Home/Documentation/Regulation-specific sets

NIS2 & DORA Documentation Set

Governance, risk, incident and third-party documentation for EU entities in scope of NIS2 or DORA, with an obligations map showing where the two overlap.

New

What this set does

NIS2 and DORA both hold management bodies personally accountable for cyber risk governance. This set is organised by obligation rather than by control, so you can show a supervisory authority exactly which document satisfies which article, including the DORA regulatory technical standards on ICT risk, incident classification and third-party contracts.

What's inside

  • Management body accountability and oversight charter
  • ICT risk management framework (DORA Article 6 and RTS structure)
  • Cyber risk measures policy set (NIS2 Article 21 items a–j)
  • Major incident classification and reporting procedure (DORA 4-hour / 72-hour timeline; NIS2 24-hour / 72-hour / 1-month)
  • ICT third-party register and contractual provisions checklist
  • Digital operational resilience testing programme
  • Obligations map: NIS2 vs DORA vs ISO 27001

Who it is for

Financial entities, essential and important entities, and their ICT service providers operating in the EU.

How the documents are structured

Every document opens with its purpose, scope and owner, then the substantive content, then a control cross-reference showing which framework requirements it satisfies. Standards state requirements in testable language ("must", with the parameter). Procedures follow one format: trigger, roles, steps, frequency, records produced. Placeholders are limited to things only you can know: organisation name (which we fill in), system names, role titles, tool names and timelines. There are no "[insert policy here]" sections.

Tailoring effort

Expect to spend a few hours on a policies-and-standards set and longer on procedures, because procedures describe how your team actually works. The document register in each set lists every file with a suggested owner so you can split the work.

Included in these bundles

Licence

One purchase covers one organisation for internal use, with unlimited users and unlimited edits. Consultancies and MSPs tailoring documents for clients need the multi-client licence; see the terms or ask us.

Related products

Policies & Standards — ISO/IEC 27001:2022

A complete policy and standards set structured to the 93 Annex A controls of ISO/IEC 27002:2022, plus the clause 4–10 management-system requirements.

£495 · 41 documents

Policies & Standards — NIST CSF 2.0

Policies and standards organised by the six CSF 2.0 functions, with standards written at the subcategory level so each one is auditable.

£445 · 36 documents

Procedures Library

Step-by-step operating procedures that show how each control is actually carried out, who does it, how often, and what record it produces.

£595 · 118 documents