The complete, ready-to-adopt documentation set that proves your NIS2 incident response is in place — before an incident forces you to build it under a 24-hour clock.
The NIS2 Incident Response Document List & Document Library Register is the master inventory of every policy, procedure, register, checklist, form, playbook, evidence log and reporting template an essential or important entity needs to meet its incident response and reporting obligations under the NIS2 Directive (EU) 2022/2555.
Rather than starting from a blank page, you get a fully mapped documentation architecture: 146 documents organised into 13 categories, each one tied to the exact NIS2 article or implementing act it satisfies, with defined ownership, lifecycle position (before, during, or after an incident), a consistent numbering convention, and a recommended folder structure.
It is built around the reporting clock NIS2 actually enforces — the 24-hour early warning, 72-hour incident notification, and one-month final report — and it's designed to be imported straight into Excel, SharePoint or your GRC platform as a living single source of truth.
|
146 documents |
Across 13 categories — governance, intake & triage, significance assessment, regulatory reporting, response & recovery, evidence & audit, supply chain, business impact, communications, privacy & legal, root cause & remediation, testing & training, and registers & trackers. |
|
Regulatory mapping |
Every document tied to its NIS2 article or the relevant implementing act, plus adjacent regimes (GDPR, DORA, ISO 27035, NIST SP 800-61). |
|
15 full document profiles |
Deep specifications for the documents NIS2 makes mandatory — 22 fields each, covering purpose, owner, regulatory basis, lifecycle, contents and dependencies. |
|
Master register (CSV) |
An 18-column, Excel-ready register pre-populated with all 146 documents — import into Excel, SharePoint or your GRC tool. |
|
Numbering convention |
A structured NIS2-IR-[TYPE]-[NNN] scheme across 18 document types (policies, procedures, plans, forms, playbooks, logs, and more). |
|
Recommended folder structure |
A 16-folder architecture, including restricted closed-incident files and regulator submission folders with retention enforced. |
|
Adaptation guidance |
How to scale the library by entity type and size — including which documents to keep, merge or streamline. |
Under NIS2, responsibility for cybersecurity risk — incident response included — sits directly with the management body, and Article 21(2)(b) requires a documented incident management process. When a supervisor reviews you, the review almost always starts with your governance documents: without an approved policy, defined roles and controlled documents, nothing downstream can be evidenced.
The reporting deadlines make this urgent. Once you become aware of a significant incident, an early warning is due within 24 hours, a full notification within 72 hours, and a final report within one month — and missing a deadline is itself a sanctionable breach. Weak intake documentation is the single most common reason entities later can't prove they classified and reported on time.
This library closes that gap. It gives you the artefacts that demonstrate compliance is real and operational — not aspirational — so you're audit-ready before an incident and reporting-ready the moment one begins.
Skip months of scoping work. The full document set, categories, ownership and regulatory mapping are already defined — you adapt, you don't invent.
Know exactly what's mandatory. Every document carries a status code — M (explicitly mandatory), C (required in practice to evidence compliance), or R (recommended good practice) — so you can prioritise the gaps that create direct compliance exposure.
Be ready before the clock starts. The documents you complete during an incident are supplied as pre-approved blank templates, because the 24-hour early warning window leaves no time to design forms.
Survive a supervisory review. Documents are mapped to Articles 20, 21, 23 and Implementing Regulation (EU) 2024/2690, so you can show an auditor the artefact behind each obligation.
Assemble evidence packs automatically. The folder structure mirrors the incident lifecycle, so a closed-incident file effectively builds its own regulatory evidence pack.
One controlled source of truth. The 18-column master register keeps ownership, versions, review dates and regulatory basis in a single maintained list.
** GDPR & Privacy ** We wholeheartedly believe in your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data.
Both. It's a complete register of all 146 documents with their regulatory mapping and ownership, plus full 22-field profiles for the 15 documents NIS2 makes mandatory and an Excel-ready master register. It's a template product, so you adapt each document to your entity before use.
No product can do that on its own. This gives you the documentation architecture and content that compliance depends on, but you still need to adopt, approve, populate and maintain the documents, and align them to your Member State's transposition law.
Article references are used as the directive-level anchor. Because each Member State's transposition law designates the competent authority, CSIRT and reporting channel and sets how the deadlines operate, the guide is explicit that you anchor exact obligations and wording to your national law.
M = mandatory (explicitly required by NIS2, an implementing act or your national law — absence is a direct compliance gap). C = required in practice to evidence a mandatory obligation. R = recommended good practice drawn from ISO 27035, NIST SP 800-61 and supervisory expectations.
An Excel-ready CSV, pre-populated with all 146 documents across 18 columns. You import it into Excel, SharePoint or your GRC tool and maintain it as your single source of truth.
The library is built around the NIS2 reporting clock and supplies the early warning, incident notification and final report templates as pre-approved blank forms — so they exist before an incident, when there's no time to design them.
The guide includes adaptation guidance by entity type and size. The principle is to keep every mandatory (M) document, merge C documents into combined artefacts where sensible, and consolidate roles — without merging away the reporting obligations themselves.
One incident can trigger several regimes at once. The library includes privacy, legal and cross-regulatory documents to keep facts consistent across authorities, and notes that DORA is lex specialis for financial entities and displaces NIS2 incident reporting where it applies.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.