NIS 2 Documentation Toolkit
Become NIS 2 compliant without a consultant, with an AI wizard that speeds up filling out the documents.Step-by-step guidance with LIVE EXPERT SUPPORTn
-
What you getn
nNIS 2 Documentation Toolkit (in English) — 77 editable documents (policies, procedures, templates, and reports)
nFree add-on: Local cybersecurity toolkit — NIS 2 Documentation Toolkit translated into the local language, expanded with additional templates required by national cybersecurity laws and incident reporting regulations.Editable MS Word and MS Excel policies, procedures, plans, and forms required for NIS 2 articles 20, 21, and 23 and Commission Implementing Regulation (CIR) 2024/2690nAI-powered wizard to speed up document completionEvery EU country will publish their own laws and regulations based on NIS 2 and CIR 2024/2690 where they specify additional cybersecurity requirementsnnWizard that automatically inserts company-specific information into your documents — company name, logo, job titles, departments, etc. -
NIS 2 Documentation Toolkit (in English) includesn
nAll required cybersecurity and incident reporting templates, fully compliant with NIS 2 Directive and Commission Implementing Regulation (CIR) 2024/2690nPractical examples of evidence to help you demonstrate implementation in line with the ENISA NIS2 Technical Implementation Guidancenn
-
Local cybersecurity toolkitn
nSelect one country-specific local cybersecurity toolkit as a free add-on during the purchase process
nFully localized and aligned with national legislation, including additional required templates — see available country-specific toolkitsnnIf national cybersecurity legislation for your selected country is not yet published, we will deliver your country-specific toolkit within 90 days of its official release — free of charge. -
Included supportn
nFree updates for 24 months
nEmail supportYou’ll receive updated policies and procedures for a full 2 years after your purchase, free of charge.nExpert review of a documentWe will answer your questions within 1 business day. You can send up to 10 questions per month.nOne hour of live 1-on-1 online consultationAfter completing the document, you can send it for our review, and we’ll give you our comments on what you need to improve to make it compliant with the standard.nNIS2 Cybersecurity Training & Awareness programSet up a time to speak to our experts to resolve issues with implementation or answer questions regarding the standard.nnThree months of free access for up to 10 users to a comprehensive NIS2 Cybersecurity Training & Awareness program.
Austria has published a local law (Netz- und Informationssystemsicherheitsgesetz 2026 – NISG 2026) based on NIS 2 — you will receive:nnNIS2 Documentation Toolkit (English and German version, compliant with both NIS 2 and Austria’s Netz- und Informationssystemsicherheitsgesetz 2026 – NISG 2026) — immediately after purchasenn
Belgium has published a local law (Durchführungsverordnung (EU) 2024/2690 der Kommission und dem Netz- und Informationssystemsicherheitsgesetz 2026 – NISG 2026 based on NIS 2 — you will receive:nnNIS2 Documentation Toolkit (English, French, and Dutch version, compliant with both NIS 2 and Belgium’s Loi NIS2 / NIS2-wet) — immediately after purchasenn
Bulgaria has published a local law (Закон за киберсигурност) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (in English) — immediately after purchasen(free add-on) Local Cybersecurity Toolkit (in Bulgarian), compliant with Bulgaria’s Закон за киберсигурност — we have started working on it and will deliver the toolkit at no extra cost as soon as it is readynn
Croatia has published a local law (Zakon o kibernetičkoj sigurnosti NN 14/2024) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (English and Croatian version, compliant with both NIS 2 and Croatia’s Zakon o kibernetičkoj sigurnosti) — immediately after purchasenn
Cyprus has published a local law (Ασφάλειας Δικτύων και Συστημάτων Πληροφοριών Νόμοι του 2020 και 2025) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (English and Greek version, compliant with both NIS 2 and Cypriot Ασφάλειας Δικτύων και Συστημάτων Πληροφοριών Νόμοι του 2020 και 2025) — immediately after purchasenn
Czechia has published a local law (Zákon o kybernetické bezpečnosti) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (English and Czech version, compliant with both NIS 2 and Czechia's Zákon o kybernetické bezpečnosti) — immediately after purchasenn
Denmark has published a local law (Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau (NIS 2-loven)) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (English and Danish version, compliant with both NIS 2 Directive and Denmark’s NIS 2-loven) — immediately after purchase.nn
