NIS2 remediation roadmap (Piano di Adeguamento): practical guide for ID.IM-01 approval


Article Thumbnail

NIS2 remediation roadmap (Piano di Adeguamento): practical guide for ID.IM-01 approval

January 30, 2026

The remediation roadmap (“Piano di Adeguamento”) is a mandatory Appendix C document and requires governing/management approval under ID.IM-01 point 1. In practice, this plan should convert risk, audit, and incident findings into sequenced implementation work with clear owners, deadlines, and closure evidence.

Key takeaways

  • The remediation plan is an approval-required governance instrument, not a technical to-do list.
  • It should consolidate gaps from risk assessment, control reviews, incidents, and compliance checks.
  • Milestones should be aligned with the first-application baseline deadline (October 2026).
  • Effective plans enforce accountability, dependency mapping, and measurable closure criteria.

Timeline context for planning discipline

ObligationFirst-application timingPlanning impact
Incident-notification obligationsJanuary 2026 (9-month milestone)Already live; remediation should include immediate operational stabilization
Baseline security-measure adoptionOctober 2026 (18-month milestone)Roadmap must drive closure of remaining baseline gaps before deadline

What an approvable ID.IM-01 roadmap must show

ObjectiveMinimum outputEvidence
Gap consolidationUnified list of findings and obligationsConsolidated gap register
PrioritizationRisk/impact-based sequencingPriority model and rationale
Delivery governanceOwner, milestone, due date, statusProgram tracker and steering notes
Closure controlObjective completion criteriaClosure evidence log

Practical remediation-plan structure

1. Purpose, scope, and references

Define scope of remediation and legal/ACN reference model.

2. Input sources and baseline gap inventory

List where gaps come from: assessments, reviews, incidents, audits, and authority requirements.

3. Prioritization framework

Define how actions are ranked (risk, regulatory urgency, dependency, effort).

4. Workstreams and milestones

Group actions by domain and assign delivery milestones up to October 2026.

5. Ownership and escalation

Assign accountable owners and define escalation thresholds for delays.

6. Closure and verification model

Define acceptance criteria and required evidence for each action closure.

7. Governance reporting cycle

Set steering cadence, KPI set, and re-prioritization triggers.

Frequent remediation-plan failures

  1. Too many actions with no prioritization logic.
  2. Deadlines without dependency mapping.
  3. Actions closed with no verifiable evidence.
  4. No explicit accountability for delayed or blocked items.
  5. Plan not updated after incidents or risk reassessment.

20-day hardening checklist

  1. Consolidate all open findings into one remediation register.
  2. Apply a documented prioritization model.
  3. Define milestones and dependency chains through October 2026.
  4. Assign accountable owners and escalation paths.
  5. Set closure criteria and required evidence per action.
  6. Submit roadmap for governing-body approval and monthly review.

FAQ

Is the remediation roadmap mandatory for approval?

Yes. Appendix C lists “Piano di adeguamento” with reference ID.IM-01 point 1.

Can the remediation plan be merged with risk treatment?

It can be linked tightly, but should remain clear as a governance roadmap with milestone and closure discipline.

What is the main governance KPI for this plan?

On-time closure rate of prioritized actions with valid evidence, not just task completion volume.

Conclusion and next steps

A strong ID.IM-01 plan is the operational backbone of NIS closure toward October 2026. The immediate focus should be one integrated, evidence-driven roadmap that links risk decisions to accountable execution and verifiable outcomes.

Related reading

Official sources

Share this post