Risk analysis and security policies
Policies on risk analysis and information system security.
NIS2 is not a regulation. It sets a floor, and each member state built its own law on top. What binds you is that national text — its authority, its register, its reporting channel. We track all 27, and we sell what you need to comply with yours.
Every entity in scope must implement all ten. They are the baseline the directive sets — national law may add to them, never subtract.
Policies on risk analysis and information system security.
Detection, response and recovery — feeding the article 23 reporting chain.
Backup management, disaster recovery and crisis management.
Security in relationships with direct suppliers and service providers.
Including vulnerability handling and disclosure.
Policies and procedures to assess whether the measures actually work.
Basic cyber hygiene practices and cybersecurity training.
Policies on the use of cryptography and, where appropriate, encryption.
Human resources security, access control policies and asset management.
Multi-factor authentication or continuous authentication, secured voice, video and text, and secured emergency communication systems.
Indicate whether the incident is suspected of being caused by unlawful or malicious acts, and whether it could have cross-border impact.
Update the early warning with an initial assessment, severity, impact and, where available, indicators of compromise.
Detailed description, threat type, root cause, applied mitigations and any cross-border impact.
Each Member State shall ensure that essential and important entities notify […] without undue delay any incident that has a significant impact on the provision of their services.Directive (EU) 2022/2555
All five assessment toolkits: risk analysis, incident handling, continuity, supply chain, and access control with MFA.
Value if bought separately: 395 €
Every premium document: policies, board pack, incident templates and gap analysis workbook.
Value if bought separately: 266 €
How NIS2 actually applies in Germany: the BSI as competent authority, registration duties, and where German law goes beyond the directive.