Valeo · security governance / January 2026
NIS2 started working when we stopped treating it as a list of legal quotations
The first hard problem was not technical. Legal requirements had to be translated into operational tasks with real evidence, accountable roles and states that could actually be verified.
Situation
During NIS2 preparation in January, it quickly became clear that knowing the wording of the regulation was not enough. Management needed to understand what each requirement meant in day-to-day operations, while technical teams needed to know which concrete evidence was expected from them. Without a translation layer between those worlds, everyone can read the same paragraph and still be solving a different problem.
Approach
Instead of continuing chapter-by-chapter explanations, I decomposed requirements into operational questions: what is the control trying to achieve, who can demonstrate it, which system produces the evidence, how fresh that evidence is, and what happens when it is missing. That created a shared language across legal, audit and technical roles. Where the regulation allowed more than one interpretation, I did not present an assumption as a technical fact.
Outcome
The work gradually moved from audit preparation into a manageable operating backlog. Gaps no longer meant only red cells; they had next actions, responsible roles and outputs that could be checked. Management reporting also became shorter because each status update no longer had to retell the full regulatory background.