Guides & checklists
Guides & checklists
What the authority will ask you.
Why it helps
From regulation to action.
Regulation and best practice are only useful once they become steps. My guides translate obligations into what to actually do, in what order and with what priority: what to handle now, what can wait, and how to tell when you have done enough. Not a generic summary of the law, but practical, plain-language guidance you can act on.
They are written for the people who have to act on them — boards, leadership and the teams doing the work — not to fill a compliance shelf. Each guide starts from the decision or obligation in front of you and ends in verifiable steps, with the limits stated where your specific situation needs a dedicated assessment.
What's inside
NIS2 board briefing
What directors need to know, in a single document.OpenNIS2 operational checklist
The minimum controls the authority expects to find.OpenDORA readiness checklist
The essentials for regulated financial entities.OpenIncident-reporting checklist
Be ready to report within the deadlines.OpenThe first 48 hours of an incident
What to do — and not do — when decisions matter most.OpenCyber due diligence: what to ask in the data room
The requests that surface risk before signing.Open
More from Resources
Keep exploring
Guides, checklists and tools built from the same obligations and decisions. Pick the one closest to your situation — they are made to be used, not filed.