Free Download

Free — Editable XLSX — No Payment

One Spreadsheet. Four EU Frameworks. See What You’ve Already Covered — and What’s Actually Missing.

The EU Cybersecurity Framework Control Crosswalk maps NIS2 Article 21 × ISO/IEC 27001:2022 Annex A × DORA × CRA across 14 security domains — with overlap notes on what transfers between frameworks, a colour-coded coverage tracker, and a reporting-deadlines sheet that keeps the 24-hour and 72-hour clocks straight.

  • Exact article and control anchors in every cell — Art. 21(2)(a)–(j), Annex A controls, DORA and CRA articles
  • “Your Coverage” dropdown per domain: Covered / Partial / Not Covered — it doubles as your first gap scan
  • Reporting-deadlines sheet: NIS2, DORA, CRA (obligations start 11 September 2026), ISO 27001 and GDPR side by side

Get the crosswalk by email

Sent instantly. One XLSX, three sheets, no payment details.

✓ Check your inbox — the crosswalk is on its way.

Something went wrong. Please try again, or email info@nis-2-templates.com.

  • Editable XLSX — a working file, not a locked PDF
  • From the publisher of the NIS2 & ISO 27001 template libraries on this site
  • One-click unsubscribe. No sales calls.

The Same Control, Documented Four Times

If NIS2 applies to your organisation, there’s a good chance at least one more framework does too — ISO 27001 because a customer or RFP demands it, DORA (the Digital Operational Resilience Act) because you serve financial entities, CRA (the Cyber Resilience Act) because you ship products with digital elements. Each one arrives with its own vocabulary, its own article numbers, and its own auditors.

Here’s what that turns into in practice: your team re-documents access control, incident handling, and supplier security from scratch for every framework — because nobody can point to a single sheet showing that the control you built for NIS2 Article 21(2)(i) is substantially the same one ISO 27001 calls A.5.15–A.5.18. And when the board asks “are we covered for DORA?”, the honest answer becomes a research project instead of a look-up.

A control you already run shouldn’t cost you four rounds of paperwork. The overlap between these frameworks is real and substantial — but it only saves you time if it’s written down.

What’s Inside — Real Rows, Not a Teaser

Sheet 1 maps all 14 security domains. Here are four of them, exactly as they appear in the file:

Sample — 4 of 14 domains
Security DomainNIS2ISO/IEC 27001:2022DORACRAYour Coverage
Incident handlingArt. 21(2)(b)A.5.24–A.5.28; A.6.8Art. 17, 18Art. 14; Annex I Part IICovered
Incident reporting to authoritiesArt. 23No equivalentArt. 19Art. 14 (via single reporting platform)Partial
Supply chain / third-party riskArt. 21(2)(d), Art. 22A.5.19–A.5.23Art. 28–30Art. 13Partial
MFA & secure authenticationArt. 21(2)(j)A.8.5, A.5.17Art. 9Annex I Part INot Covered

Sheet 1 — The Crosswalk

14 domains × 4 frameworks with exact article and control anchors, an overlap-notes column explaining what genuinely transfers (and what doesn’t), and a colour-coded Covered / Partial / Not Covered dropdown per row.

Sheet 2 — Reporting Deadlines

The statutory clocks side by side: NIS2’s 24 h early warning / 72 h notification / 1-month final report, DORA’s Article 19 regime, CRA’s obligations from 11 September 2026, ISO 27001, and GDPR for context.

Sheet 3 — How to Use It

A short, practical guide: how to run the coverage scan, how to scope the crosswalk per framework, and where each framework’s detail lives beyond the map.

Get the Free Crosswalk

Delivered by email in about two minutes. No payment details, ever.

Built for Three Situations

You’re NIS2-compliant — and ISO 27001 just came up

A customer, RFP, or insurer is asking about certification. The crosswalk shows which of your existing NIS2 controls already map to Annex A before you spend anything on the gap.

You’re ISO-certified — and NIS2 pulled you in

Your ISMS covers most of Article 21 already. The map shows where the statutory extras sit — reporting clocks, registration, board accountability — so you extend instead of rebuilding.

You’re juggling DORA or CRA on top

Financial-sector entities and product manufacturers get the same view for their frameworks — including where CRA regulates the product rather than the organisation.

When You Need the Documents, Not Just the Map

ISO 27001:2022 Documentation Toolkit

71 ISMS templates (58 Word + 13 Excel) plus 10 implementation guides: a Statement of Applicability pre-loaded with all 93 Annex A controls, an ISO 27005-aligned risk methodology, the internal audit pack, and the full policy corpus. Ships with the NIS2↔ISO 27001 Delta/Mapping Pack as a free bonus.

“I’ve just purchased the Complete Toolkit. It provides detailed policy and procedure templates as well as detailed NIS2 compliance implementation guides. Believe this will be a very useful tool for us.”

Enda Macken — Data and Systems Manager, Dromone Engineering Limited (Ireland), on this site’s NIS2 Complete Toolkit — the same documentation system behind the ISO toolkit
€397

One-time · instant download · 30-day update-or-add pledge

See the Toolkit →

Questions, Answered Straight

Is it really free?

Yes. You get the XLSX by email immediately, plus occasional EU compliance updates from us. Every email has a one-click unsubscribe, and we never ask for payment details.

What format is it — and can I edit it?

A single .xlsx file with three sheets (Crosswalk, Reporting Deadlines, How to Use). Fully editable — the coverage column is a dropdown you fill in as your own first-pass gap scan.

Is this an official compliance mapping I can hand to an auditor?

It’s a working mapping aid built from the framework texts — NIS2 (EU) 2022/2555, ISO/IEC 27001:2022, DORA (EU) 2022/2554 and CRA (EU) 2024/2847 — not a legal opinion or a certification artifact. It tells you where to look and what transfers; your documented controls are what an auditor assesses.

We only care about two of the four frameworks. Still useful?

Yes — hide the columns you don’t need. Most users start with exactly one pair (usually NIS2 × ISO 27001) and keep the rest for the day a customer or regulator adds a third.

Who publishes this?

ZILIO Marzena Rewers (EU VAT PL6451705993), the publisher behind nis-2-templates.com — the NIS2 and ISO 27001 template libraries and 350+ published compliance guides. Real company, real address, contact at info@nis-2-templates.com.