The clause that changes behaviour in NIS2 is not a technical control – it is NIS2 management body accountability, which makes directors personally answerable for the cybersecurity risk-management measures and can result in them being temporarily barred from management functions. This pack documents the measures they are accountable for. 78 editable files, downloadable the moment you check out. On this page:
- What is in the toolkit
- NIS2 is enforced nationally, which is where the obligations actually bite
- Who needs NIS2 management body accountability
- How the documents map to the framework
- Frequently asked questions
- Related toolkits
What is in the NIS2 management body accountability pack
The documents cover the ten minimum measures NIS2 Article 21 requires, plus the governance and reporting obligations around them:
- Risk management – risk analysis and information system security policies, acceptance of residual risks, and the risk register that evidences the process
- Incident handling – the incident response procedure and the reporting chain built to the NIS2 timeline of early warning, notification and final report
- Business continuity – backup and recovery policy, BCM crisis and operational resilience plan, exercising and testing plan and report
- Supply chain security – supplier security policy, assessment of direct suppliers and service providers, and contractual security requirements
- Security in acquisition, development and maintenance, including vulnerability handling and disclosure
- Policies to assess the effectiveness of the measures – the internal audit and evaluation set
- Cyber hygiene and training – acceptable use and communications policy, awareness programme and the board-level briefing material
- Cryptography and encryption policy
- Human resources security, access control and identity management, and asset management with the asset register
- Multi-factor authentication and secured communications policies
- Governance and registration – the entity registration position, scope determination for essential versus important entities, and the NIS2 management body accountability documents

NIS2 is enforced nationally, which is where the obligations actually bite
Directive (EU) 2022/2555 had a transposition deadline of 17 October 2024, and many member states missed it. That has made the picture uneven rather than lenient: Germany published its law in December 2025 with registration opening in March 2026, and other states are at different points.
The practical consequence is that your obligations come from your national implementing law, not from the Directive text, and they may differ on registration mechanics, reporting portals and supervisory approach. The pack is written to the Directive requirements that every transposition must carry, with registration handled as a configurable position rather than assuming one national process.
What does not vary is NIS2 management body accountability. Across transpositions, directors must approve the risk-management measures, oversee implementation and undergo training – and can be held personally liable. That is why the board briefing material and the approval records evidencing NIS2 management body accountability are treated here as primary documents rather than appendices.
Who needs NIS2 management body accountability
Entities in the sectors NIS2 covers – energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing, digital providers and research. Suppliers to those entities, who receive the supply chain requirements contractually. And groups needing one consistent framework across several member states.
How the NIS2 management body accountability maps to the framework
NIS2 distinguishes essential from important entities, which changes supervisory regime rather than the measures themselves – essential entities face proactive supervision, important entities reactive. Scope determination therefore drives how much scrutiny you attract, and the pack treats it as a documented decision rather than an assumption.
Frequently asked questions
Do we register, and where?
Registration is run nationally. Most transpositions require in-scope entities to register with the national competent authority. The pack includes the registration position and scope determination; the mechanics follow your member state.
What is the reporting timeline?
An early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. The incident procedure is built to that sequence.
We are in financial services. Does DORA replace this?
For financial entities DORA takes precedence as the more specific regime. Non-financial entities in the same group may still be in NIS2 scope. See the DORA Toolkit.
Is NIS2 certifiable?
No. It is a directive enforced by national authorities, so there is no certificate – which is why documented evidence and board approval records matter more than they would under a certification scheme.
How many documents are included?
78 editable files – 70 Word documents, 7 Excel workbooks and a training presentation.
Related toolkits
NIS2 obligations overlap heavily with certifiable standards. See the ISO 27001 Toolkit for the ISMS most of the Article 21 measures map onto, the ISO 22301 Toolkit for business continuity, the DORA Toolkit for financial entities and the CIS Controls Toolkit for the technical baseline. Manufacturers of products with digital elements also need the EU Cyber Resilience Act toolkit, and operators of industrial control systems the IEC 62443 toolkit.
Implementing for clients? The Consultant Package licenses all 86 toolkits and assessment tools on this site for unlimited client engagements, under one firm-wide licence. One payment of $1,399, no subscription and no per-client fee.
Delivery, format and licence
Your NIS2 management body accountability downloads immediately after checkout as native Microsoft Word and Excel files. Nothing is watermarked or locked, so you can rebrand the documents, bring them under your own document control and revise them for as long as you need them.
One-time purchase. No subscription and no annual renewal. Because the source files are yours, revising a procedure after an audit finding or a change of scope is an internal edit rather than another purchase.













Reviews
There are no reviews yet.