NIS2 Document Package
Who it's for: essential entity, important entity
A complete document package for meeting NIS2/KüTS requirements — generated automatically for your company's profile, grounded in the law text in force.
The package includes:
- Cybersecurity Risk Management Policy — describes how your company identifies and manages cyber risks (NIS2 Art. 21).
- Incident Handling Plan — a step-by-step guide for what to do and whom to notify when a security incident happens.
- Business Continuity Plan — how your company keeps operating and recovers after a serious disruption.
- Supply Chain Security Policy — the security requirements you set for your own suppliers and partners.
- Management Responsibility Statement and Training Framework — documents management's responsibility and the staff training plan (NIS2 Art. 20).
- Fill-in wizard in the portal — step by step, with a manual explanation for every field
3 400 EUR
The NIS2 document package is usually ready within an hour of payment — we'll notify you when it's done.
Larger volume, multiple countries or a group? Request a personal quote.
VAT
All prices are net (excluding VAT). Invoices are issued by AIPOS OÜ (Estonia).
- For Estonian clients, Estonian VAT of 24% is added.
- Business clients in another EU country with a valid VAT number (VIES-verified): reverse charge — 0% on the invoice, you account for VAT in your own country (Art. 196 of the VAT Directive). Without a valid VAT number, Estonian VAT of 24% is added.
- For clients outside the EU, no Estonian VAT is added (export of services, 0%).
Recommended next steps
An independent external technical check: DNS, SPF/DKIM/DMARC, TLS configuration, open ports and security headers — results are mapped against the NIS2 Article 21(2) measures and packaged as verifiable evidence you can show to a client or a supervisor. This is not a penetration test or an audit — it is an external check of your publicly visible infrastructure.
- DNS setup — we check whether your domain's nameservers and records are correctly configured and protected against spoofing.
- Email spoofing protection (SPF, DKIM, DMARC) — we check whether an outside party could send emails pretending to be your company.
- Encrypted connection (TLS) — we check whether your website's certificate is valid and the encryption strong enough.
- Open ports — we check which services are reachable from the internet. Open admin interfaces are a common attack path.
- Web server security headers — we check whether the server gives visitors' browsers protective instructions that block common attacks.
- Findings mapped against the Article 21(2) measures — you see which NIS2 requirement each finding relates to, not just a technical result.
- Verifiable evidence report — a document you can show to a client, partner or supervisor as proof of the check performed.
- Ranked remediation recommendations — you know which finding to start with when time or resources are limited.
590 EUR