The single, Excel-ready control sheet that turns 146 NIS2 incident response documents into one maintained source of truth
The NIS2 Master Document Register is the working spreadsheet at the heart of the NIS2 Incident Response Document Library. Where the guide describes the documentation set, the register operationalises it — a single, 18-column table listing all 146 documents across 13 categories, pre-populated and ready to import into Excel, SharePoint or your GRC platform.
Each row is a complete control record: document ID, name, category, type, owner, approver, the exact NIS2 article or implementing act it maps to, its mandatory/recommended status, format, review frequency, retention period, current status, version, review dates, linked documents, evidence location and notes.
It's supplied as a free, adaptable CSV template — you take it as your starting baseline, set the owners and dates for your organisation, and maintain it as the live single source of truth for your entire incident response documentation set.
|
Component |
Detail |
|
146 document records |
Every document in the library, one per row, ready to sort and filter. |
|
13 categories |
Governance & Policy, Incident Detection/Intake/Triage, Significant Incident Assessment, Regulatory Reporting, Response & Recovery, Evidence & Audit Trail, Supply Chain & Third-Party, Business Impact & Operational Resilience, Communications, Privacy/Legal/Cross-Regulatory, Root Cause/Remediation/Lessons Learned, Testing/Training/Continuous Improvement, and Registers & Trackers. |
|
18 columns per record |
Document ID · Name · Category · Type · Owner · Approver · NIS2 article/implementing act reference · Mandatory/recommended status · Format · Review frequency · Retention period · Status · Version · Last reviewed date · Next review date · Linked documents · Evidence location · Notes. |
|
Status classification |
Every document coded as Mandatory under NIS2 (15), Required for practical compliance (99), or Recommended good practice (32). |
|
Cross-references |
A "Linked documents" column connects each record to its dependencies, so you can trace how the set fits together. |
|
Adaptation-ready |
Delivered as an editable CSV under a free internal-use licence — set your own owners, dates and sector notes. |
NIS2 places responsibility for the incident management process directly on the management body, and a supervisory review will ask you to evidence it — not just describe it. Without a controlled register showing which documents exist, who owns them, when they were last reviewed and which NIS2 article each one satisfies, you can't demonstrate that your documentation set is real and maintained.
A pile of 146 separate documents with no index is also unmanageable in practice. Owners drift, versions fork, reviews lapse, and dependencies get lost. When an incident hits and the 24-hour / 72-hour / one-month reporting clocks start, you need to know instantly which template to reach for and that it's the approved, current version.
The register solves both problems at once. It's the control layer that makes the whole library governable — the difference between having documents and being able to prove you manage them.
** GDPR & Privacy ** We wholeheartedly believe in your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data.
It's a spreadsheet. A single CSV file with 146 rows (one per document) and 18 columns of control information, ready to open in Excel or import into SharePoint or a GRC tool.
They're a pair. The guide explains the 146 documents, their categories and the mandatory profiles; the register is the working control sheet you actually maintain. The guide is the map, the register is the live tracker.
Each document is classified as Mandatory under NIS2 (explicitly required — 15 documents), Required for practical compliance (needed to evidence a mandatory obligation — 99 documents), or Recommended good practice (drawn from ISO 27035 and NIST SP 800-61 — 32 documents).
Yes. It's a free template you adapt for internal use. Set your owners, dates and sector-specific notes, and add columns if your GRC process needs them. It may not be resold.
No. It's a control and tracking tool that helps you organise and evidence your documentation, but compliance still requires you to create, approve and maintain the underlying documents and align them to your national transposition law.
The "NIS2 article / implementing act reference" column uses directive-level article numbers as the anchor. Because each Member State transposes NIS2 into national law, you should map these to your own national provisions where exact wording matters.
Use the review frequency, last-reviewed and next-review columns to schedule maintenance — typically annually and after every major incident or failed test — and update the status and version columns as documents move from template to approved.
It's a standard comma-separated CSV, which opens natively in Excel and Google Sheets and imports cleanly into SharePoint lists and most GRC document modules.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.