Docply Browse kits
Compliance Suite · Directive (EU) 2022/2555

Every NIS-2 obligation, mapped to the step that discharges it.

One procedure per process — not four documents on the same subject. Every procedure opens with a coverage table stating which obligation it satisfies and whether that obligation comes from the Directive, the Implementing Regulation or your national law.

Written on the European layer and usable in any Member State: everything that varies by country lives in one document, the National Annex, which you complete once.

Editions

Three editions, one document library.

Complete and Enterprise contain the same procedures and forms; Enterprise adds the Board Pack, the Gap Assessment Tool and a licence that covers a group and consultancy use. Starter is a subset, and says exactly which measures it leaves out.

Starter
€390
The first sixty days.
22 documents
5 of the 10 Article 21 measures
6 procedures: governance, risk, continuity, incidents, training, effectiveness
9 forms, registers workbook, glossary
National Annex for your Member State
Explicit scope and coverage statement

Covers the obligations with the tightest deadlines. Not full Article 21 coverage — the kit says so, in writing.

Most complete
Complete
€790
All ten measures.
30 documents
10 of the 10 Article 21 measures
13 procedures — one per process
13 forms, registers workbook, glossary
Mapped to the Directive, CIR 2024/2690 and ENISA guidance
Start Here — implementation sequence

The full picture. Every obligation mapped to the step, the role and the record that discharges it.

Enterprise
€1,490
For groups and consultants.
35 documents
10 of the 10 Article 21 measures
Everything in Complete
Board Pack: briefing, resolution, training syllabus, dashboard
Gap Assessment Tool — 52 questions, scored by measure
Multi-entity licence and use in consultancy

Use across your group without limit, and in delivering services to your own clients.

One-time payment · VAT included · Instant download · 12 months of updates
Coverage

What each edition covers, stated plainly.

Every in-scope entity must address all ten measures of Article 21(2). Starter covers five of them and ships with a written statement saying so — presenting it as full coverage would not survive a supervisory check.

Reference Obligation Starter Complete Enterprise
Art. 20 Governance and management body accountability
Art. 21(2)(a) Risk analysis and information security policies
Art. 21(2)(b) Incident handling
Art. 21(2)(c) Business continuity, backup, crisis management
Art. 21(2)(d) Supply chain security
Art. 21(2)(e) Acquisition, development and maintenance; vulnerabilities
Art. 21(2)(f) Assessing the effectiveness of measures
Art. 21(2)(g) Basic cyber hygiene and training
Art. 21(2)(h) Cryptography and encryption
Art. 21(2)(i) HR security, access control, asset management
Art. 21(2)(j) Multi-factor authentication, secure communications
Art. 23 Significant incident reporting — 24h / 72h / 1 month

Entities in the digital infrastructure and digital provider sectors are also subject to Commission Implementing Regulation (EU) 2024/2690, which applies directly and identically across the Union. Complete and Enterprise map to all thirteen sections of its Annex and carry its entity-specific incident thresholds.

What you get

Thirteen processes, thirteen forms, one registers workbook.

Each process has exactly one procedure covering every aspect of it. Business continuity is one document, not seventeen. Forms exist only where a record is required, and everything continuous lives in the workbook.

Governance & Scope
Art. 2, 3, 20, 21(1) · CIR §1
Risk Management
Art. 21(2)(a) · CIR §2
Asset & Information Protection
Art. 21(2)(a), (h), (i) · CIR §9, §12
Access Control & Authentication
Art. 21(2)(i), (j) · CIR §11
Network & Communications
Art. 21(2)(j) · CIR §6.5
Physical & Workplace Security
Art. 21(2)(i) · CIR §13
Secure Operations & Change
Art. 21(2)(e) · CIR §6
Logging & Retention
Art. 21(2)(b), (f) · CIR §3.4
Backup, Continuity & Crisis
Art. 21(2)(c) · CIR §4
Supply Chain Security
Art. 21(2)(d), 21(3) · CIR §5
Incidents & Notification
Art. 21(2)(b), 23 · CIR Art. 3-14
HR, Training & Cyber Hygiene
Art. 20(2), 21(2)(g) · CIR §8, §10
Effectiveness & Audit
Art. 21(2)(f) · CIR §7
Also included
Registers workbook (25 sheets)
National Annex
Glossary & framework cross-reference
Start Here — implementation sequence
Licence
How it is built

Structured the way a supervisory check reads it.

One procedure per process

Impact analysis, recovery objectives, backup, disaster recovery, crisis management and exercising are one document. Nobody running a crisis has time to hold seventeen files open.

Coverage tables with a source column

Each obligation states whether it comes from the Directive, from the Implementing Regulation, or from national law. You see at a glance what applies unchanged in your country.

One National Annex, not 27 versions

No procedure names an authority, a portal, a deadline or a national threshold. Those values live in a single document you complete once for your jurisdiction.

Single sources

Retention periods are stated in one procedure. Indicators and targets in one. No document declares its own, so nothing drifts out of step with the rest.

Evidence, not intention

Every step names one accountable role and one output record. A step with no record has not been performed — and the output column is the evidence list for internal audit.

Honest about the gaps

Where a national rule is still moving, the kit says so and gives you a field for the date you last checked. The Legal register sheet exists to keep that current.

Get the suite

From €390. Download now.

One-time payment, twelve months of updates. Editable DOCX and XLSX, ready to tailor.

Documentation templates, not legal advice and not certification. NIS-2 is implemented through national law that varies by Member State; confirm your obligations against the legislation and the competent authority that apply to you.