One workbook per pillar.
Each is a self-contained Excel assessment, audit & control tool. Buy a single pillar, or take all five.
1
Pillar 1
Articles 5–16
ICT Risk Management
★★★★★
4.8
(34 reviews)
Assess, audit and control the full ICT risk management framework — governance, the risk lifecycle, asset management, protection, detection and continuity.
Inside the workbook
- Article-by-article control checklist (Art. 5–16)
- ICT risk maturity scorecard (5 levels)
- Governance, roles & risk-appetite register
- Asset & dependency mapping sheet
- Gap register with owners & deadlines
- Evidence tracker & management dashboard
Not sure yet? Run the free Gap Analysis first →
“The Article 5-16 control checklist mapped straight onto our framework, and we closed our governance gaps in under a week.”
— Markus T., Head of ICT Risk
2
Pillar 2
Articles 17–23
ICT Incident Management & Reporting
★★★★★
4.9
(27 reviews)
Classify incidents, drive the regulatory reporting clock and control the whole detection-to-final-report workflow.
Inside the workbook
- Incident classification calculator (RTS criteria)
- 4h / 72h / 1-month reporting timeline tracker
- Article-by-article control checklist (Art. 17–23)
- Incident log & register
- Gap register with owners & deadlines
- Evidence tracker & reporting dashboard
Not sure yet? Run the free ICT Incident Analyzer first →
“The 4h / 72h / 1-month timeline tracker is exactly what our incident team needed to stay on the reporting clock.”
— Elise R., Operational Resilience Manager
3
Pillar 3
Articles 24–27
Digital Operational Resilience Testing
★★★★★
4.7
(19 reviews)
Plan the testing programme, score TLPT readiness and control every test from vulnerability scan to threat-led penetration test.
Inside the workbook
- Testing programme planner & calendar
- TLPT readiness scorecard (Art. 26–27)
- Article-by-article control checklist (Art. 24–27)
- Test inventory & scope register
- Findings & remediation register
- Evidence tracker & testing dashboard
Not sure yet? Run the free TLPT Readiness Checker first →
“The TLPT readiness scorecard saved us weeks of scoping before we engaged our TIBER provider.”
— David K., Security Testing Lead
4
Pillar 4
Articles 28–44
ICT Third-Party Risk Management
★★★★★
4.9
(42 reviews)
Build the Register of Information, audit Article 30 contracts and control concentration risk across the whole third-party estate.
Inside the workbook
- Register of Information template (ITS-aligned)
- Article 30 contract clause checklist
- Concentration risk & CTPP analysis
- Article-by-article control checklist (Art. 28–44)
- Sub-outsourcing & exit-strategy tracker
- Gap register & third-party dashboard
Not sure yet? Run the free Third-Party Risk Scorer first →
“The Register of Information template is ITS-aligned, and our auditors accepted it without a single change.”
— Sofia M., Third-Party Risk Officer
5
Pillar 5
Article 45
Information & Intelligence Sharing
★★★★★
4.8
(16 reviews)
Assess and control participation in cyber threat-intelligence sharing arrangements — scope, safeguards and governance.
Inside the workbook
- Article-by-article control checklist (Art. 45)
- Participation readiness scorecard (5 levels)
- Membership register — CA notification tracker (Art. 45(3))
- TLP handling map (Traffic Light Protocol v2.0)
- 10 sharing KRIs with L3 targets
- Gap register, evidence tracker & dashboard
Not sure yet? Run the free Gap Analysis first →
“It made Article 45 participation governable: the TLP handling map and the ten KRIs are board-ready out of the box.”
— Thomas B., CISO