Accountability should sit with leadership as well as security operations. NIS2 explicitly raises the responsibility of boards, executives, and operational teams, because compliance depends on governance, funding, supplier oversight, and technical enforcement. OT leaders need a clear owner for access control, evidence collection, and incident readiness, otherwise compliance becomes fragmented and difficult to sustain.
Why accountability for NIS2 readiness in OT cannot be pushed to one team
NIS2 readiness in OT is a governance problem as much as a technical one. It depends on the people who can fund remediation, set risk appetite, approve supplier constraints, and force through operational changes, as well as the teams that implement access control, logging, segmentation, and incident procedures. The accountable owner must be able to resolve cross-functional blockers, not just monitor status.
In practice, that means accountability should not sit only with plant operations or only with security. OT environments mix availability, safety, legacy systems, and vendor dependency, so readiness fails when the owner cannot direct both policy and implementation. A clear accountable leader is what turns NIS2 from a checklist into a sustained control programme.
The leadership owner also needs enough authority to make trade-offs explicit. If a remediation step affects uptime, supplier access, maintenance windows, or evidence collection, someone senior must decide whether the residual risk is accepted, reduced, or escalated. Without that authority, the organisation tends to inherit fragmented ownership and delayed decisions.
What accountability should cover across leadership, security, and OT operations
Accountability should cover governance, resourcing, and enforcement together. Leadership owns the programme outcomes, security operations own the control design and monitoring, and OT teams own the operational realities that make controls safe to deploy. This division works only when one named accountable executive can align them and remove ambiguity over who approves, who implements, and who verifies.
For NIS2, the accountable function must cover three concrete areas. First, access governance, including who can reach control systems and under what conditions. Second, evidence collection, because readiness requires proof of control operation, not just policy language. Third, incident readiness, because OT teams must know who declares, escalates, contains, and communicates when something goes wrong.
Supplier oversight is part of that accountability too. OT organisations often depend on integrators, OEMs, managed service providers, and remote support paths, so readiness depends on someone being able to constrain third-party access and verify that supplier obligations are reflected in contracts, technical controls, and review cycles.
Why fragmented ownership undermines NIS2 readiness in OT
Fragmentation creates gaps between policy intent and field reality. If one team owns compliance wording, another owns remote access, and a third owns plant uptime, then no one is accountable for the full control chain. That is how evidence gets stale, exceptions accumulate, and access decisions are made informally outside the governance process.
OT also amplifies the cost of unclear ownership because changes are slow, safety-sensitive, and often vendor-dependent. A weakly defined accountability model can leave critical accounts unreviewed, incident playbooks untested, and exceptions untracked. For a useful reference point on how OT security expectations are structured, see NIST SP 800-82 Rev 3, the OT Security Guide.
For NIS2 specifically, readiness also benefits from a clear control-owner model for identity and access. If your organisation is mapping readiness obligations to control ownership, Identity Security Regulatory Map is useful for aligning governance expectations with access control work, and Ultimate Guide to NHIs, Regulatory and Audit Perspectives is useful where machine and service access must also be governed and evidenced.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | NIS2 readiness in OT depends on governance ownership and business context. |
| GV.RM-01 — Risk Management Strategy | Accountability must align readiness work with accepted OT risk and resourcing. | |
| Recommendation — Define the OT readiness owner and decision rights within the governance context. Assign a leader to set the OT risk posture and resolve readiness trade-offs. | ||
| NIST SP 800-53 Rev 5 | PM-1 — Information Security Program Plan | Readiness needs a managed program with named ownership and oversight. |
| AC-2 — Account Management | OT readiness includes ownership of account provisioning, review, and revocation. | |
| AU-6 — Audit Record Review, Analysis, and Reporting | NIS2 readiness requires evidence collection and review responsibility. | |
| Recommendation — Establish a formal program owner for OT security and compliance delivery. Make one role accountable for OT account lifecycle control. Assign responsibility for reviewing and acting on OT security evidence. | ||
| ISO/IEC 27001:2022 | A.5.3 — Segregation of duties | OT readiness needs clear role boundaries so accountability does not blur. |
| A.5.1 — Policies for information security | A NIS2 program needs governance policy with accountable oversight. | |
| Recommendation — Separate approval, implementation, and review duties for OT controls. Set policy ownership for OT security and compliance expectations. | ||
Practitioner Guidance
What to prioritise: Name one accountable executive for NIS2 readiness, then assign operational control owners underneath that role. If you cannot point to a single person who can approve scope, force remediation, and accept or escalate residual risk, accountability is still diffused.
What to verify: Confirm that the accountable owner can produce evidence for access reviews, supplier controls, incident exercises, and remediation tracking. In OT, readiness is credible only when the organisation can show who approved exceptions, who closed gaps, and who is responsible for overdue actions.
Common mistake: Treating readiness as a compliance exercise owned solely by security or solely by plant operations. That usually produces good paperwork and weak execution, because neither side can independently close the loop across governance, technology, and operational constraints.
Practitioner takeaway: The right accountable owner is the one who can align board expectations, operational constraints, and technical enforcement, then prove that the controls still work after the first exception, vendor request, or incident.