Estonia has published a local law (Küberturvalisuse seadus (KüTS)) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (in English) — immediately after purchasen(free add-on) Local Cybersecurity Toolkit (in Estonian), compliant with Estonia’s Küberturvalisuse seadus (KüTS) — we have started working on it and will deliver the toolkit at no extra cost as soon as it is readynn
Finland has published a local law (Kyberturvallisuuslaki tulemaan voimaan 8 päivänä huhtikuuta 2025) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (English and Finnish version compliant with both NIS 2 Directive and Finland's Kyberturvallisuuslaki) — immediately after purchasenn
France has not yet published local laws and regulations based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (in English) — immediately after purchasen(free add-on) Local cybersecurity toolkit (in French) — delivered at no extra cost as soon as the localized toolkit is ready, once France publishes the local laws and regulationsnn
Germany has published a local law (Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung) based on NIS 2 — you will receive:nnNIS2 Documentation Toolkit (English and German version, compliant with both NIS 2 and Germany’s Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung) — immediately after purchasenn
Greece has published a local law (NOMOΣ ΥΠ’ ΑΡΙΘΜ. 5160/2024) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (English and Greek version, compliant with both NIS 2 Directive and Greece’s NOMOΣ ΥΠ’ ΑΡΙΘΜ. 5160/2024) — immediately after purchasenn
Hungary has published a local law (2024. évi LXIX. törvény Magyarország kiberbiztonságáról (Kiberbiztonsági törvény) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (English and Hungarian version, compliant with both NIS 2 Directive and Hungary’s 2024. évi LXIX. törvény) — immediately after purchasenn
Ireland has not yet published local laws and regulations based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (in English) — immediately after purchasen(free add-on) Local cybersecurity toolkit (in English) — delivered at no extra cost as soon as the localized toolkit is ready, once Ireland publishes the local laws and regulationsnn
Italy has published a local law (Decreto legislativo, n. 138, di recepimento nell’ordinamento italiano della direttiva 2022/2555. Notifica provvediemento di attuazione.) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (English and Italian version, compliant with both NIS 2 and Italy’s Decreto NIS 2) — immediately after purchase.nn
Latvia has published a local law (Nacionālās kiberdrošības likums OP 2024/128A.1) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (English and Latvian version, compliant with both NIS2 Directive and Latvia’s Nacionālās kiberdrošības likums) — immediately after purchase.nn
Lithuania has updated a local law (Kibernetinio saugumo įstatymas) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (English and Lithuanian version, compliant with both NIS 2 Directive and Lithuania’s Kibernetinio saugumo įstatymas) — immediately after purchase.nn
Luxembourg has published a local law (Loi du 5 mai 2026 concernant des mesures destinées) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (in English) — immediately after purchasen(free add-on) Local Cybersecurity Toolkit (in French), compliant with Luxembourg’s Loi du 5 mai 2026 concernant des mesures destinées — we have started working on it and will deliver the toolkit at no extra cost as soon as it is readynn
Malta has published a local law (Legal Notice 71 of 2025 – Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, 2025) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (English, compliant with both NIS2 Directive and Malta’s NIS2 Order) — immediately after purchasenn
Netherlands has not yet published local laws and regulations based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (in English) — immediately after purchasen(free add-on) Local cybersecurity toolkit (in Dutch) — delivered at no extra cost as soon as the localized toolkit is ready, once Netherlands publishes the local laws and regulationsnn
Poland has published a local law (Ustawa o krajowym systemie cyberbezpieczeństwa) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (in English) — immediately after purchasen(free add-on) Local Cybersecurity Toolkit (in Polish), compliant with Poland’s Ustawa o krajowym systemie cyberbezpieczeństwa — we have started working on it and will deliver the toolkit at no extra cost as soon as it is readynn
Portugal has published a local law (Decreto-Lei n.º 125/2025, que aprova o Regime Jurídico da Cibersegurança e transpõe a Diretiva (UE) 2022/2555) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit — (English and Portuguese versions, compliant with both NIS 2 and Portugal’s Decreto NIS 2 — immediately after purchasenn
