Directive NIS2 European Union

Toolkits, policy packs and country packs


Documents you can put in front of an auditor, a board, or a competent authority. Written against the text of the directive, article by article.

  • Instant download
  • Lifetime updates
  • EU VAT invoice
  • 30-day money-back guarantee

Volume discount, applied automatically

-15% from 150 € · -25% from 300 € · -40% from 500 € · -50% from 800 € — calculated on the subtotal excluding VAT, no code needed.

Certifications


Art. 21(2)

NIS2 National Transposition — certification

The certification our transposition data hub uniquely supports: how the 27 member states turn article 21(2) into national law, the six national assessment frameworks in use, and how to run one security programme across several jurisdictions.

  • Eight lessons across four modules, about two and a half hours
  • Where all 27 member states stand, and what a late transposition does not suspend
  • The six national assessment frameworks, distinguished by what kind of object each one is
  • CyberFundamentals in detail: joint ownership by Belgium, Ireland and Romania, the four levels and their control counts, the maturity thresholds
  • IT-Grundschutz, E-ITS, Kybermittari, the ACN determinations and ReCyF — including which ones have no label to hold
  • National renumbering, and the eleventh measure Belgian law adds at article 30 §3
  • Registration channels, supervisory bodies and reporting deadlines per member state, including where Sweden is stricter than the directive
  • Server-side exam drawn from a bank of 36 questions, 12 per attempt, three attempts
  • A certificate with a public verification page, revocable on refund
249 € excl. VAT

301,29 € incl. VAT (BE 21%)

Assessment toolkits


Art. 21(2)(a)

Risk Analysis & Security Policy Toolkit

Assess and evidence your risk-analysis methodology and information system security policies, as required by article 21(2)(a).

  • Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
  • Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
  • Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • Regenerated from our data hub, so it carries the same review date as the site and cannot drift from it
79 € excl. VAT

95,59 € incl. VAT (BE 21%)

Art. 21(2)(b) · Art. 23

Incident Handling Toolkit

Build the incident handling capability article 21(2)(b) requires, wired to the 24h / 72h / one-month reporting chain of article 23.

  • Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
  • Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
  • Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • Regenerated from our data hub, so it carries the same review date as the site and cannot drift from it
79 € excl. VAT

95,59 € incl. VAT (BE 21%)

Art. 21(2)(c)

Business Continuity & Crisis Management Toolkit

Backup management, disaster recovery and crisis management, the three components named in article 21(2)(c).

  • Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
  • Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
  • Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • Regenerated from our data hub, so it carries the same review date as the site and cannot drift from it
79 € excl. VAT

95,59 € incl. VAT (BE 21%)

Art. 21(2)(d) · Art. 21(3)

Supply Chain Security Toolkit

Supplier risk assessment and contractual security requirements — the obligation most entities are least prepared for.

  • Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
  • Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
  • Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • Regenerated from our data hub, so it carries the same review date as the site and cannot drift from it
79 € excl. VAT

95,59 € incl. VAT (BE 21%)

Art. 21(2)(i) · 21(2)(j)

Access Control, MFA & Asset Management Toolkit

Human resources security, access control policies, asset management and the multi-factor authentication requirement of article 21(2)(j).

  • Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
  • Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
  • Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • Regenerated from our data hub, so it carries the same review date as the site and cannot drift from it
79 € excl. VAT

95,59 € incl. VAT (BE 21%)

Best value

Complete Assessment Toolkit Bundle

All five assessment toolkits: risk analysis, incident handling, continuity, supply chain, and access control with MFA.

  • All five article 21 assessment toolkits, each delivered as its own download
  • Contents summary (Markdown) listing every component
  • Every component generated from the same data hub on the same review date, so the per-country tables agree with each other and with the site
249 € excl. VAT

301,29 € incl. VAT (BE 21%)

Value if bought separately: 395 €

Policy & board documents


NIS2 Policy & Procedures Pack

Twelve editable policies covering every article 21 measure, written to survive a competent authority review.

  • Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
  • Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
  • Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • Ten policy skeletons, one per article 21(2) measure (Markdown): purpose, scope, testable requirements, accountability at management-body level, evidence, review cycle, and a slot for your national article reference
  • Stated plainly: these are skeletons with bracketed fields to complete, not policies to sign as they stand
  • Regenerated from our data hub, so it carries the same review date as the site
69 € excl. VAT

83,49 € incl. VAT (BE 21%)

Art. 20

Board & Management Accountability Pack

Article 20 makes management bodies personally accountable and requires them to follow training. This pack is what you put in front of them.

  • Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
  • Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
  • Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • Article 20 management record (CSV): the five obligations of the management body, each with the evidence a supervisor expects — approval decision, oversight reporting, board training, employee training, allocation of accountability
  • Regenerated from our data hub, so it carries the same review date as the site
49 € excl. VAT

59,29 € incl. VAT (BE 21%)

Art. 23

Article 23 Incident Reporting Template Set

The full reporting chain as fill-in forms, so the 24-hour clock is not spent designing a document.

  • Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
  • Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
  • Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • Article 23 notification template (CSV): the full chain as fillable fields — early warning within 24 hours, notification within 72 hours, intermediate report on request, final report within one month
  • Reporting channels for all 27 member states (CSV): CSIRT, competent authority and registration channel, so the 24-hour clock is not when you find out which portal applies
  • Flags where a member state is stricter than the directive — Sweden requires a 24-hour follow-up from trust service providers
49 € excl. VAT

59,29 € incl. VAT (BE 21%)

NIS2 Gap Analysis Workbook

A single workbook that scores you against all ten article 21 measures and produces a costed, sequenced remediation roadmap.

  • Gap-analysis worksheet (CSV, semicolon-separated, UTF-8 with BOM — opens directly in Excel and LibreOffice)
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • One row per risk-management measure of article 21(2), with the measure text and what it requires
  • Audit columns a supervisor asks for: status, evidence held, gap identified, remediation action, owner, target date
  • Guidance note on national renumbering — several member states renumber these measures and at least one adds to them
  • Review-dated and regenerated from our data hub, so it stays consistent with the country packs
99 € excl. VAT

119,79 € incl. VAT (BE 21%)

Most popular

NIS2 Complete Implementation Library

Every premium document: policies, board pack, incident templates and gap analysis workbook.

  • The policy pack, board pack, incident templates and gap analysis workbook, each delivered as its own download
  • Contents summary (Markdown) listing every component
  • Every component generated from the same data hub on the same review date, so the per-country tables agree with each other and with the site
199 € excl. VAT

240,79 € incl. VAT (BE 21%)

Value if bought separately: 266 €

Country transposition packs


DE

Germany Transposition Pack (NIS2UmsuCG)

How NIS2 actually applies in Germany: the BSI as competent authority, registration duties, and where German law goes beyond the directive.

  • National reference document (Markdown): what binds you in Germany, not the directive
  • The national law, its adoption and entry-into-force dates, and its current status
  • How Germany numbers the article 21(2) measures, and any measure it adds
  • Registration channel and portal, with the deadline rule
  • Supervision: who inspects, and from when
  • IT-Grundschutz: the three implementation routes, the modules and layers, the move to Grundschutz++, and why it is the de facto benchmark without being legally mandatory
  • Gap-analysis worksheet (CSV, opens in Excel): one row per measure with the national reference, plus status, evidence, gap, remediation, owner and target-date columns
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • Every fact carries its source and a review date — regenerated from our data hub, so it cannot drift from the site
129 € excl. VAT

156,09 € incl. VAT (BE 21%)

FR

France Transposition Pack

NIS2 as transposed in France: ANSSI as competent authority, entity classification, and the national registration procedure.

  • National reference document (Markdown): what binds you in France, not the directive
  • The national law, its adoption and entry-into-force dates, and its current status
  • How France numbers the article 21(2) measures, and any measure it adds
  • Registration channel and portal, with the deadline rule
  • Supervision: who inspects, and from when
  • Référentiel Cyber France (ReCyF): the two entity grades, and the plain warning that it sits on a law which is not yet promulgated
  • Gap-analysis worksheet (CSV, opens in Excel): one row per measure with the national reference, plus status, evidence, gap, remediation, owner and target-date columns
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • Every fact carries its source and a review date — regenerated from our data hub, so it cannot drift from the site
129 € excl. VAT

156,09 € incl. VAT (BE 21%)

BE

Belgium Transposition Pack (CCB / CyFun)

Belgium transposed early and added CyFun. This pack covers the CCB regime, Safeonweb@Work registration and the CyFun assurance levels.

  • National reference document (Markdown): what binds you in Belgium, not the directive
  • The national law, its adoption and entry-into-force dates, and its current status
  • How Belgium numbers the article 21(2) measures, and any measure it adds
  • Registration channel and portal, with the deadline rule
  • Supervision: who inspects, and from when
  • CyberFundamentals (CyFun 2025): the four assurance levels with their control counts, the maturity thresholds, the Belgian deadlines, and what a CyFun label does not prove
  • Gap-analysis worksheet (CSV, opens in Excel): one row per measure with the national reference, plus status, evidence, gap, remediation, owner and target-date columns
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • Every fact carries its source and a review date — regenerated from our data hub, so it cannot drift from the site
129 € excl. VAT

156,09 € incl. VAT (BE 21%)

VAT is calculated at checkout based on your country. Business customers with a valid EU VAT number are invoiced under the reverse-charge procedure.

Our certifications are private training attestations. They are not accredited under ISO/IEC 17024, are not a European cybersecurity certification scheme within the meaning of article 24 of NIS2, and do not certify the NIS2 compliance of your organisation.

Cart 0