NIS2
NIS2 information security policy: what it must include
Updated September 27, 2026
Article 21(2)(a) of NIS2 starts the list of minimum measures with policies on risk analysis and information system security. In practice this means one top-level information security policy, approved by management, that the other procedures and technical rules refer to. It does not need to be long. It needs to be specific, approved and kept current.
Approval by the management board
Under NIS2 the management body approves the cybersecurity risk-management measures and oversees their implementation. In Estonia, at least one management board member must be designated as responsible for approving and supervising the measures and must follow regular training. If nobody is designated, the whole board is responsible.
Record the approval in a board resolution that names the responsible board member, the policy version and the date. An unsigned draft on a shared drive is not evidence of approval.
Scope, roles and responsibilities
- Scope: the organisation, services, locations and information systems the policy covers, including systems run by suppliers.
- Management board and the responsible board member: approve the measures, oversee them, accept residual risk and follow training.
- Security lead: runs the security programme, keeps the risk register, reports to the board regularly and leads incident response.
- Staff and contractors: follow the policy, complete training and report suspected incidents immediately.
Link to the risk analysis
NIS2 measures must be based on a risk analysis. The policy should say how risks are identified and rated, who owns the risk register, how often it is reviewed and who may accept residual risk. The measures in the rest of the policy should trace back to the risks they address.
One line per Article 21(2) area
The policy does not have to contain every procedure, but it should state a commitment for each minimum measure and point to the document that implements it. For example:
- (a) Risk analysis and system security: risks are assessed at least yearly and after major changes.
- (b) Incident handling: incidents are detected, assessed and reported to RIA within 24 hours, 72 hours and one month, following the incident procedure.
- (c) Business continuity: critical services, backups, restore tests, disaster recovery and crisis management are covered by a continuity plan.
- (d) Supply chain: suppliers are listed, rated by criticality and bound by security clauses, including incident notification.
- (e) Acquisition, development and maintenance: security requirements for new systems, patch deadlines and a way to receive vulnerability reports.
- (f) Effectiveness: a small set of indicators is reported to the board and the measures are reviewed against them.
- (g) Cyber hygiene and training: all staff are trained at onboarding and at least yearly, and board members follow their own training.
- (h) Cryptography: rules for encrypting devices, data in transit and backups.
- (i) HR security, access control and assets: an asset inventory, least privilege and a joiner-mover-leaver process.
- (j) Authentication and communications: multi-factor authentication, secured communications and an emergency communication channel.
Review cycle and evidence
Review the policy at least once a year and after any significant incident, organisational change or change in the law, and have the board re-approve it. Keep a version history.
Evidence is what makes the policy credible to RIA, auditors and customers: the signed board resolution, review minutes, training records, the risk register and the indicators reported to the board.
Aligning with E-ITS or ISO/IEC 27001 in Estonia
In Estonia the detailed measures follow E-ITS unless you hold a valid ISO/IEC 27001 certificate, and smaller organisations may be allowed to apply basic measures. State in the policy which baseline you apply and why.
If you follow ISO/IEC 27001, the same document can serve as the top-level policy the standard requires. If you follow E-ITS, reference the relevant catalogue modules in the supporting documents. Confirm with RIA which baseline applies to you.
Where to start
Our free NIS2 assessment checks your scope and scores your readiness for each Article 21 area. Subscribers get the information security policy pre-filled from their answers, together with the board resolution naming the responsible board member and the incident reporting procedure, ready for board approval.
Where does your company stand on NIS2?
Free assessment, about 10 minutes, score for every area of the law.
Start the free assessmentThis guide is general information, not legal advice.