NIS2 Complete Toolkit
497,00 €
- 66 compliance templates (54 Word + 12 interactive Excel) + 10 guides
- Free bonus: NIS2 AI Assistant Pack — 4 AI prompts to self-audit, build your risk register & gap-check policies
- Instant download after payment
- Covers Article 21(2)(a)–(j) in full
- 1 year of updates included
- Secured by Stripe
Licence scope: covers one legal entity. For multiple companies, see the Enterprise Licence (€997) — up to 5 organisations.
30-Day Update-or-Add Pledge: if a template needs adapting to your compliance environment — or your implementation calls for a document outside the standard scope — email info@nis-2-templates.com within 30 days and we’ll update it or add it. You keep everything either way.
Digital download — once you confirm at checkout, the EU 14-day withdrawal right is waived per Directive 2011/83/EU, Art. 16(m).
Description
You’ll walk into your NIS2 audit with every Article 21 security measure already documented—not scrambling to write policies the weekend before. The Complete Toolkit hands you 66 editable compliance templates—54 Word policies and 12 Excel workbooks—each mapped to the NIS2 Directive, CIR 2024/2690 Annex, and ENISA guidance with ISO 27001:2022 cross-references built in. You also get 10 implementation guides—role matrices, flowcharts, and quick-start cards—so you know exactly how to deploy them. You fill in your company details; the regulatory mapping is done for you.
New in v1.2 — included free: the NIS2 AI Assistant Pack — 4 prompts that turn ChatGPT, Claude or Gemini into a NIS2 readiness auditor, risk-register co-pilot, policy gap-checker and incident-triage assistant (a separate download). Plus your Risk Assessment, Gap Analysis and Internal Audit spreadsheets are now interactive — auto-calculating dashboards with a 5×5 risk heat-map and maturity/conformance scoring.
CIR 2024/2690 referenced
ISO 27001:2022 cross-referenced
ENISA guidance referenced
66 templates · 54 Word + 12 Excel
€497 · instant download
Not ready to buy? Download the free NIS2 Article 21 checklist and see exactly what an auditor looks for.
The Audit Is Coming—and Your Policy Folders Are Empty
You already know the deadline passed. The NIS2 Directive had to be in national law by 17 October 2024, enforcement frameworks are live across the EU, and your national competent authority can now audit and sanction you for missing documentation. That’s the part you can’t change.
Here’s what keeps you up at night. It isn’t the directive—it’s the gap between what you’re responsible for and what you can actually produce on the day:
- You’re the one who has to produce the evidence. When the auditor asks for your risk assessment, your incident-handling policy, your board sign-off—those documents have to already exist. You can’t draft them in the meeting.
- If it goes wrong, it’s your name on it. Article 20 puts your management body personally responsible for approving and overseeing risk-management measures. “We hadn’t written it down yet” is not a position you want to defend—and the fines under Article 34 can reach €10,000,000 or 2% of worldwide annual turnover, whichever is higher.
- And you shouldn’t need a €6,000 consultant just to be compliant. Forty hours of someone billing €150 an hour to write policies that already follow a known structure—that’s a tax on not having a template, not a tax on being secure.
The villain here isn’t the regulation. It’s the blank page—every empty policy folder standing between you and an audit you can’t afford to fail, and every weekend you’d lose trying to fill them from scratch. The gap most organisations face isn’t technical. It’s documentary. And that’s a gap you can close fast.
You Don’t Have to Face the Blank Page Alone
We know what it’s like to face an audit with no documentation and a deadline that won’t move—to stare at a list of twenty-one security domains and wonder which policy proves which requirement. The Complete Toolkit was built so you never have to start from that blank page. You bring the knowledge of your own organisation; it brings the structure, the wording, and the regulatory mapping.
Every measure listed in Article 21(2)(a) through (j) is covered. Each of the 66 compliance templates follows the same 9-section structure—Purpose, Scope, Definitions, RACI matrix, Requirements, Exceptions, Monitoring, References, and Appendix—so you can hand any one of them to an auditor and they’ll know exactly where to look. You’ll find pre-filled RACI tables for six organisational roles, the fields you need to complete highlighted in red so you never miss one, and 3+ KPIs per document so your board reporting writes itself.
