---
title: "Free European Compliance Templates"
description: "The Orbiq template library is a collection of free, ungated compliance templates for European regulations such as NIS2, DORA, GDPR, and the Cyber Resilience Act. Every template is versioned, grounded in the underlying legal texts, and available in editable formats — including machine-readable Markdo"
canonical: https://www.orbiqhq.com/templates
html: https://www.orbiqhq.com/templates
publisher: Orbiq GmbH
language: en
---
# Free European Compliance Templates

The Orbiq template library is a collection of free, ungated compliance templates for European regulations such as NIS2, DORA, GDPR, and the Cyber Resilience Act. Every template is versioned, grounded in the underlying legal texts, and available in editable formats — including machine-readable Markdown — so you can adapt it to your own compliance programme.

- [NIS2 Supplier Evidence Request Checklist (Free XLSX & PDF)](/templates/nis2-supplier-evidence-request-checklist.md) - Free NIS2 supplier evidence request checklist (XLSX, PDF, MD): evidence categories, criticality tiers, and cadences mapped to Article 21(2)(d) and 21(3).
- [Free CRA Conformity Self-Assessment (2026) — Annex I, Excel](/templates/cra-conformity-self-assessment.md) - Classify your product, pick the lawful Article 32 route and check every Annex I requirement before the CRA deadlines. Free XLSX, no email gate.
- [Free Pay Transparency Gap Analysis Template (2026) — Excel](/templates/eu-pay-transparency-gap-analysis.md) - Gender pay gap analysis aligned to Directive (EU) 2023/970: Article 9 metrics, category gaps, the 5% joint-assessment trigger. Free XLSX, no email gate.
- [Free NIS2 Management Training Log (2026) — Article 20, Excel](/templates/nis2-management-training-log.md) - Track management-body cybersecurity training for NIS2 Art 20 audits: sessions, hours, renewal dates. Free XLSX, no email gate.
- [Free Subprocessor Register Template (2026) — GDPR, Excel](/templates/gdpr-subprocessor-register.md) - Subprocessor list template with transfer mechanism, data categories, chain visibility and change-notice tracking columns. Free XLSX, no email gate.
- [Free DORA Exit Strategy Template (2026) — Art 28(8), Word](/templates/dora-exit-strategy-plan.md) - Article 28(8) exit strategy and per-provider exit plan: triggers, alternatives, transition, testing log. Free DOCX + PDF + MD, no email gate.
- [Free DORA Register of Information Starter (2026) — Excel](/templates/dora-register-of-information-starter.md) - Human-readable Art 28(3) working register mapped to the ITS fields — maintain year-round, convert at reporting time. Free XLSX, PDF and MD, no email gate.
- [Free DPIA Template (2026) — GDPR Article 35, Word + PDF](/templates/dpia-template.md) - DPIA template with screening questions, Art 35(7) sections, likelihood×severity risk matrix, AI annex and DPO sign-off. Free DOCX, no email gate.
- [Free GDPR Breach Notification Letter Pack (2026) — Word](/templates/gdpr-breach-notification-letter-pack.md) - Art 33 authority notification + Art 34 data-subject letter, ready to adapt inside the 72-hour window. Free DOCX pack with breach log — no email gate.
- [Free GDPR RoPA Template (2026) — Article 30 Register, Excel](/templates/gdpr-ropa-template.md) - Record of Processing Activities template: controller + processor sheets, lawful basis, transfers, retention columns. Free XLSX, PDF and Markdown, no email gate.
- [Free NIS2 Incident Report Templates (2026) — 24h/72h/Final, Word](/templates/nis2-incident-reporting-pack.md) - All three NIS2 Article 23 report stages as ready-to-file forms: 24-hour early warning, 72-hour notification, one-month final report. Free DOCX pack, no email gate.
- [Free Vendor Security Questionnaire Template (2026) — Excel](/templates/eu-vendor-security-questionnaire.md) - Free EU vendor security questionnaire (XLSX, PDF, MD): 67 tiered questions covering GDPR Art 28, NIS2 supply chain, DORA and data residency. No email gate.
- [Free ISO 27001 SoA Template (2026) — All 93 Controls, Excel](/templates/iso-27001-statement-of-applicability-template.md) - Free ISO 27001 Statement of Applicability template with all 93 Annex A controls pre-loaded (XLSX, PDF, MD): applicability, justification, status, evidence.
- [CRA Vulnerability Advisory Template (Free DOCX & PDF)](/templates/cra-vulnerability-advisory-template.md) - Free CRA vulnerability advisory template with CVE/EUVD fields, CVSS v4.0 scoring, subscriber notification email, and a filled sample advisory. Ungated.
- [DORA ICT Provider Evidence Checklist: Free Template (XLSX)](/templates/dora-ict-provider-evidence-checklist.md) - Free DORA ICT provider evidence checklist: RoI-aligned provider register fields, criticality tiers, evidence cadence per tier, and exit-strategy tracker.
- [European Trust Center Readiness Checklist (Free, Scored)](/templates/european-trust-center-readiness-checklist.md) - A free, scored European Trust Center readiness checklist: 58 line items across six stakeholder lanes, mapped to NIS2, DORA, and GDPR evidence expectations.
- [GDPR Subprocessor Change Notice Template (Free DOCX & PDF)](/templates/gdpr-subprocessor-change-notice.md) - Free GDPR subprocessor change notice template with every EDPB-expected field, plus the notice email variant, objection handling, and approval workflow.