One procedure per process — not four documents on the same subject. Every procedure opens with a coverage table stating which obligation it satisfies and whether that obligation comes from the Directive, the Implementing Regulation or your national law.
Written on the European layer and usable in any Member State: everything that varies by country lives in one document, the National Annex, which you complete once.
Complete and Enterprise contain the same procedures and forms; Enterprise adds the Board Pack, the Gap Assessment Tool and a licence that covers a group and consultancy use. Starter is a subset, and says exactly which measures it leaves out.
Covers the obligations with the tightest deadlines. Not full Article 21 coverage — the kit says so, in writing.
The full picture. Every obligation mapped to the step, the role and the record that discharges it.
Use across your group without limit, and in delivering services to your own clients.
Every in-scope entity must address all ten measures of Article 21(2). Starter covers five of them and ships with a written statement saying so — presenting it as full coverage would not survive a supervisory check.
| Reference | Obligation | Starter | Complete | Enterprise |
|---|---|---|---|---|
| Art. 20 | Governance and management body accountability | ✓ | ✓ | ✓ |
| Art. 21(2)(a) | Risk analysis and information security policies | ✓ | ✓ | ✓ |
| Art. 21(2)(b) | Incident handling | ✓ | ✓ | ✓ |
| Art. 21(2)(c) | Business continuity, backup, crisis management | ✓ | ✓ | ✓ |
| Art. 21(2)(d) | Supply chain security | — | ✓ | ✓ |
| Art. 21(2)(e) | Acquisition, development and maintenance; vulnerabilities | — | ✓ | ✓ |
| Art. 21(2)(f) | Assessing the effectiveness of measures | ✓ | ✓ | ✓ |
| Art. 21(2)(g) | Basic cyber hygiene and training | ✓ | ✓ | ✓ |
| Art. 21(2)(h) | Cryptography and encryption | — | ✓ | ✓ |
| Art. 21(2)(i) | HR security, access control, asset management | — | ✓ | ✓ |
| Art. 21(2)(j) | Multi-factor authentication, secure communications | — | ✓ | ✓ |
| Art. 23 | Significant incident reporting — 24h / 72h / 1 month | ✓ | ✓ | ✓ |
Entities in the digital infrastructure and digital provider sectors are also subject to Commission Implementing Regulation (EU) 2024/2690, which applies directly and identically across the Union. Complete and Enterprise map to all thirteen sections of its Annex and carry its entity-specific incident thresholds.
Each process has exactly one procedure covering every aspect of it. Business continuity is one document, not seventeen. Forms exist only where a record is required, and everything continuous lives in the workbook.
Impact analysis, recovery objectives, backup, disaster recovery, crisis management and exercising are one document. Nobody running a crisis has time to hold seventeen files open.
Each obligation states whether it comes from the Directive, from the Implementing Regulation, or from national law. You see at a glance what applies unchanged in your country.
No procedure names an authority, a portal, a deadline or a national threshold. Those values live in a single document you complete once for your jurisdiction.
Retention periods are stated in one procedure. Indicators and targets in one. No document declares its own, so nothing drifts out of step with the rest.
Every step names one accountable role and one output record. A step with no record has not been performed — and the output column is the evidence list for internal audit.
Where a national rule is still moving, the kit says so and gives you a field for the date you last checked. The Legal register sheet exists to keep that current.
One-time payment, twelve months of updates. Editable DOCX and XLSX, ready to tailor.
Documentation templates, not legal advice and not certification. NIS-2 is implemented through national law that varies by Member State; confirm your obligations against the legislation and the competent authority that apply to you.