Information Security Management System

Compliance documentation aligned with the NIS2 Directive. Documents logically interconnected, ready to be completed by the organization.

Project version: 1.0 | Date: ▸ enter approval date | Owner: ▸ organisation name
© 2026 Tomasz Zysko / CrazyRat  ·  Commercial documentation protected by copyright  ·  All rights reserved  ·  Reproduction or distribution without the author's written consent is prohibited

Colour Legend – fields to be completed by the organisation

Yellow field – organisation enters its own value (no constraints)
Orange field – value with constraint min/max shown alongside
Blue field – cross-reference or date
Red field – critical field, absolutely required by NIS2
ℹ️
Fields marked with indicate a place to fill in. Text in square brackets [...] is an instruction or example – replace it with the organisation's actual content.
21
Documents total
6
Phases
21
Ready
100%
Completeness

PHASE 1 Foundation Documents ✓ Ready

Security policy, risk management and risk register – the foundation of the entire ISMS.

PHASE 2 Incident Management ✓ Ready

Procedures for detecting, handling and reporting cybersecurity incidents – a key NIS2 requirement.

PHASE 3 Access Control, Cryptography and Data ✓ Ready

Technical policies on identity, passwords, encryption and information classification.

PHASE 4 Continuity, Backup and Operations ✓ Ready

Business continuity, disaster recovery, change management and vulnerability management.

PHASE 5 Supply Chain and Human Resources ✓ Ready

Supplier security, personnel security and training programme – required under Art. 21 NIS2.

PHASE 6 Physical, Network and Assets ✓ Ready

Physical security, networks, asset register and compliance audit.

Legal Basis

RegulationKey documentation requirementsRelated documents
NIS2 Directive
(EU 2022/2555)
Art. 21 – risk management measures, policies, continuity, supply chain, MFA, encryption, trainingDOC-001, 002, 011, 015, 008, 009, 017
GDPR
(EU 2016/679)
Technical and organisational measures, personal data protection, data breachesDOC-010, 005, 016
ISO/IEC 27001:2022Reference ISMS standard – Annex A forms the control baselineAll documents