Why exceptions are where posture is lost
The exceptions register is usually the least governed document in a security program and the first thing an auditor or a regulator asks for after an incident. An exception granted by email, without expiry, is a permanent hole nobody remembers agreeing to. Unpatchable medical devices, legacy industrial controllers, a supplier that cannot meet a contractual clause: each is legitimate as a time-boxed decision and dangerous as a forgotten one.
The lifecycle that makes them defensible
A governed exception moves through request, risk assessment, approval by the authority the residual risk requires (a team lead for low, the CISO for medium, the risk committee for high), active with compensating controls verified, then expiry with a forced re-decision: close, extend with a new date, or escalate. Every step is dated and attributable, so the register can answer “who accepted this, when, and on what basis” for any item at any time.
In the regulations
Neither NIS2 nor DORA uses the word derogation, but both require risk-management measures to be approved by management and assessed for effectiveness, and DORA explicitly expects documented risk acceptance for residual ICT risk. An exception is precisely that acceptance, and a register that shows the decision ladder and the expiry dates is what turns a policy gap from a finding into a governed risk.