Observation
Compliance Is More Than Just Yes or No
15 June 2026 · Author: Lisbeth Loft
What matters is not only whether a requirement is met, but how it works in practice.
Compliance is often treated as a binary question: is the requirement met – yes or no?
That makes sense when adherence must be documented. But it does not necessarily say much about how well a requirement is actually implemented, or whether it works in the organisation’s everyday life.
A requirement can be described in a policy without being implemented. It can be implemented without being known to those who must work according to it. And it can be known and applied without necessarily working as intended.
Compliance therefore becomes more interesting when we move beyond asking only whether something exists, and instead examine how it works.
From Requirement to Actual Practice
When we assess compliance, it can be useful to distinguish between several levels:
- Requirement
- What is the organisation expected to do?
- Documentation
- Has the requirement been translated into policies, procedures, roles or other governing documents?
- Implementation
- Has what is documented actually been introduced into the organisation?
- Actual practice
- Does it work in the way the organisation goes about its work?
These four levels can give very different pictures of the same control.
An organisation may, for example, have a well-documented procedure for supplier risk assessment. But if the assessments are only carried out sporadically, or if the results are not used in decisions, it is difficult to say that the control works fully in practice.
The same applies across many other areas: policies may be approved, roles described and controls established – without that necessarily meaning they function consistently across the organisation.
Compliance Comes in Degrees
That does not mean requirements become optional. Some requirements obviously must be assessable as met or not met.
But between those two extremes there is often important information.
A control can, for example, be:
- established, but only partially implemented
- implemented, but not consistently applied
- working well in parts of the organisation, but not in others
- implemented, but without sufficient documentation
- both implemented and documented, but without systematic follow-up
It is precisely these differences that make a compliance assessment useful as a governance tool.
When Compliance Is Subject to Regulatory Oversight
With new and tightened requirements, including NIS2, it is becoming increasingly important to be able to demonstrate more than the existence of a policy or procedure.
NIS2 sets requirements for, among other things, management accountability, reporting of significant security incidents and the implementation of cybersecurity measures. For organisations in scope, adherence is also something that may become subject to supervision by the relevant sectoral authorities.
That changes the perspective on compliance.
It is not necessarily sufficient to present a policy and conclude that a requirement has been formally addressed. The organisation must also be able to show how the requirements have been put into practice, how the chosen measures work, and how they are followed up.
The Danish Digitalisation Agency, for example, carries out NIS2 supervision within the digital sector, while other sectoral authorities supervise their respective areas.
It is precisely here that the difference between documentation, implementation and actual practice becomes important.
The Assessment Must Be Usable
If the result is merely a long list of green and red markers, it can be difficult to see where the organisation should actually act.
A more nuanced picture makes it possible to distinguish between, for example:
- areas where basic implementation is missing
- minor gaps that can be closed relatively easily
- controls that work but should be better documented
- areas where practice varies across the organisation
- issues that constitute a real risk and should therefore be prioritised
In this way, compliance becomes not only documentation of the past. It also becomes a basis for prioritising the next step.
That also makes the assessment more usable in dialogue with management, because it shows not only where there are gaps, but how significant they are and where the organisation should prioritise its effort.
From Compliance to Governance
That is particularly important in complex organisations, where requirements from NIS2, internal policies, standards, contracts and other regulatory requirements must all work at the same time.
Here the question is not only whether the organisation can tick a box for a requirement.
The relevant question is also:
How well is the requirement embedded, where does it work in practice, and where is there a need to do things differently?
That gives management a better basis for prioritising resources and makes it easier to follow developments over time.
Compliance thereby becomes less a question of yes or no – and more a question of understanding where the organisation actually stands.