NIS2 Security Policy
Information security policy template compliant with NIS2 Art. 21, ready for board approval and adaptation to your organization.
What's included
- Editable Word document with the full policy, structured around the 10 minimum domains of Art. 21
- Reference PDF for internal distribution
- Legal Notice
Why this document exists
NIS2 Art. 21 requires "all-hazards" risk management measures across ten specific domains, and Art. 20 makes the board directly accountable for approving and overseeing them — with personal liability for serious non-compliance. This template gives you the document already structured by domain, ready to adapt to your organization and take to formal approval, instead of starting from a blank page.
Frequently asked questions
What does NIS2 Art. 21 cover?
Ten minimum domains: risk management, incident handling, business continuity, supply chain security, security in system acquisition, effectiveness assessment, cyber hygiene, cryptography, HR security and access control, and multi-factor authentication.
Can it be approved directly by the board?
Yes, it's drafted for formal approval by the management body, as required by NIS2 Art. 20 on senior management accountability.
What format is it delivered in?
Editable Word and reference PDF, plus the Legal Notice, as an instant download after purchase.