Date: 28 July 2026
Mapping the Real Scope: 146 Documents Across 13 Categories
This is where most organisations underestimate the task. NIS2 incident response documentation isn't just "an IR plan". It spans governance and policy, incident detection, intake and triage, significant-incident assessment, regulatory reporting, response and recovery, evidence and audit trail, supply chain and third-party risk management, business impact and operational resilience, communications, privacy and cross-regulatory issues, root cause and remediation, testing and training, and the registers and trackers that tie it all together.
Laid out in full, that's 146 distinct documents across those 13 categories. The NIS2 Incident Response Document Library is built specifically around this scope. It maps every one of the 146 documents against the categories above, and against the reporting clock NIS2 actually enforces, so you can see exactly what a complete documentation set looks like rather than guessing at coverage.
The 15 Documents NIS2 Actually Makes Mandatory
Not all 146 carry equal regulatory weight. A subset of 15 documents are the ones NIS2 makes mandatory. The incident response plan, the notification templates for each reporting deadline, the significant-incident assessment criteria, and similar core instruments. These are the documents an auditor or competent authority will ask for first.
Because they carry more regulatory exposure, they need more than a title and an owner, they need full specifications: purpose, owner, regulatory basis, lifecycle stage, contents and dependencies. The document library profiles each of these 15 mandatory documents across 22 fields, and applies a structured NIS2-IR-[TYPE]-[NNN] numbering convention across 18 document types (policies, procedures, plans, forms, playbooks, logs, and more), so mandatory documents are never mixed up with supporting or best-practice ones.
From List to Living System: Why You Need a Master Register
A list of 146 documents is only useful if it's actively maintained, otherwise it becomes stale within a quarter as owners change, review dates pass and new regulatory guidance lands. That's the gap the NIS2 Master Document Register closes.
It's an 18-column, Excel-ready CSV register pre-populated with all 146 documents, structured so it drops straight into Excel, SharePoint or a GRC platform as your single source of truth. Rather than treating the document library as a one-off checklist, the register turns it into something your compliance team actually owns and updates with assigned owners, review dates and regulatory basis tracked against every row, not just the mandatory 15.
Used together, the two resources cover both halves of the problem: the library explains what the 146 documents are and why each one matters, and the register is how you keep them current once they exist.
Common Documentation Mistakes That Undermine NIS2 Readiness
A few patterns show up repeatedly in organisations that think they're ready but aren't:
- Treating the incident response plan as the only document that matters. NIS2 requires an evidenced trail across detection, triage, notification, evidence and remediation. The plan is one document among many.
- No named owner per document. A policy nobody owns doesn't get reviewed, and an unreviewed policy is a liability during an audit.
- No regulatory basis mapped to each document. When a regulator asks "which article does this satisfy," "we're not sure" is not a good answer.
- Documents that exist but were never rehearsed. A notification template nobody has used under time pressure will produce errors on the day it's needed for real.
- Version sprawl. Multiple copies of the same playbook circulating across SharePoint, email and shared drives, with no single controlled version.
A Practical Path to Getting Your Documentation in Order
- Benchmark what you already have against the full 146-document scope in the NIS2 Incident Response Document Library to see exactly where the gaps sit.
- Prioritise the 15 mandatory documents first — these carry the highest regulatory exposure and the most immediate audit risk.
- Import the NIS2 Master Document Register as your working control sheet rather than building a tracker from scratch.
- Assign an owner and a review date to every document, not just the mandatory ones.
- Test the documents, not just the technology. A tabletop exercise that runs your team through an actual 24-hour and 72-hour notification workflow will surface gaps a document review never will.
Key NIS2 Terms
- Early Warning (24-Hour Notification): The initial alert an affected entity must send to its national CSIRT or competent authority within 24 hours of becoming aware of a significant incident.
- Incident Notification (72-Hour Report): The follow-up report due within 72 hours, providing an initial assessment of the incident's severity, impact and, where available, indicators of compromise.
- Final Report (One-Month Report): The closing report due within one month, detailing root cause, impact and the remediation measures taken.
- Significant Incident: An incident that has caused, or is capable of causing, severe operational disruption or financial loss, or that affects other persons through considerable material or non-material damage.
- Essential Entity: An organisation in a high-criticality sector (e.g., energy, transport, health, digital infrastructure) subject to NIS2's stricter supervisory regime.
- Important Entity: An organisation in a sector NIS2 treats as important but less critical than essential entities, subject to lighter-touch (but still mandatory) supervision.
- Master Document Register: The maintained control sheet listing every incident response document an entity holds, along with its owner, review date and regulatory basis.
- Mandatory Document Profile: A detailed, multi-field specification (purpose, owner, regulatory basis, lifecycle, contents, dependencies) for one of the 15 documents NIS2 explicitly requires.
Frequently Asked Questions about NIS2 Documentation
1. What documents does NIS2 require for incident response?
NIS2 requires a full set of governance, detection, assessment, reporting, response, evidence and recovery documents — not just an incident response plan. A complete mapping covers 146 documents across 13 categories, of which 15 are explicitly mandatory.
2. How many documents do I need for NIS2 compliance?
There's no single number that applies to every organisation, but a comprehensive baseline runs to 146 documents across the full incident lifecycle. The 15 mandatory documents should be treated as the non-negotiable starting point, with the remainder prioritised based on your sector and risk profile.
3. What is the NIS2 incident reporting timeline?
NIS2 enforces a three-stage clock: a 24-hour early warning, a 72-hour incident notification with an initial severity assessment, and a final report within one month. Each stage depends on a pre-built template rather than a document drafted during the incident.
4. What's the difference between the NIS2 Document Library and the Master Document Register?
They're a paired set. The NIS2 Incident Response Document Library explains the 146 documents, their categories and the 15 mandatory profiles in detail. The NIS2 Master Document Register is the working Excel-ready control sheet you actually maintain, with owners and review dates tracked against every document.
5. Which NIS2 documents are legally mandatory versus best practice?
Fifteen documents are mandatory under NIS2 — primarily the incident response plan and the notification templates for each reporting deadline. The remaining documents across the 13 categories represent best-practice governance, evidence and resilience documentation that strengthens compliance and reduces audit risk, without being explicitly named in the directive.
6. Who should own NIS2 incident response documentation within an organisation?
Ownership should be assigned per document, not held centrally by one person. Typically this splits across the CISO or security lead (technical and response documents), legal or compliance (regulatory reporting and privacy documents), and business continuity or operations (impact and recovery documentation), all tracked in a single register.
7. How often should NIS2 incident response documents be reviewed and updated?
Mandatory documents should be reviewed at least annually and after any significant incident, regulatory guidance update, or material change to systems or third-party relationships. A maintained register with review dates against every document is what makes this cadence enforceable rather than aspirational.
8. Can I reuse a generic incident response plan for NIS2 compliance?
A generic IR plan will not satisfy NIS2 on its own. It needs to be restructured around NIS2's specific reporting deadlines, significant-incident criteria and regulatory notification requirements, and supported by the wider set of intake, evidence and reporting documents NIS2 expects alongside the plan itself.

.webp)

