Template Library
49 templates, sorted by NIS2 chapter
Request starting points for policies, registers and incident forms, then adapt scope, roles and approvals to your organisation.
- Templates
- 49
- Articles
- 10
- Readiness check
- 1
1 templates
Basics & Compliance
Basic information about the NIS2 directive, who is affected, deadlines, and legal requirements.
Classification Documentation
Records whether your organisation counts as important or particularly important and which figures that classification rests on. Without it, neither the registration nor the extent of your duties can be justified.
Chapter 1.2Formats DOCX
5 templates
Risk Management
Risk analysis, risk assessment, and treatment plans according to NIS2 requirements.
Asset Inventory
Captures the systems, data and services that need protecting in the first place, with the people responsible and the protection requirement. Every risk assessment and every BIA builds on it.
Chapter 2.1Formats XLSX
Risk Management
Carries risks from identification through assessment to treatment, with named owners and dates. Section 30 BSIG asks for an all-hazards approach rather than a plain list.
Chapter 2.2 + 2.3Formats XLSX
Gap Assessment
Compares the current state against the ten minimum measures and shows, requirement by requirement, what is missing. The assessment is produced in this worksheet and summarised in the report next to it.
Chapter 2.4Formats XLSX
Gap Assessment Report
Turns the worksheet results into a report with findings, priorities and an action plan. It addresses the specialist level; the short version for the management body sits next to it.
Chapter 2.4Formats DOCX
Gap report for the management body
Condenses the same findings to what the management body has to decide: residual risk, budget, dates. It has to approve the measures under Section 38 BSIG and needs a document it can actually read.
Chapter 2.4.3Formats DOCX
4 templates
Technical Security
Network security, access control, encryption, and patch management.
Role-Based Access Control Matrix
Maps roles to the permissions they actually need and makes over-entitlement visible. The recertification required by the access control policy in chapter 5.2.2 runs on it.
Chapter 3.1Formats XLSX
Certificate & Key Register
Tracks certificates and keys with validity, owner and expiry date. An expired certificate takes a service down just as effectively as an attack does.
Chapter 3.2Formats XLSX
Vulnerability Register
Collects reported and discovered vulnerabilities with criticality, deadline and remediation status. The patch management policy sets the deadlines; this register evidences that they are met.
Chapter 3.3.3Formats XLSX
Network Security
Documents segmentation, transitions and rules of the network in a reviewable overview. Assessors ask for it as soon as the separation of critical areas comes up.
Chapter 3.4Formats XLSX
6 templates
Incident Response
Incident handling, reporting obligations, and crisis management under NIS2.
Incident Register
Logs every security incident with the time of becoming aware, the classification and the reporting status. That time is what starts the 24-hour deadline under Section 32 BSIG.
Chapter 4.1Formats XLSX
Notification Process Policy
Defines who assesses an incident, who reports it and who is reachable outside office hours. The 24-hour deadline runs at weekends too.
Chapter 4.2Formats DOCX
Final Incident Report Form
Covers the third step, the final report one month after the full notification, with cause, severity and the measures taken.
Chapter 4.2.2Formats DOCX
Early Warning Report Form
Covers the first step of the reporting cascade, due at the BSI within 24 hours of becoming aware.
Chapter 4.2.2Formats DOCX
Full Incident Report Form
Covers the second step, due within 72 hours, which adds cause, impact and countermeasures to the initial assessment.
Chapter 4.2.2Formats DOCX
Incident Response Drills
Plans and records incident response drills with findings and follow-up. A reporting process that has never been rehearsed rarely survives its first real deadline.
Chapter 4.3.1Formats XLSX
16 templates
Governance & Accountability
Management accountability, policies, and documentation requirements.
Security Officer Appointment
Appoints the security officer in writing, with duties, authority and the reporting line to the management body. Assessors regularly ask for this document.
Chapter 5.1.1Formats DOCX
Policy Review Calendar
Schedules the periodic review of every policy with the person responsible and the due date. It is how you show that the policy set is maintained rather than written once.
Chapter 5.2Formats XLSX
Information Security Charter
In the charter, the management body sets objectives, scope and binding force for information security. Every policy below it builds on that.
Chapter 5.2.1Formats DOCX
Information Security Policy Template
This policy works out the roles, rules and references to the individual policies beneath the charter. It suits organisations that want to start with a single document.
Chapter 5.2.1Formats DOCX
Backup Recovery Policy
Sets out backup procedures, retention and restoration, including who may trigger a restore. Section 30 BSIG names backup management explicitly.
Chapter 5.2.2Formats DOCX
Incident Response Policy
Defines how an incident is detected, classified, escalated and closed, and who owns the notification to the BSI.
Chapter 5.2.2Formats DOCX
Cryptography Policy
Governs the algorithms in use, key lengths and key handling across the lifecycle. The certificate and key register in chapter 3.2 carries the operational side of it.
Chapter 5.2.2Formats DOCX
Supplier Security Policy
Describes the security requirements suppliers have to meet and how that is verified. Sets the frame for the questionnaire and contract clauses in chapter 6.