Romania has published a local law (Ordonanța de Urgență nr. 155/2024) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (English and Romanian version, compliant with both NIS 2 Directive and Romania’s Ordonanța de Urgență nr. 155/2024) — immediately after purchasenn
Slovakia has published a local law (Zákon o kybernetickej bezpečnosti) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (in English) — immediately after purchasen(free add-on) Local Cybersecurity Toolkit (in Slovak), compliant with Slovakia’s Zákon o kybernetickej bezpečnosti — we have started working on it and will deliver the toolkit at no extra cost as soon as it is readynn
Slovenia has published a local law (Zakon o informacijski varnosti (ZInfV-1)) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (English and Slovenian version, compliant with both NIS 2 Directive and Slovenian Zakon o informacijski varnosti (ZInfV-1)) — immediately after purchasenn
Spain has not yet published local laws and regulations based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (in English) — immediately after purchasen(free add-on) Local cybersecurity toolkit (in Spanish) — delivered at no extra cost as soon as the localized toolkit is ready, once Spain publishes the local laws and regulationsnn
Sweden has published a local law (Cybersäkerhetslag (2025:1506)) based on NIS 2 — you will receive:nnNIS 2 Documentation Toolkit (English and Swedish version, compliant with both NIS 2 Directive and Swedish Cybersäkerhetslag (2025:1506)) — immediately after purchasenn
Please select the country for Local cybersecurity toolkit to proceed with checkout
AES-256bit SSL safe
Toolkit Documents
-
-
Project Launch Decision
-
Project Plan
-
Initial Training Plan
-
Policy on Information System Security
-
-
-
Risk Assessment Methodology
-
Risk Assessment Table
-
Risk Treatment Table
-
Acceptance of Residual Risks
-
Risk Assessment and Treatment Report
-
Risk Treatment Plan
-
-
-
IT Security Policy
-
Clear Desk and Clear Screen Policy
-
Mobile Device and Remote Work Policy
-
Bring Your Own Device (BYOD) Policy
-
Physical Security Policy
-
Information Classification Policy
-
Asset Management Procedure
-
IT Asset Register
-
Security Procedures for IT Department
-
Network Security Policy
-
Vulnerability and Patch Management Procedure
-
Logging and Monitoring Procedure
-
ICT Change Management Procedure
-
Backup Policy
-
Information Transfer Policy
-
Secure Communication Policy
-
Disposal and Destruction Policy
-
Policy on Encryption and Cryptographic Controls
-
Access Control Policy
-
Authentication Policy
-
Password Policy
-
Policy for the Acquisition, Development, and Maintenance of ICT Systems
-
Specification of Acquisition, Development, and Maintenance Requirements of ICT System
-
Security Policy for Human Resources
-
Statement of Acceptance of Cybersecurity Documents
-
Supplier Security Policy
-
Security Clauses for Suppliers and Partners
-
Confidentiality Statement
-
Directory of Suppliers and Service Providers
-
-
-
Business Impact Analysis Methodology
-
Business Impact Analysis Questionnaire
-
Business Continuity Strategy
-
Recovery Time Objectives for Activities
-
Examples of Disruptive Incident Scenarios
-
Preparation Plan for Business Continuity
-
Activity Recovery Strategy for (activity name)
-
Crisis Management Plan
-
Business Continuity Plan
-
Disruptive Incident Response Plan
-
List of Business Continuity Sites
-
Transportation Plan
-
Key Contacts
-
Disaster Recovery Plan
-
Activity Recovery Plan for (activity name)
-
Exercising and Testing Plan
-
Exercising and Testing Report
-
-
-
Incident Handling Policy
-
Minor Incident Response Procedure
-
Incident Log
-
Post Incident Review Form
-
Significant Incident Notification for Recipients of Services
-
Significant Incident Early Warning
-
Significant Incident Notification
-
Significant Incident Intermediate Report
-
Significant Incident Final Report
-
Significant Incident Progress Report
-
-
-
Measurement Methodology
-
Measurement Report
-
Training and Awareness Plan
-
Internal Audit Procedure
-
Internal Audit Program
-
Internal Audit Report
-
Internal Audit Checklist
-
Procedure for Management Review
-
Management Review Minutes
-
Procedure for Corrective Actions
-
Corrective Action Form
-
Adapted for Local Cybersecurity Laws
According to the NIS2 Directive, each EU country must transpose the directive by publishing national legislation with specific cybersecurity requirements. To help you stay compliant, we’ve developed localized versions of our NIS2 Documentation Toolkit — tailored to local laws and regulations, translated into your language, and ready to use.nDon’t see your country listed? Contact us — we may already be working on a localized version for your region.n