Harmonizing NIS2 and NIST 800–53

Has anyone built a unified control baseline that satisfies NIS2 without blowing up existing NIST 800–53 mappings? I’m updating our enterprise security policy for Q1 2025 and running into conflicts on incident reporting clocks (early warning in 24 hours vs fuller report by 72) and supplier assurance evidence; curious what you’ve codified in policy text versus left to procedures to keep compliance clean.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‌​⁠​​​⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠‍‍‌⁠‌‍‌‍‍​‌‌​‍​⁠​⁠‌‍‌​​⁠​​‌‌‌‍‌‍‍⁠‌‌‍‌‌‍​‍‌​​⁠‌​⁠‌‌​​⁠‌​‌‌‌⁠‌⁠​‍​‍‌⁠⁠‌​