Compliance documentation aligned with the NIS2 Directive. Documents logically interconnected, ready to be completed by the organization.
[...] is an instruction or example – replace it with the organisation's actual content.Security policy, risk management and risk register – the foundation of the entire ISMS.
Main ISMS document. Objectives, scope, roles, principles. Linked to all other documents.
Methodology for assessing and treating cybersecurity risks. Required under Art. 21 NIS2.
Register template with risk acceptance criteria and likelihood/impact matrix.
RACI matrix for all security functions. NIS2 requirement for a designated cybersecurity responsible person.
Procedures for detecting, handling and reporting cybersecurity incidents – a key NIS2 requirement.
Definitions, P1–P4 classification, significance thresholds, reporting obligations to CSIRT (24h/72h).
Timeline, forms A–D, step-by-step instructions, reporting to CSIRT and DPA.
Playbooks PB-001–004 (ransomware, account, leak, DDoS), PICERL, crisis communications.
Technical policies on identity, passwords, encryption and information classification.
Access principles, MFA, access reviews, privileged access, passwords (min. 8 characters).
Algorithms, key lengths, certificate management, encryption of data at rest and in transit.
Classification levels, labelling, media handling, personal data (GDPR).
Business continuity, disaster recovery, change management and vulnerability management.
RTO/RPO, emergency procedures, tests, crisis communications.
Schedule, retention, recovery tests, backup isolation.
CAB, change classification, testing, rollback, maintenance windows.
Scanning, CVSS, patching SLA (critical 72h), penetration tests.
Supplier security, personnel security and training programme – required under Art. 21 NIS2.
Supplier risk assessment, contractual requirements, monitoring, supply chain audits.
Employee screening, NDA agreements, offboarding, penalties for violations.
Training plans, phishing awareness, mandatory certifications, register.
Physical security, networks, asset register and compliance audit.
Security zones, entry control, server rooms, CCTV, clean desk.
Segmentation, DMZ, firewall, monitoring, SOC, logs (min. 12 months).
Asset classification, owners, value, critical dependencies.
Audit plan, reporting to board, security KPIs, statement of applicability.
| Regulation | Key documentation requirements | Related documents |
|---|---|---|
| NIS2 Directive (EU 2022/2555) | Art. 21 – risk management measures, policies, continuity, supply chain, MFA, encryption, training | DOC-001, 002, 011, 015, 008, 009, 017 |
| GDPR (EU 2016/679) | Technical and organisational measures, personal data protection, data breaches | DOC-010, 005, 016 |
| ISO/IEC 27001:2022 | Reference ISMS standard – Annex A forms the control baseline | All documents |