Resources

Working material, not a glossy brochure.

Every file here came out of real implementation work: checkpoints, evidence, deadlines. Fill it in, take it into the audit, done. No account and no email address — pick your language and download.

Checklists, evidence packs and reporting templates

Workbooks and forms to fill in. Every checkpoint with evidence, status and owner — plus the incident notifications that have to be ready under time pressure.

ISO 27001

ISO/IEC 27001:2022 — Statement of Applicability and Readiness

All 93 Annex A controls with applicability, justification, status and owner. Plus the 28 checkpoints from clauses 4 to 10, each with the evidence an auditor expects and the question they will ask. The dashboard sheet computes readiness per theme.

93 controls · 28 clause checkpoints · 6 worksheets

Available inendefrespt-PTpt-BR
About ISO 27001
NIS2

NIS2 — Article 21 / Section 30 checklist

The ten risk-management measures broken down into 40 checkable points with evidence, status and owner. Includes a calculator for the three reporting deadlines — 24 hours, 72 hours, one month — and a sheet for management approval.

10 measures · 40 checkpoints · deadline calculator

Available inendefrespt-PTpt-BR
About NIS2
NIS2

NIS2 — Incident reporting templates

Three fill-in templates along the statutory deadlines: early warning after 24 hours, incident notification after 72 hours, final report after one month. Each carries the mandatory fields — including the ones usually forgotten in the heat of an incident.

3 notifications · early warning, report, final

Available inendefrespt-PTpt-BR
About NIS2
DORA

DORA — Implementation and evidence checklist

50 requirements from Regulation (EU) 2022/2554, sorted along the seven pillars from ICT risk management to oversight of critical third-party providers. Each row names the article, the expected evidence and the status. Includes the 4-hour, 72-hour and one-month reporting deadlines.

50 requirements · 7 pillars · article references

Available inendefrespt-PTpt-BR
About DORA
Medical practices

Section 75b SGB V — evidence pack for medical practices

The KBV IT security directive broken down into 49 checkpoints across eleven themes. You enter your practice size once and the workbook then shows only the points that apply to you, including annexes 1 to 5. With firewall rule sheet and emergency documentation. German only — the directive is German law.

49 checkpoints · annexes 1 to 5 · by practice size

Available inde

Not available in that language yet. The download is in Deutsch.

Guides and white papers

To read, not to fill in. Context, sequence, pitfalls.

ISO 9001

ISO 9001 in three months

A roadmap from initial assessment to certification audit, split into three one-month phases. What has to be done in which week, which documents the standard actually requires, and where projects typically stall.

Guide · 3 phases · 90 days

Available inendefrespt-PTpt-BR
About ISO 9001
Fundamentals

Sightadel white paper

Why compliance breaks down in spreadsheets as soon as a second framework arrives, and how to run checkpoints, evidence and deadlines so that an audit stops being a project. Includes the model behind Sightadel and an honest account of what software cannot do for you.

White paper · compliance without spreadsheet sprawl

Available inende

Looking for something that is not here?

Tell us which framework is on your desk. When several people ask for the same one, we build it.

Suggest material

Not legal advice. The frameworks in their current version prevail.