Folderit can help an organisation control the documents and evidence used in its NIS2 programme: policies, management approvals, supplier reviews, training records and incident documentation. A DMS is one part of that programme; installing it does not establish NIS2 compliance or replace technical security operations.

This guide focuses on configuring that evidence repository. For the broader planning view, see the NIS2 compliance checklist.

Confirm scope and the applicable national rules

NIS2 is Directive (EU) 2022/2555. It generally covers medium and large entities in specified sectors, with exceptions that can bring smaller entities into scope. Confirm your entity, sector, jurisdiction and competent authority before defining its obligations. The European Commission’s NIS2 overview and national implementation pages provide starting points.

Reviewed September 2026: do not treat the original October 2024 transposition deadline as a new organisation-wide deadline. The Commission’s current overview also describes proposed 2026 amendments; a proposal is not itself an enacted change. Verify current national requirements for your situation.

1. Build an evidence structure with named owners

Create a controlled folder structure for governance, risk assessment, incident handling, continuity, supplier assurance, access reviews and staff awareness. Use it to store the actual evidence produced by those processes, rather than treating an empty folder as a completed control.

Add a small metadata template: control reference, evidence owner, document status, approval date and next review date. Define each field and use controlled lists where appropriate. Folderit’s folder templates can apply consistent fields to new resources and mark missing required values.

2. Control access to sensitive evidence

Separate general staff policies from restricted incident files, supplier findings and privileged-access reviews. Share resources with the relevant users or groups and choose the appropriate permission level. Test with a user who should have access and one who should not.

Use Security Policy settings to enforce two-factor authentication and, where suitable, IP restrictions. Review access when staff change roles or leave. Configuration choices should follow your security policy and recovery needs.

3. Keep approvals and acknowledgements with the controlled version

Article 20 places governance responsibilities on management bodies, including approval and oversight of cybersecurity risk-management measures. Record the decision, approver, date and relevant document version; see the NIS2 Directive.

Use approval workflows for review and acknowledgement workflows when staff must confirm receipt. An acknowledgement records a response; it does not by itself prove that a person understood the policy or completed effective training.

Maintain earlier versions when the audit question is “Which policy applied at the time?” Define who can issue a replacement and how the team identifies the current approved version.

4. Retain evidence from the actual security processes

ProcessUseful records to organiseWork that remains outside document storage
Risk managementRisk register, treatment decisions and owners.Assessing systems, threats and the effectiveness of controls.
Continuity and recoveryRecovery plans, exercise records and corrective actions.Operating backups and testing system restoration.
Supplier assuranceSupplier assessments, relevant terms and review decisions.Evaluating supplier risk and following up findings.
Access managementAccess-review approvals and removal evidence.Managing identities and privileges across all systems.
Incident responseChronology, decisions, submitted reports and receipts.Detection, containment, investigation and authority notification.

For entities covered by Implementing Regulation (EU) 2024/2690, ENISA’s technical implementation guidance can help structure the relevant control evidence. Check applicability before using it as your assessment framework.

5. Prepare incident documentation before an incident

Under the Directive’s general Article 23 sequence, significant incidents require an early warning within 24 hours of awareness, an incident notification within 72 hours, and a final report within one month of that notification. Ongoing incidents and trust-service providers have specific provisions. Check national implementation and the authority’s reporting procedure. Source: Article 23.

Prepare a restricted incident template with awareness time, responsible contact, affected services, initial assessment, actions, report deadlines and submission receipts. Record time zones explicitly. Keep an alternative way to reach the response plan if the normal repository is unavailable.

Folderit workflows and document notifications can support coordination. They should not be described as automatic cyberattack detection or automatic submission to a regulator. Assign a responsible person to the reporting process and test it in an exercise.

6. Review the document audit trail and retention rules

Folderit records document and folder activities in audit trails. The global audit log supports filtering and export. Use these records to investigate document actions and support evidence reviews; they are not a substitute for network, endpoint or application-security monitoring.

Assign review dates to policies and evidence. Apply an approved retention policy, preserve relevant records when an investigation requires it, and validate exceptions before any disposal automation runs.

Test the repository as a reviewer would

Ask a colleague to retrieve one approved policy, its earlier version, the relevant acknowledgement record and a recent access-review decision. Check who can see them, whether their dates and owners are clear, and whether the evidence demonstrates the action claimed. Fix gaps in the underlying process as well as in the filing structure.

For product configuration, use the linked Folderit knowledge-base instructions. For legal scope and reporting duties, use your applicable national rules and competent authority’s guidance.