EU cybersecurity directive · In force since October 2024

NIS2 compliance. Hard to ignore, simple to run with the right process.

Attacks are increasingly automated and AI-driven, and around 160,000 organisations across 18 sectors now fall under NIS2. The directive asks you to manage the risk, and to be able to show how — with documentation an authority can read.

Editable Word & Excel. Pay once. Instant download.

Why NIS2, why now

Attacks are industrialising.

Intrusions are increasingly automated and AI-assisted, which lowers the cost of targeting ordinary mid-sized organisations.

The law is already in force.

NIS2 has applied since 18 October 2024 and national authorities are building supervisory practice.

Preparedness is documentation.

What counts is what you can show. Implemented but undocumented reads as non-compliant.

NIS2 document packages

Three depths of the same audit-ready programme.

NIS2 Starter

€99

6 documents

The process control workbook, annual wheel, risk & gap analysis, implementation guide and the foundation IT security policy. Everything you need to take control of NIS2.

Buy Starter
Most popular

NIS2 Professional

€249

15 documents

Everything in Starter plus the operational layer: risk, access control, supplier and continuity policies, the full incident management pack with statutory reporting forms, and the training programme with tracker.

Buy Professional

NIS2 Complete

€449

23 documents

The entire audit-ready programme: everything in Professional plus backup, cryptography and vulnerability policies, asset management with register, board resolution, board reporting deck and internal audit checklist.

Buy Complete

Start small. 100% of what you pay is deducted when you upgrade.

Free NIS2 Readiness Checklist

Not ready to buy? Get the checklist and see where you stand — no payment required.

Get the free NIS2 checklist

Pay once. No subscription. 100% of a smaller package is deducted when you upgrade.

The Auditra Method for NIS2

Control the process, plan the year, document the evidence — every NIS2 package contains all three layers, and the bigger the package the deeper each layer goes.

See what each package contains
The annual wheel changed how the board talks about security.
Anna VirtanenAnna VirtanenCompliance lead, medtech manufacturer · Finland

What is inside a package

Editable Word and Excel files, written against the directive and ready to adapt to your organisation.

Process control workbook

Excel: every Article 21 measure with an owner, status, evidence link and due date.

Annual compliance wheel

Risk assessment, training, exercising and board reporting scheduled across the year.

Risk assessment template

Asset and threat register with scoring, treatment decisions and residual risk sign-off.

Policy library

Information security, access control, cryptography, supplier security, continuity and more.

Incident management pack

Escalation path plus 24-hour, 72-hour and one-month notification report templates.

Evidence templates

Minutes, training records, test reports and registers auditors ask to see.

Risk management measures

Documented policies on risk analysis, incident handling, business continuity, supply chain security and access control.

Incident reporting

Early warning within 24 hours and a full notification within 72 hours, with a defined internal escalation path.

Management accountability

Company leadership must approve the measures and can be held personally responsible for failures.

Evidence on request

Supervisory authorities may request documentation, audit results and proof of training at short notice.

Frequently asked questions

Ready to start your NIS2 programme?

Buy once, download immediately, and edit everything. Or start with the free readiness checklist.

View NIS2 packages