NIS2 does not prescribe a fixed frequency, but organizations should:

  • Conduct assessments periodically (e.g., annually)
  • Update assessments after:
    • Major changes
    • New threats
    • Significant incidents

The approach should be risk-based and proportionate.