Attacks are industrialising.
Intrusions are increasingly automated and AI-assisted, which lowers the cost of targeting ordinary mid-sized organisations.
EU cybersecurity directive · In force since October 2024
Attacks are increasingly automated and AI-driven, and around 160,000 organisations across 18 sectors now fall under NIS2. The directive asks you to manage the risk, and to be able to show how — with documentation an authority can read.
Editable Word & Excel. Pay once. Instant download.
Intrusions are increasingly automated and AI-assisted, which lowers the cost of targeting ordinary mid-sized organisations.
NIS2 has applied since 18 October 2024 and national authorities are building supervisory practice.
What counts is what you can show. Implemented but undocumented reads as non-compliant.
NIS2 document packages
€99
6 documents
The process control workbook, annual wheel, risk & gap analysis, implementation guide and the foundation IT security policy. Everything you need to take control of NIS2.
Buy Starter€249
15 documents
Everything in Starter plus the operational layer: risk, access control, supplier and continuity policies, the full incident management pack with statutory reporting forms, and the training programme with tracker.
Buy Professional€449
23 documents
The entire audit-ready programme: everything in Professional plus backup, cryptography and vulnerability policies, asset management with register, board resolution, board reporting deck and internal audit checklist.
Buy CompleteStart small. 100% of what you pay is deducted when you upgrade.
Not ready to buy? Get the checklist and see where you stand — no payment required.
Pay once. No subscription. 100% of a smaller package is deducted when you upgrade.
The Auditra Method for NIS2
Control the process, plan the year, document the evidence — every NIS2 package contains all three layers, and the bigger the package the deeper each layer goes.
See what each package contains“The annual wheel changed how the board talks about security.”
Anna VirtanenCompliance lead, medtech manufacturer · FinlandEditable Word and Excel files, written against the directive and ready to adapt to your organisation.
Excel: every Article 21 measure with an owner, status, evidence link and due date.
Risk assessment, training, exercising and board reporting scheduled across the year.
Asset and threat register with scoring, treatment decisions and residual risk sign-off.
Information security, access control, cryptography, supplier security, continuity and more.
Escalation path plus 24-hour, 72-hour and one-month notification report templates.
Minutes, training records, test reports and registers auditors ask to see.
Documented policies on risk analysis, incident handling, business continuity, supply chain security and access control.
Early warning within 24 hours and a full notification within 72 hours, with a defined internal escalation path.
Company leadership must approve the measures and can be held personally responsible for failures.
Supervisory authorities may request documentation, audit results and proof of training at short notice.
NIS2 is Directive (EU) 2022/2555, enforceable since 18 October 2024 after national transposition. It splits organisations into essential and important entities. The detail lives in five guides.
Also regulated: AI systems under the EU AI Act.
Eighteen sectors and the size thresholds that decide whether you are in scope.
Read the guideEvery Article 21 risk-management measure in plain language.
Read the guide24-hour early warning, 72-hour notification, one-month final report.
Read the guideUp to €10 million or 2% of global turnover, plus management accountability.
Read the guideThe Annex I and Annex II lists, each with a one-line description.
Read the guideNational laws, authorities and status in all 27 EU member states.
Read the guideBuy once, download immediately, and edit everything. Or start with the free readiness checklist.