What’s Inside: 66 Templates + 10 Implementation Guides
You receive 66 editable compliance templates (54 Word + 12 Excel) plus 10 implementation guides, organised into 10 functional categories so you can find what the auditor asks for in seconds:
1. Management & Planning
5 docs — Welcome Guide, Implementation Guide, Project Launch Pack, Project Plan, Training Plan
2. Risk Management
7 docs — Information Security Policy, Risk Assessment Methodology, Risk Assessment Table, Risk Treatment Table, Residual Risk Acceptance, Risk Report, Risk Treatment Plan
3. Core Security Policies
23 docs — IT Security, Clear Desk, Mobile/Remote Working, BYOD, Physical Security, Information Classification, Asset Management, IT Asset Register, Network Security, Patching, Logging, Change Management, Backup, Information Transfer, Secure Communications, Disposal, Encryption, Access Control, Authentication, Password Policy, ICT Acquisition, ICT Security Requirements, HR Security + Statement of Acceptance
4. Business Continuity
9 docs — BIA Methodology, BIA Questionnaire, BC Strategy, BC Plan, Crisis Management Plan, Exercise Plan, Exercise Report, Backup Policy, Disaster Recovery Plan
5. Supply Chain
6 docs — Supplier Security Policy, Security Clauses, Confidentiality Statement, Supplier Directory, Self-Assessment Questionnaire, Compliance Checklist
6. Incident Management
5 docs — Incident Handling Policy, Minor Incident Procedure, Incident Log, Notification Forms (24h/72h/1-month per Art. 23), Corrective Actions Register
7. Measurement & KPIs
2 docs — Measurement Methodology, Measurement Report
8. Board & Governance
2 docs — Board Briefing Pack, Board Resolution Template
9. Compliance & Audit Tools
9 docs — NIS2–ISO Mapping Spreadsheet, Gap Analysis, Training Tracker, Internal Audit Checklist, CIR Compliance Matrix, GDPR–NIS2 Checklist, NCA Registration Guide, Audit Procedure, Audit Report
10. System Layer
8 docs — Master Map, Role Matrix, Quick-Start Cards (NIS2 Officer, IT Lead, HR Manager), Incident Flowchart, Implementation Flowchart, Dependency Map
See all 76 files
- 00a — Welcome & Overview
- 00b — Implementation Guide
- 00c — Master Map
- 00d — Role Matrix
- 00e — Quick-Start Card: NIS2 Officer
- 00f — Quick-Start Card: IT Lead
- 00g — Quick-Start Card: HR Manager
- 00h — Incident Flowchart
- 00i — Implementation Flowchart
- 00j — Document Dependency Map
- 01 — Project Launch Pack
- 02 — Project Plan
- 03 — Initial Training Plan
- 04 — Information Security Policy
- 05 — Risk Assessment Methodology
- 06 — Risk Assessment Table
- 07 — Risk Treatment Table
- 08 — Acceptance of Residual Risks
- 09 — Risk Assessment & Treatment Report
- 10 — Risk Treatment Plan
- 11 — IT Security Policy
- 12 — Clear Desk & Clear Screen Policy
- 13 — Mobile & Remote Working Policy
- 14 — BYOD Policy
- 15 — Physical Security Policy
- 16 — Information Classification Policy
- 17 — Asset Management Policy
- 18 — IT Asset Register
- 19 — Network Security Policy
- 20 — Vulnerability & Patch Management
- 21 — Logging & Monitoring Policy
- 22 — Change Management Policy
- 23 — Backup Policy
- 24 — Information Transfer Policy
- 25 — Secure Communications Policy
- 26 — Secure Disposal Policy
- 27 — Encryption & Cryptographic Controls
- 28 — Access Control Policy
- 29 — Authentication Policy (incl. MFA)
- 30 — Password Policy
- 31 — ICT Acquisition Policy
- 32 — ICT Security Requirements
- 33 — HR Security Policy
- 34 — Statement of Acceptance
- 35 — BIA Methodology
- 36 — BIA Questionnaire
- 37 — Business Continuity Strategy
- 38 — Business Continuity Plan
- 39 — Crisis Management Plan
- 40 — Exercise Plan
- 41 — Exercise Report
- 42 — Supplier Security Policy
- 43 — Supplier Security Clauses
- 44 — Confidentiality Statement
- 45 — Supplier Directory
- 46 — Measurement Methodology
- 47 — Measurement Report
- 48 — Incident Handling Policy
- 49 — Minor Incident Procedure
- 50 — Incident Log
- 51 — Incident Notification Forms
- 52 — Corrective Actions Register
- 53 — NIS2–ISO 27001 Mapping Spreadsheet
- 54 — Gap Analysis Workbook
- 55 — Training Tracker
- 56 — Internal Audit Checklist
- 57 — CIR 2024/2690 Compliance Matrix
- 58 — Board Briefing Pack
- 59 — Board Resolution Template
- 60 — Supplier Self-Assessment Questionnaire
- 61 — Supplier Compliance Checklist
- 62 — NCA Registration Guide
- 63 — GDPR–NIS2 Crosswalk Checklist
- 64 — Disaster Recovery Plan
- 65 — Audit Procedure
- 66 — Audit Report Template
How You Get from Empty Folders to Audit-Ready—in 3 Steps
- Download instantly. The moment your payment clears, all 76 files are yours—no waiting, no onboarding call.
