Skip to content

Template Library

49 templates, sorted by NIS2 chapter

Request starting points for policies, registers and incident forms, then adapt scope, roles and approvals to your organisation.

Templates
49
Articles
10
Readiness check
1

1 templates

Basics & Compliance

Basic information about the NIS2 directive, who is affected, deadlines, and legal requirements.

  • Classification Documentation

    Records whether your organisation counts as important or particularly important and which figures that classification rests on. Without it, neither the registration nor the extent of your duties can be justified.

    Chapter 1.2Formats DOCX

5 templates

Risk Management

Risk analysis, risk assessment, and treatment plans according to NIS2 requirements.

  • Asset Inventory

    Captures the systems, data and services that need protecting in the first place, with the people responsible and the protection requirement. Every risk assessment and every BIA builds on it.

    Chapter 2.1Formats XLSX

  • Risk Management

    Carries risks from identification through assessment to treatment, with named owners and dates. Section 30 BSIG asks for an all-hazards approach rather than a plain list.

    Chapter 2.2 + 2.3Formats XLSX

  • Gap Assessment

    Compares the current state against the ten minimum measures and shows, requirement by requirement, what is missing. The assessment is produced in this worksheet and summarised in the report next to it.

    Chapter 2.4Formats XLSX

  • Gap Assessment Report

    Turns the worksheet results into a report with findings, priorities and an action plan. It addresses the specialist level; the short version for the management body sits next to it.

    Chapter 2.4Formats DOCX

  • Gap report for the management body

    Condenses the same findings to what the management body has to decide: residual risk, budget, dates. It has to approve the measures under Section 38 BSIG and needs a document it can actually read.

    Chapter 2.4.3Formats DOCX

4 templates

Technical Security

Network security, access control, encryption, and patch management.

  • Role-Based Access Control Matrix

    Maps roles to the permissions they actually need and makes over-entitlement visible. The recertification required by the access control policy in chapter 5.2.2 runs on it.

    Chapter 3.1Formats XLSX

  • Certificate & Key Register

    Tracks certificates and keys with validity, owner and expiry date. An expired certificate takes a service down just as effectively as an attack does.

    Chapter 3.2Formats XLSX

  • Vulnerability Register

    Collects reported and discovered vulnerabilities with criticality, deadline and remediation status. The patch management policy sets the deadlines; this register evidences that they are met.

    Chapter 3.3.3Formats XLSX

  • Network Security

    Documents segmentation, transitions and rules of the network in a reviewable overview. Assessors ask for it as soon as the separation of critical areas comes up.

    Chapter 3.4Formats XLSX

6 templates

Incident Response

Incident handling, reporting obligations, and crisis management under NIS2.

  • Incident Register

    Logs every security incident with the time of becoming aware, the classification and the reporting status. That time is what starts the 24-hour deadline under Section 32 BSIG.

    Chapter 4.1Formats XLSX

  • Notification Process Policy

    Defines who assesses an incident, who reports it and who is reachable outside office hours. The 24-hour deadline runs at weekends too.

    Chapter 4.2Formats DOCX

  • Final Incident Report Form

    Covers the third step, the final report one month after the full notification, with cause, severity and the measures taken.

    Chapter 4.2.2Formats DOCX

  • Early Warning Report Form

    Covers the first step of the reporting cascade, due at the BSI within 24 hours of becoming aware.

    Chapter 4.2.2Formats DOCX

  • Full Incident Report Form

    Covers the second step, due within 72 hours, which adds cause, impact and countermeasures to the initial assessment.

    Chapter 4.2.2Formats DOCX

  • Incident Response Drills

    Plans and records incident response drills with findings and follow-up. A reporting process that has never been rehearsed rarely survives its first real deadline.

    Chapter 4.3.1Formats XLSX

16 templates

Governance & Accountability

Management accountability, policies, and documentation requirements.

  • Security Officer Appointment

    Appoints the security officer in writing, with duties, authority and the reporting line to the management body. Assessors regularly ask for this document.

    Chapter 5.1.1Formats DOCX

  • Policy Review Calendar

    Schedules the periodic review of every policy with the person responsible and the due date. It is how you show that the policy set is maintained rather than written once.

    Chapter 5.2Formats XLSX

  • Information Security Charter

    In the charter, the management body sets objectives, scope and binding force for information security. Every policy below it builds on that.

    Chapter 5.2.1Formats DOCX

  • Information Security Policy Template

    This policy works out the roles, rules and references to the individual policies beneath the charter. It suits organisations that want to start with a single document.

    Chapter 5.2.1Formats DOCX

  • Backup Recovery Policy

    Sets out backup procedures, retention and restoration, including who may trigger a restore. Section 30 BSIG names backup management explicitly.

    Chapter 5.2.2Formats DOCX

  • Incident Response Policy

    Defines how an incident is detected, classified, escalated and closed, and who owns the notification to the BSI.

    Chapter 5.2.2Formats DOCX

  • Cryptography Policy

    Governs the algorithms in use, key lengths and key handling across the lifecycle. The certificate and key register in chapter 3.2 carries the operational side of it.

    Chapter 5.2.2Formats DOCX

  • Supplier Security Policy

    Describes the security requirements suppliers have to meet and how that is verified. Sets the frame for the questionnaire and contract clauses in chapter 6.