Chapter 5.2.2Formats DOCX
Patch Management Policy
Sets deadlines for security updates by criticality, plus exceptions and who approves them. Works together with the vulnerability register in chapter 3.3.3.
Chapter 5.2.2Formats DOCX
Access Control Policy
Governs granting, changing and withdrawing access rights, including periodic recertification. Implemented through the role and rights matrix in chapter 3.1.
Chapter 5.2.2Formats DOCX
Employee Signature List
Evidences that staff have acknowledged the applicable policies, with date and version. Without it, a policy is an assertion in an audit.
Chapter 5.2.4Formats DOCX
Liability Documentation
Records which decision was taken and approved by whom and when. You fall back on it when the personal responsibility of the management body is examined.
Chapter 5.3Formats XLSX
Management resolution on NIS2 implementation
With this resolution the management body orders implementation, assigns budget and names those responsible. Section 38 BSIG makes that approval a personal duty.
Chapter 5.3.1Formats DOCX
Training record for the management body
Documents the mandatory training of the management body itself, with content, date and participants.
Chapter 5.3.2Formats DOCX
Management Review Minutes
Minutes the management review with inputs, decisions and actions. It is how you show each year that the management system is steered and not merely run.
Chapter 5.4Formats DOCX
Security KPI Dashboard
Collects the metrics that feed the management review, such as open actions, incidents and patch status. That turns status reports into a trend.
Chapter 5.4Formats XLSX
5 templates
Supply Chain Security
Vendor management and supply chain security.
Supplier Inventory
Captures suppliers and service providers with the service, criticality and contacts. Without this inventory the supply chain duties under Section 30 BSIG cannot be evidenced.
Chapter 6.1Formats XLSX
Supplier Security Questionnaire
Asks suppliers about their security posture, scaled to how critical they are. The completed questionnaire is the evidence that you checked rather than trusted.
Chapter 6.2Formats XLSX
Supplier Assessment Register
Consolidates the questionnaire results and tracks conditions and review dates. Individual answers become a maintained picture across all suppliers.
Chapter 6.2Formats XLSX
Contract Clause Monitoring
Tracks which contract carries which security clauses and when it comes up for renegotiation. A clause only takes effect once it is in the actual contract.
Chapter 6.3Formats XLSX
Supplier Contract Clauses
Provides wording for security requirements, notification duties and audit rights to be taken into supplier contracts. It belongs in a legal review before use.
Chapter 6.3Formats DOCX
5 templates
Business Continuity
Business continuity management, disaster recovery, and backup procedures.
Business Impact Analysis (BIA)
Determines per business process how long an outage is tolerable and derives RTO and RPO from that. Those figures decide which recovery strategy is even an option.
Chapter 7.1Formats XLSX
IT Disaster Recovery Handbook
Sets out the recovery sequence, responsibilities and immediate actions for an IT emergency. It has to be reachable even when the systems it describes are down.
Chapter 7.2Formats XLSX
Crisis Communication Plan
Defines who informs whom in a crisis, through which channel and with whose approval. It covers customers, supervisory authorities and the press, not only your own staff.
Chapter 7.2Formats XLSX
Restore Test Log & Schedule
Schedules restore tests and records each result with duration and deviations. A backup only counts as a backup once a restore has demonstrably worked.
Chapter 7.3Formats XLSX
BCM Exercise Pack
Bundles scenarios, run sheet and evaluation for continuity exercises, including findings. Those findings belong in risk management afterwards, otherwise the exercise stays without consequence.
Chapter 7.4Formats XLSX
7 templates
Training & Awareness
Employee training and security awareness programs.
Training Record
Tracks across all people and dates who completed which training and when. This is the view an assessor asks for, not the individual attendance sheet.
Chapter 8.1Formats XLSX
Training Plan & Audience Matrix
Sets out in advance which audience receives which training at which interval. The records are later checked against this plan.
Chapter 8.1Formats XLSX
Training Attendance Log
Documents a single training session with date, content and participant signatures. The training record is fed from this raw log.
Chapter 8.2Formats DOCX
Phishing Simulation Tracker
Tracks runs, click rates and reporting rates of phishing simulations over time. The reporting rate says more about awareness than the click rate does.
Chapter 8.3Formats XLSX
Training Documentation
Documents a single awareness measure or campaign with content, reach and effect. It complements the training record with everything that is not a classic training session.
Chapter 8.3Formats XLSX
Annual Awareness Programme
Distributes training, simulations and campaigns across the year and assigns responsibility. It turns single measures into a programme the management body can approve.
Chapter 8.4Formats XLSX
Reporting Channel Register
Lists the routes staff can use to report anomalies, with availability and responsibility. A reporting channel nobody knows about lengthens the time until you become aware.
Chapter 8.4Formats XLSX
We send the download link by email.
Scope settled, what now?
Once the classification stands, the work starts: ten measures under Section 30 BSIG, reporting routes, the supply chain and the evidence the BSI expects. We go through your case and tell you what is still open.