- Fill in your company details. Work through the red-highlighted fields—your name, scope, roles, thresholds—using the Implementation Guide and Quick-Start Cards as your map. The structure and regulatory wording are already in place.
- Hand the audit-ready pack to your board. Walk into the audit with a complete, Article-mapped set of policies—and hand your CISO the Board Briefing Pack that proves due diligence.
How Every Article 21 Measure Is Covered
So you can prove completeness on the day, the table below maps each Article 21(2) security measure to the toolkit documents and CIR 2024/2690 Annex sections that address it.
| NIS2 Article | Security Measure | Toolkit Documents | CIR Annex |
|---|---|---|---|
| Art. 21(2)(a) | Risk analysis & information system security | Docs 04–10: Information Security Policy, Risk Assessment Methodology, Risk Assessment & Treatment Tables, Residual Risk Acceptance, Risk Report, Risk Treatment Plan | Sections 1–2 |
| Art. 21(2)(b) | Incident handling | Docs 48–52: Incident Handling Policy, Minor Incident Procedure, Incident Log, Notification Forms (24h/72h/1-month), Corrective Actions Register | Section 3 |
| Art. 21(2)(c) | Business continuity & crisis management | Docs 23, 35–41, 64: BIA Methodology & Questionnaire, BC Strategy & Plan, Crisis Management Plan, Exercise Plan & Report, Backup Policy, Disaster Recovery Plan | Section 4 |
| Art. 21(2)(d) | Supply chain security | Docs 42–45, 60–61: Supplier Security Policy, Security Clauses, Confidentiality Statement, Supplier Directory, Self-Assessment, Compliance Checklist | Section 5 |
| Art. 21(2)(e) | Acquisition, development & maintenance | Docs 20, 22, 31–32: Vulnerability & Patch Management, Change Management, ICT Acquisition, ICT Security Requirements | Section 6 |
| Art. 21(2)(f) | Effectiveness assessment | Docs 46–47, 53–57, 62–66: Measurement Methodology & Report, NIS2–ISO Mapping, Gap Analysis, Audit Checklist, CIR Compliance Matrix, Audit Procedure & Report | Section 7 |
| Art. 21(2)(g) | Cybersecurity training & awareness | Doc 03: Initial Training Plan with role-specific modules; Doc 55: Training Tracker | Section 8 |
| Art. 21(2)(h) | Cryptography & encryption | Doc 27: Encryption & Cryptographic Controls | Section 9 |
| Art. 21(2)(i) | HR security, access control & asset management | Docs 28–30, 33–34: Access Control, Authentication (MFA), Password Policy, HR Security, Statement of Acceptance; Docs 16–18: Information Classification, Asset Management, IT Asset Register | Sections 10–12 |
| Art. 21(2)(j) | Multi-factor authentication & secure communications | Docs 25, 29: Secure Communications Policy, Authentication Policy (incl. MFA requirements) | Section 11 |
Which Product Fits Where You’re Starting From
If you want full coverage across every domain, the Complete Toolkit gives you all 66 compliance templates (54 Word + 12 Excel) plus 10 implementation guides. If your work is sector-specific, the sector packs give you fully rewritten, sector-adapted versions—not subsets of this toolkit. Pick the column that matches your industry and scope.
| Document Category | Quick-Start Bundle €249 |
Complete Toolkit €497 |
Manufacturing Pack €349 |
Energy Pack €349 |
|---|---|---|---|---|
| Management & Planning | Generic | Generic | Sector-Adapted | Sector-Adapted |
| Risk Management | Generic | Generic | Sector-Adapted | Sector-Adapted |
| Core Security Policies | Generic | Generic | Sector-Adapted | Sector-Adapted |
| Business Continuity | — | Generic | Sector-Adapted | Sector-Adapted |
| Supply Chain | — | Generic | Sector-Adapted | Sector-Adapted |
| Incident Management | Generic | Generic | Sector-Adapted | Sector-Adapted |
| Measurement & KPIs | Generic | Generic | — | — |
| Board & Governance | — | Generic | — | — |
| Compliance & Audit Tools | — | Generic | — | — |
If This Is You, the Toolkit Was Built for You
You’re the CISO or NIS2 Officer. You need a documentation set that’s audit-ready from day one. You’ll present a complete Article 21 evidence package to your national competent authority—policies pre-structured, regulatory references already embedded—instead of assembling it under pressure.
You’re the IT Security Lead. You need implementation-level detail, not abstract policy statements. You’ll work from RACI tables for six roles, implementation checklists (0–4 weeks and 1–3 months), and measurable KPIs—so your team knows exactly who does what, and by when.
You’re the Compliance Manager. You need the regulatory mapping done before you start drafting. You’ll reference the applicable NIS2 Article, CIR 2024/2690 Annex section, and ENISA guidance on every template—saving yourself weeks of cross-referencing.
You’re a Board Member or CEO. You need to demonstrate Article 20 due diligence. You’ll have the Board Briefing Pack and Board Resolution template that show your management oversight is documented and active.
What one of our customers said
“I’ve just purchased the Complete Toolkit. It provides detailed policy and procedure templates as well as detailed NIS2 compliance implementation guides. Believe this will be a very useful tool for us.”
Enda Macken
Data and Systems Manager · Dromone Engineering Limited · Ireland
Dromone Engineering is an NIS2 “important entity” under Annex II (manufacturing).
Common Questions About the NIS2 Complete Toolkit
Are these templates legal advice?
No. These templates are general samples intended as a starting point for your NIS2 documentation. They do not constitute legal advice. You should have every document reviewed by a qualified professional before adoption, taking into account your sector, jurisdiction, and organisational context.
Can I customise the documents?
Yes. You receive every template as an editable DOCX or XLSX file. The fields you need to complete—company name, scope, roles, thresholds—are highlighted in red bold text so you never miss one. You can add your logo, adjust section scope, and extend any template to fit your requirements.
What format are the files?
You get DOCX (Word) and XLSX (Excel) files. They open in Microsoft Word, Google Docs, LibreOffice Writer, and any application that supports the Open XML format. You won’t need any proprietary software.
What if a document doesn’t fit my environment?
This is a digital download, so the right of withdrawal is waived at checkout in accordance with EU Directive 2011/83/EU, Article 16(m)—you’ll be asked to consent to this before payment. To protect you anyway, there’s a 30-day update-or-add pledge: if a template doesn’t fit your environment, email us within 30 days and we’ll update it—or add a document outside the standard scope. You keep everything either way.
How do I know these cover all NIS2 requirements?
Every document references the specific Article 21(2) measure it addresses, the corresponding CIR 2024/2690 Annex section, and applicable ENISA guidance. The compliance matrix above maps all ten measures to their toolkit documents, and Doc 57 (CIR Compliance Matrix) gives you a standalone crosswalk to hand to an auditor.
Are updates included?
Yes. Your purchase includes one year of updates. As EU guidance evolves—new ENISA publications, member state implementation acts, or CIR amendments—you’ll be able to download the updated templates at no additional cost during your update period.
I already have ISO 27001 — do I still need this?
Yes. While NIS2 and ISO 27001:2022 share significant overlap, the Directive imposes additional requirements that ISO alone does not cover—including incident notification timelines (Article 23), supply chain due diligence (Article 21(2)(d)), board-level governance obligations (Article 20), and specific CIR 2024/2690 technical measures. Doc 53 (NIS2–ISO 27001 Mapping Spreadsheet) shows you every gap, so you know exactly where your existing ISMS needs supplementing.
Walk Into Your Audit Confident
Picture the day differently. Instead of scrambling, you walk into the audit with a complete, Article-mapped pack in hand—every Article 21 measure documented, every CIR section referenced, your board briefing ready to forward. The auditor asks for your risk register; you have it. They ask for your incident-handling policy; you have it. You’ve closed the documentary gap, and your name is on a paper trail you can stand behind. That’s what the next step buys you.
Stripe-secured checkout
VAT handled at checkout
1 year of updates included
Want to see what an auditor checks first? Download the free NIS2 Article 21 checklist.
Disclaimer: These templates are general samples for internal use. They do not constitute legal advice and must be reviewed by a qualified professional before adoption. No document in this pack guarantees NIS2 compliance. See our full Disclaimer.




Reviews
There are no reviews yet.