Skip to content

Templates

Field-tested templates for BAUER GROUP NIS2 compliance. All templates are starting points and should be adapted to the specific use case.

TemplatePurposeNIS2 Reference
Risk RegisterRecording and assessing all information security risks§30(2) No. 1
§32 Incident ReportStructured template for early warning, 72h update and final report§30(2) No. 2 + §32
Disaster Recovery Test ProtocolDocumentation of regular DR tests§30(2) No. 3
Vendor AssessmentSecurity assessment of service providers and suppliers§30(2) No. 4
Cyber Hygiene Training RecordAttendance record for mandatory training§30(2) No. 7
Management ApprovalFormal §38 approval of risk management measures§38 BSIG
Lessons Learned ProtocolPost-incident review§30(2) No. 6

Usage Notes

  • Audit readiness: All completed templates are stored centrally (document management system) and produced on request during BSI audits.
  • Retention period: At least 3 years; for §32 reports at least 5 years.
  • Language: Templates are completed in the working language of the respective site; a German translation is attached if needed.
  • Updates: Templates are reviewed at least annually or whenever the underlying measure changes.

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT