which policy documents must I have for NIS2
Policy follows from the ten measures, not from a fixed list
There is no official checklist with names of policy documents that are mandatory under NIS2. What does exist: ten categories of measures for which an organization must be able to demonstrate how they are handled, and in practice that translates into a set of policy documents that most organizations develop. Think of an information security policy as an overarching document, a risk policy, a policy for incident handling and reporting, a policy for business continuity and crisis management, a supplier policy with supply chain requirements, an access policy, and a policy for cryptography and encryption. Some organizations add a separate policy for personnel security and awareness, linked to training with a certificate of participation — the latter is relevant because why do I need a certificate of participation for a cybersecurity training explain what that evidence exactly demonstrates.
More important than the precise title of each document is that each piece aligns measure by measure with what actually happens in practice, with evidence attached and someone responsible for it. A policy document that sits on the shelf without connection to daily practice has little value during an assessment. Anyone still working out which evidence belongs to which measure will find that in which evidence document must I provide for each security measure, and the question of who should manage that policy within the organization is addressed in who should be responsible within my organisation for a measure.
Basis: Article 21(2) of the NIS2 Directive
The ten measures that serve as the basis for policy documents are set out in Article 21(2) of the NIS2 Directive, with the Cybersecurity Act as its Dutch transposition. Many organizations also use Annex A of ISO/IEC 27001 as a practical framework to make those measures concrete, and the NCSC publishes guidance on how the duty of care is fulfilled in practice.
What this is based on
- Directive (EU) 2022/2555 (NIS2), Article 21(2) — the ten measures
- Cybersecurity Act — the Dutch transposition of NIS2
- ISO/IEC 27001 — Annex A, the control measures
- NCSC — guidance on the security obligation and the reporting obligation
The Regulation itself is available on EUR-Lex. We provide references for each statement; you need not take our word for it.
What you concretely need to do
The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.
View the subscription First the free NIS2 checkThis is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.
Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.