Skip to content
Store / NIS2 / NIS2 Security Policy
NIS2 Step 3 · Internal framework

NIS2 Security Policy

Information security policy template compliant with NIS2 Art. 21, ready for board approval and adaptation to your organization.

€49
VAT included · one-time payment
Buy now → ← Back to store
Referenced article by article with the AI Act, GDPR and DAMA-DMBOK

What's included

  • Editable Word document with the full policy, structured around the 10 minimum domains of Art. 21
  • Reference PDF for internal distribution
  • Legal Notice
📄 Real content preview — first page of the document
Document preview

Why this document exists

NIS2 Art. 21 requires "all-hazards" risk management measures across ten specific domains, and Art. 20 makes the board directly accountable for approving and overseeing them — with personal liability for serious non-compliance. This template gives you the document already structured by domain, ready to adapt to your organization and take to formal approval, instead of starting from a blank page.

Frequently asked questions

What does NIS2 Art. 21 cover?

Ten minimum domains: risk management, incident handling, business continuity, supply chain security, security in system acquisition, effectiveness assessment, cyber hygiene, cryptography, HR security and access control, and multi-factor authentication.

Can it be approved directly by the board?

Yes, it's drafted for formal approval by the management body, as required by NIS2 Art. 20 on senior management accountability.

Does this replace legal advice?

No. It's a working template that speeds up drafting, but it doesn't constitute legal advice or guarantee compliance with Directive (EU) 2022/2555 on its own — see the included Legal Notice.

What format is it delivered in?

Editable Word and reference PDF, plus the Legal Notice, as an instant download after purchase.