Company-Specific NIS2 Cybersecurity Risk Management Policy
Who it's for: essential entity, important entity
Your company's NIS2 risk management policy — generated from your country, sector and company profile on the basis of your country's transposing law, with verbatim legal citations, in your language. Policies on risk analysis and information system security are the first measure in the NIS2 Article 21(2) list (point (a)) — the document the rest of your NIS2 documentation builds on. One-time payment, no subscription.
The package includes:
- Company-specific content: country, sector, size and your answers — not a generic template
- Based on your country's enacted transposing law, verbatim citations with sources
- The same quality gate as the full package — same rigour, same control chain
- In your language, downloadable from the portal
- Comes with an account and a living documentation profile: what exists, what is missing, when to renew
- The same document is included in the full documentation package
19 EUR
Larger volume, multiple countries or a group? Request a personal quote.
VAT
All prices are net (excluding VAT). Invoices are issued by AIPOS OÜ (Estonia).
- For Estonian clients, Estonian VAT of 24% is added.
- Business clients in another EU country with a valid VAT number (VIES-verified): reverse charge — 0% on the invoice, you account for VAT in your own country (Art. 196 of the VAT Directive). Without a valid VAT number, Estonian VAT of 24% is added.
- For clients outside the EU, no Estonian VAT is added (export of services, 0%).
Recommended next steps
A complete document package for meeting the requirements of NIS2 and your country's national transposition law — generated automatically for your company's profile, grounded in the law text in force.
- Cybersecurity Risk Management Policy — describes how your company identifies and manages cyber risks (NIS2 Art. 21).
- Incident Handling Plan — a step-by-step guide for what to do and whom to notify when a security incident happens.
- Business Continuity Plan — how your company keeps operating and recovers after a serious disruption.
- Supply Chain Security Policy — the security requirements you set for your own suppliers and partners.
- Management Responsibility Statement and Training Framework — documents management's responsibility and the staff training plan (NIS2 Art. 20).
- Fill-in assistant in the portal — step by step, with a manual explanation for every field
3 400 EUR