NIS2 Master Document Register

The single, Excel-ready control sheet that turns 146 NIS2 incident response documents into one maintained source of truth

NIS2 Master Document Register NIS2 Document Register

Free and Immediately Usable NIS2 Master Document Register

What is the NIS2 Master Register?

The NIS2 Master Document Register is the working spreadsheet at the heart of the NIS2 Incident Response Document Library. Where the guide describes the documentation set, the register operationalises it — a single, 18-column table listing all 146 documents across 13 categories, pre-populated and ready to import into Excel, SharePoint or your GRC platform.

Each row is a complete control record: document ID, name, category, type, owner, approver, the exact NIS2 article or implementing act it maps to, its mandatory/recommended status, format, review frequency, retention period, current status, version, review dates, linked documents, evidence location and notes.

It's supplied as a free, adaptable CSV template — you take it as your starting baseline, set the owners and dates for your organisation, and maintain it as the live single source of truth for your entire incident response documentation set.

What's Inside?

 

Component

Detail

146 document records

Every document in the library, one per row, ready to sort and filter.

13 categories

Governance & Policy, Incident Detection/Intake/Triage, Significant Incident Assessment, Regulatory Reporting, Response & Recovery, Evidence & Audit Trail, Supply Chain & Third-Party, Business Impact & Operational Resilience, Communications, Privacy/Legal/Cross-Regulatory, Root Cause/Remediation/Lessons Learned, Testing/Training/Continuous Improvement, and Registers & Trackers.

18 columns per record

Document ID · Name · Category · Type · Owner · Approver · NIS2 article/implementing act reference · Mandatory/recommended status · Format · Review frequency · Retention period · Status · Version · Last reviewed date · Next review date · Linked documents · Evidence location · Notes.

Status classification

Every document coded as Mandatory under NIS2 (15), Required for practical compliance (99), or Recommended good practice (32).

Cross-references

A "Linked documents" column connects each record to its dependencies, so you can trace how the set fits together.

Adaptation-ready

Delivered as an editable CSV under a free internal-use licence — set your own owners, dates and sector notes.

Why Do You Need the NIS2 Master Document Register? 

NIS2 places responsibility for the incident management process directly on the management body, and a supervisory review will ask you to evidence it — not just describe it. Without a controlled register showing which documents exist, who owns them, when they were last reviewed and which NIS2 article each one satisfies, you can't demonstrate that your documentation set is real and maintained.

A pile of 146 separate documents with no index is also unmanageable in practice. Owners drift, versions fork, reviews lapse, and dependencies get lost. When an incident hits and the 24-hour / 72-hour / one-month reporting clocks start, you need to know instantly which template to reach for and that it's the approved, current version.

The register solves both problems at once. It's the control layer that makes the whole library governable — the difference between having documents and being able to prove you manage them.

Key Benefits

  • One source of truth, not 146 scattered files. Every document, its owner, status and regulatory basis live in a single sheet you can sort, filter and report from.
  • See your compliance posture at a glance. Filter by status to instantly separate the 15 mandatory documents from the 99 required for practical compliance and the 32 recommended good-practice artefacts.
  • Know who owns what. Owner and approver are defined for every row, so accountability is never ambiguous during a supervisory review or a live incident.
  • Never miss a review. Built-in review frequency, last-reviewed and next-review columns turn documentation upkeep into a schedule you can track.
  • Audit-ready mapping. Each document is tied to its NIS2 article or Implementing Regulation (EU) 2024/2690 reference, so you can show an assessor the artefact behind every obligation.
  • Drops straight into your tools. As a clean CSV, it imports into Excel, SharePoint lists or a GRC document module in minutes — no reformatting.

Who Should Use the NIS2 Master Document Register? 

  • CISOs and information security leaders who need to own and evidence the incident response documentation set.
  • Compliance, risk and GRC teams maintaining the mapping between controls and NIS2 articles for audit and supervisory purposes.
  • Document and records managers responsible for versioning, retention and review scheduling across the set.
  • Management bodies and executives carrying accountability under Article 20 who need a one-page view of documentation status.
  • Essential and important entities in NIS2 scope — including the digital providers named in Implementing Regulation (EU) 2024/2690.
  • Consultants and virtual CISOs who want a ready-made, adaptable register to deploy across multiple client programmes.

 

** GDPR & Privacy ** We wholeheartedly believe in your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data.

 

Please Fill the Form Below To Get Your Free Copy of the NIS2 Master Document Register

cyber-essentials-certification
NCSC Certified Training B&W 300px
CSC

Frequently Asked Questions about the NIS2 Master Document Register

  • 1. What exactly is the register — a spreadsheet or a document?

    It's a spreadsheet. A single CSV file with 146 rows (one per document) and 18 columns of control information, ready to open in Excel or import into SharePoint or a GRC tool.

  • 2.  How does it relate to the NIS2 Incident Response Document Library guide?

    They're a pair. The guide explains the 146 documents, their categories and the mandatory profiles; the register is the working control sheet you actually maintain. The guide is the map, the register is the live tracker.

  • 3. What do the status values mean?

    Each document is classified as Mandatory under NIS2 (explicitly required — 15 documents), Required for practical compliance (needed to evidence a mandatory obligation — 99 documents), or Recommended good practice (drawn from ISO 27035 and NIST SP 800-61 — 32 documents).

  • 4. Can I edit it and add my own columns?

    Yes. It's a free template you adapt for internal use. Set your owners, dates and sector-specific notes, and add columns if your GRC process needs them. It may not be resold.

  • 5. Does using the register make us NIS2 compliant?

    No. It's a control and tracking tool that helps you organise and evidence your documentation, but compliance still requires you to create, approve and maintain the underlying documents and align them to your national transposition law.

  • 6. How do the article references work if NIS2 is a directive?

    The "NIS2 article / implementing act reference" column uses directive-level article numbers as the anchor. Because each Member State transposes NIS2 into national law, you should map these to your own national provisions where exact wording matters.

  • 7. How should we keep it up to date?

    Use the review frequency, last-reviewed and next-review columns to schedule maintenance — typically annually and after every major incident or failed test — and update the status and version columns as documents move from template to approved.

  • 8. What format is the file and will it work in our systems?

    It's a standard comma-separated CSV, which opens natively in Excel and Google Sheets and imports cleanly into SharePoint lists and most GRC document modules.

We are industry experienced practitioners when it comes to cyber security training & cyber security consultancy services

1487652208_graduationcap

Training

We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.

1487652701_like

Virtual CISO Services

Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.

1487652784_calendar-3

Virtual Cyber Assistant

A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.

1487652846_microphone

Cyber Crisis Tabletop Exercises

Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.

1487652632_search

Ransomware Tabletop Exercise

Measure your organisation’s Ransomware Readiness with a unique blend of verbal and visual simulations and ransomware scenario walkthroughs.

1487652567_line-chart

Executive Cyber Awareness Sessions

Specially designed for executive management, CEOs and boards of directors, engaging them in a business context to help explain the threats and risks from cyber-attacks.

How we use your data:

  • Contact you about our services including, but not limited to, training, trusted advisory and consultancy.
  • Keep you posted on free resources and documents.
  • Update you on upcoming webinars and surveys.
  • Update you when we host our ground-breaking Wisdom of Crowds events.
  • Ask you, every now and then, if you want to take part in crowdsourced initiatives.
  • Our partners (we carefully select our partners) may contact you to arrange or demo or share more information with you about their products or services when you watch one of our sponsored webinars. Remember, you can always tell us or our partners, "No, not interested".
Cyber Incident Response Plan Template