ShopNIS2 Compliance Toolkit
Directive (EU) 2022/2555 · implementation, not restatement

Get NIS2-ready without starting from a blank page

The directive tells you what. This toolkit is the how the registers, policies, incident-reporting playbook and 90-day roadmap a real in-scope organisation uses, written by someone running production Active Directory and a self-hosted SIEM inside an EU org in NIS2 scope.

See what's in the toolkit First: am I even in scope? →

  • Mapped to ISO 27001:2022, NIST CSF 2.0 & CIS v8
  • Registers pre-seeded with worked examples
  • The 24h / 72h / 1-month reporting clock, wired in
  • No DRM · editable files you own
Start free

Two free resources before you spend anything

Answer the scope question first, then take the one-page reference. Both are genuinely useful on their own, and there is no better way to judge whether the paid toolkit is worth it.

NIS2 Scope Self-Check

Free

Answers Are we in scope? Essential or Important?

A six-question checker that gives a defensible working answer in a couple of minutes, the size test, the sector test, and the size-independent rules that catch people who assume they are too small.

  • Interactive
  • 2 minutes
  • No signup
£0on this page
Run the scope check

NIS2 on One Page

Free

Best for pinning above your desk

The whole directive distilled: who's in scope, the ten Article 21 measures with the one thing to get right on each, and the reporting clock. The reference you'll actually keep.

  • 1 page
  • PDF
  • Print-ready
£0instant download
Download the cheat sheet
Free scope self-check

Are you in scope, and as what?

This is the first question, and the most-mis-answered one. Answer honestly for the whole legal entity. You'll get a working classification and what it means. Not legal advice, confirm against your national transposition.

1. Headcount, do you employ 50 or more people?
2. Finances, is annual turnover or balance sheet total above €10 million?
4. Do you operate in a high-criticality (Annex I) sector? Energy · transport · banking · financial market infrastructure · health · drinking & waste water · digital infrastructure · ICT service management / MSP · MSSP · public administration · space.
5. Or in an "other critical" (Annex II) sector? Postal & courier · waste management · chemicals · food · manufacturing (medical devices, electronics, machinery, vehicles) · digital providers (marketplace, search, social) · research.
6. Regardless of size, are you a telecom, trust-service, DNS/TLD provider, or the sole/critical provider of a service in your country? These are in scope whatever your size. Your national law may list more.

JavaScript is off, so here's the rule directly: you're generally in scope if you meet the size gate (Q1 or Q2 = yes) and a sector (Q4 or Q5 = yes), Essential if large in Annex I, Important otherwise. Q6 puts you in regardless of size. Confirm nationally.

Prefer paper? The printable worksheet is included in the free cheat sheet and the toolkit's implementation guide.

Entry, the on-ramp

Not ready for the full toolkit? Start here.

A guided workbook and a control-by-control checklist. Enough to get a small team to a defensible baseline, and everything maps straight onto the Core toolkit when you outgrow it.

NIS2 Implementation Workbook

.PDF

Best for a small team starting cold

One guided document you work top to bottom, filling in the prompts: scope decision, governance setup, starter risk list, incident-reporting details and a gap list that becomes your project plan.

  • 8 sections
  • Fill-in
  • Maps to Core

NIS2 Compliance Checklists

.XLSX

Best for a fast self-assessment

Governance, all ten Article 21 measures and the reporting duty as 40 concrete items, each with what "done" looks like, plus Status / Owner / Evidence columns so it doubles as an assurance tracker.

  • 40 items
  • Self-score
  • Trackable
Entry bundle

NIS2 Starter Pack

The Workbook and the Checklists together, the fastest way to find out where you stand and what to fix first.

  • NIS2 Implementation Workbook
  • NIS2 Compliance Checklists (40 items)
Coming soon Pricing under review Coming soon

Launching shortly

Core, flagship The core toolkit

Everything to go from "in scope" to audit-ready

Nine deliverables that fit together, the guide explains it, the registers record it, the playbook handles the incident, the policies document it, the roadmap sequences it, and the board pack proves management owned it.