    Chapter 5.2.2Formats DOCX

  • Patch Management Policy

    Sets deadlines for security updates by criticality, plus exceptions and who approves them. Works together with the vulnerability register in chapter 3.3.3.

    Chapter 5.2.2Formats DOCX

  • Access Control Policy

    Governs granting, changing and withdrawing access rights, including periodic recertification. Implemented through the role and rights matrix in chapter 3.1.

    Chapter 5.2.2Formats DOCX

  • Employee Signature List

    Evidences that staff have acknowledged the applicable policies, with date and version. Without it, a policy is an assertion in an audit.

    Chapter 5.2.4Formats DOCX

  • Liability Documentation

    Records which decision was taken and approved by whom and when. You fall back on it when the personal responsibility of the management body is examined.

    Chapter 5.3Formats XLSX

  • Management resolution on NIS2 implementation

    With this resolution the management body orders implementation, assigns budget and names those responsible. Section 38 BSIG makes that approval a personal duty.

    Chapter 5.3.1Formats DOCX

  • Training record for the management body

    Documents the mandatory training of the management body itself, with content, date and participants.

    Chapter 5.3.2Formats DOCX

  • Management Review Minutes

    Minutes the management review with inputs, decisions and actions. It is how you show each year that the management system is steered and not merely run.

    Chapter 5.4Formats DOCX

  • Security KPI Dashboard

    Collects the metrics that feed the management review, such as open actions, incidents and patch status. That turns status reports into a trend.

    Chapter 5.4Formats XLSX

5 templates

Supply Chain Security

Vendor management and supply chain security.

  • Supplier Inventory

    Captures suppliers and service providers with the service, criticality and contacts. Without this inventory the supply chain duties under Section 30 BSIG cannot be evidenced.

    Chapter 6.1Formats XLSX

  • Supplier Security Questionnaire

    Asks suppliers about their security posture, scaled to how critical they are. The completed questionnaire is the evidence that you checked rather than trusted.

    Chapter 6.2Formats XLSX

  • Supplier Assessment Register

    Consolidates the questionnaire results and tracks conditions and review dates. Individual answers become a maintained picture across all suppliers.

    Chapter 6.2Formats XLSX

  • Contract Clause Monitoring

    Tracks which contract carries which security clauses and when it comes up for renegotiation. A clause only takes effect once it is in the actual contract.

    Chapter 6.3Formats XLSX

  • Supplier Contract Clauses

    Provides wording for security requirements, notification duties and audit rights to be taken into supplier contracts. It belongs in a legal review before use.

    Chapter 6.3Formats DOCX

5 templates

Business Continuity

Business continuity management, disaster recovery, and backup procedures.

  • Business Impact Analysis (BIA)

    Determines per business process how long an outage is tolerable and derives RTO and RPO from that. Those figures decide which recovery strategy is even an option.

    Chapter 7.1Formats XLSX

  • IT Disaster Recovery Handbook

    Sets out the recovery sequence, responsibilities and immediate actions for an IT emergency. It has to be reachable even when the systems it describes are down.

    Chapter 7.2Formats XLSX

  • Crisis Communication Plan

    Defines who informs whom in a crisis, through which channel and with whose approval. It covers customers, supervisory authorities and the press, not only your own staff.

    Chapter 7.2Formats XLSX

  • Restore Test Log & Schedule

    Schedules restore tests and records each result with duration and deviations. A backup only counts as a backup once a restore has demonstrably worked.

    Chapter 7.3Formats XLSX

  • BCM Exercise Pack

    Bundles scenarios, run sheet and evaluation for continuity exercises, including findings. Those findings belong in risk management afterwards, otherwise the exercise stays without consequence.

    Chapter 7.4Formats XLSX

7 templates

Training & Awareness

Employee training and security awareness programs.

  • Training Record

    Tracks across all people and dates who completed which training and when. This is the view an assessor asks for, not the individual attendance sheet.

    Chapter 8.1Formats XLSX

  • Training Plan & Audience Matrix

    Sets out in advance which audience receives which training at which interval. The records are later checked against this plan.

    Chapter 8.1Formats XLSX

  • Training Attendance Log

    Documents a single training session with date, content and participant signatures. The training record is fed from this raw log.

    Chapter 8.2Formats DOCX

  • Phishing Simulation Tracker

    Tracks runs, click rates and reporting rates of phishing simulations over time. The reporting rate says more about awareness than the click rate does.

    Chapter 8.3Formats XLSX

  • Training Documentation

    Documents a single awareness measure or campaign with content, reach and effect. It complements the training record with everything that is not a classic training session.

    Chapter 8.3Formats XLSX

  • Annual Awareness Programme

    Distributes training, simulations and campaigns across the year and assigns responsibility. It turns single measures into a programme the management body can approve.

    Chapter 8.4Formats XLSX

  • Reporting Channel Register

    Lists the routes staff can use to report anomalies, with availability and responsibility. A reporting channel nobody knows about lengthens the time until you become aware.

    Chapter 8.4Formats XLSX

We send the download link by email.

Scope settled, what now?

Once the classification stands, the work starts: ten measures under Section 30 BSIG, reporting routes, the supply chain and the evidence the BSI expects. We go through your case and tell you what is still open.