coverage, status of documentary evidence and maturity of the incident response processes.
Reporting to the management committee
Moreover, management is no longer satisfied with knowing whether the project is on time. It demands to know whether the project is on compliance, because they are the ones who bear personal responsibility under NIS2. According to ENISA, the level of preparedness of European organisations to comply with NIS2 varies significantly by sector.
In conclusion, compliance project management for NIS2 is neither a fad nor added bureaucracy: it is the new normal of technology project management in Europe. The Project Managers who master it will become strategic assets for their organisations; those who stay in the classic delivery model will progressively lose relevance. The future of the PM is no longer in the Gantt: it is at the intersection between execution and compliance.
In that vein of regulatory compliance: DORA regulation and IT regulations 2026.
Frequently asked questions
Compliance project management for NIS2 changes relative to the original NIS directive because it broadens the scope to more sectors, requires much shorter incident notification deadlines (24-72 hours) and holds management directly responsible. What used to be good practice is now an obligation with penalties.
Essential and important entities in sectors such as energy, banking, healthcare, digital infrastructure, transport, water and public administration. If you have more than 50 employees or more than 10 million in turnover in one of those sectors, you are almost certainly within scope.
Every project that touches critical systems carries requirements for risk management, provider controls, a continuity plan and reporting. The PM has to integrate those points into the planning, not add them at the end.
Ensuring that each delivery meets the required controls, that the risks are documented and that the traceability survives an audit. If the PM does not lead it, it ends up being security work done too late.
An inventory of critical systems, a gap analysis against the required controls and a quarterly plan with quick wins in incident management and supply chain. Perfection is not the goal, demonstrating measurable progress and executive awareness is.
A programme to run with little margin for error? See how I have done it.
See the nine case studies