  • 01Implementation GuideThe ten Article 21 measures, each as what-good-looks-like, how to implement, the common mistake, and the evidence an auditor asks for.
  • 02Article 21 Control MappingEvery measure cross-walked to ISO/IEC 27001:2022, NIST CSF 2.0 and CIS Controls v8. Spreadsheet.
  • 03Risk RegisterA 5×5 method, pre-seeded with ten worked risks (Kerberoasting, ransomware, MSP compromise…) and a scoring key.
  • 04Asset & Supplier RegisterSystems, data, endpoints and a supplier tab tiered by criticality, the 21(d) and 21(i) evidence base.
  • 05Evidence TrackerEvery measure mapped to its artifact, owner, status and review date. The audit becomes a lookup, not a scramble.
  • 06Incident Reporting PlaybookThe significance decision tree and ready-to-send 24h / 72h / 1-month templates. Decided before the incident.
  • 07Policy & Procedure PackTen ready-to-adopt policies covering the documented half of every measure, short enough to actually maintain.
  • 0890-Day RoadmapA proportionate, six-phase sequence with owners, governance first, highest-consequence gaps early.
  • 09Board Reporting PackThe quarterly report, the management sign-off record, and the director-training record, the Article 20 evidence teams rarely produce.
One-time · yours to keep

NIS2 Compliance Toolkit

All nine deliverables in one download. Built for the in-scope SMB and the consultant, MSP or internal team serving one, proportionate, practical, and mapped to the framework you already run.

  • Implementation guide + 90-day roadmap
  • Risk, asset & evidence registers + control mapping
  • Incident-reporting playbook + 10-policy pack
  • Board reporting pack (Article 20 evidence)
Coming soon Pricing under review Coming soon

Launching shortly

Premium, for teams & MSPs

Deliver NIS2 to a whole portfolio, or run the room

For the people who take others through NIS2: consultants, MSPs, and internal leads. Licensed for client delivery and rebrandable.

NIS2 Team / MSP Edition

.PDF+.XLSX

Best for MSPs, MSSPs and vCISOs

A repeatable, productised delivery method, a portfolio-wide multi-client tracker, and the MSP's own obligations, because if you run managed services, you are in scope and you are your clients' biggest supply-chain risk.

  • Multi-client tracker
  • Rebrandable
  • Engagement model
Coming soonpricing under review
Coming soon

NIS2 Workshop Pack

.PPTX+.PDF

Best for running a leadership session

A ready-to-run 3.5-hour workshop: a 24-slide deck and a facilitator guide with a minute-by-minute run sheet, that turns "we should look at NIS2" into an owned, prioritised action list in one sitting.

  • 24 slides
  • Facilitator guide
  • Run sheet
Coming soonpricing under review
Coming soon
Choose your tier

From free scope check to full portfolio delivery

Every tier is a step up from the last, and each one credits into the next. Start where you are.

TierWhat you getBest forPrice
Free Scope self-check + one-page cheat sheet "Are we in scope?" $0 Start
Entry Starter Pack: Implementation Workbook + 40-item Checklists A small team starting cold Coming soon Preview
Core Compliance Toolkit: guide, control mapping, 3 registers, incident playbook, 10 policies, roadmap, board pack Getting to audit-ready Coming soon Preview
Premium Team / MSP Edition · Workshop Pack Delivering NIS2 to others Coming soon See both
Pairs with

The technical evidence behind the measures

NIS2 asks you to prove the controls. These are the read-only tooling and reference packs that produce that evidence, the Article 21 measures made concrete.

Hardening Checklist Pack

.PDF

Windows Server & AD hardening checklists, the 21(e)/21(g) baseline in a working form.

$5one-time
Get the checklists $5

Incident Response Runbook

.PDF

Phase-by-phase triage for compromised accounts, ransomware and lateral movement, the response half of 21(b).

$12one-time
Get the runbook $12

Expanded Script Bundle

.PS1

Read-only AD audit scripts (DCSync rights, delegation, dangerous ACLs), evidence for 21(i)/21(j).

$9one-time
Get the scripts $9
Before you buy

NIS2 toolkit FAQ

Is this legal advice?

No. NIS2 is Directive (EU) 2022/2555, transposed into national law by each Member State. This is implementation guidance written by a practitioner, it builds the security programme. Confirm the legal specifics against your national transposition and, where the stakes justify it, your counsel.

Who is the toolkit for?

In-scope SMBs and the consultants, MSPs and internal IT/security teams serving them. It is written to be proportionate a 60-person organisation is not held to a national bank's standard, and the guidance says so throughout.

What format do I receive?

Editable working files: the guide, playbook, roadmap and board pack as PDFs; the risk, asset and evidence registers plus the Article 21 control mapping as spreadsheets; the ten policies as ready-to-adopt templates. Nothing is DRM-locked and nothing phones home.

Does it map to ISO 27001 or NIST?

Yes. Every Article 21 measure is cross-walked to ISO/IEC 27001:2022 Annex A, NIST Cybersecurity Framework 2.0 and CIS Controls v8, so it slots into a framework you already run rather than starting over.

How is this different from a generic template pack?

It is built by someone running production Active Directory, Windows Server and a self-hosted SIEM inside an EU organisation in NIS2 scope. The registers ship pre-seeded with worked examples, the incident playbook has the reporting clock wired in, and every measure comes with the common mistake and the evidence an auditor actually asks for. The blog shows the depth for free, read it first.