NEWVenvera speaks your language: the full platform, in English, German, Spanish and Bulgarian.See what’s new →
Incident Response Plan Template (Free Excel, 2026)
Resources

Incident Response Plan Template (Free Excel, 2026)

·Alexander Sverdlov

This free incident response plan template gives EU compliance leads and CISOs a single place to see every reporting clock that fires when something goes wrong. Built as an Excel workbook, the incident response plan template pairs a deadlines reference sheet with a working incident log, so you record detection and awareness times the moment an event surfaces. It covers the four regimes that most often overlap in practice: GDPR, NIS2, DORA and the EU AI Act. Whether you are a security lead drafting a first runbook or a compliance manager tightening an existing one, this gives you a defensible starting point instead of a blank page. You can download it below, fill in your own contacts and thresholds, and keep it beside your incident bridge. Confirm which regimes apply to your organisation before you rely on any single clock.

Free download

Get the Incident Response and Notification Template

A notification-deadline reference for GDPR, NIS2, DORA and the EU AI Act, plus an incident log. Because most clocks run from awareness.

By downloading, you agree to receive occasional relevant emails from Venvera. Unsubscribe anytime. See our Privacy Policy. This template is a starting point, not legal advice.

One evidence library covering incidents and overlapping frameworks
One evidence library, mapped across incidents and the frameworks it shares controls with.

What the Incident Response and Notification Template covers

The file is deliberately small and practical. It has two working parts that do the job a real incident needs.

A deadlines reference sheet. One row per obligation, so you never have to hunt through legislation mid-incident. It lays out GDPR Article 33 (notify the supervisory authority no later than 72 hours) and Article 34 (notify affected individuals where the breach is likely to result in a high risk); NIS2 Article 23 (early warning within 24 hours, notification within 72 hours, final report within one month); DORA (initial notification within 4 hours of classifying an incident as major and no later than 24 hours from awareness, an intermediate report within 72 hours, and a final report within one month); and EU AI Act Article 73 (serious incidents within 15 days, 10 days if a person has died, 2 days for a widespread infringement or serious disruption to critical infrastructure).

An incident log. Columns for the incident reference, a short description, the detection time and the awareness time as separate fields, whether it has been classified as major or serious, the regimes engaged, the calculated deadline for each notification, the owner, and links to your evidence. The awareness field is separate on purpose, because that is the timestamp most of these clocks actually run from.

Mapping a incidents control across other frameworks
A control entered once maps across incidents and every framework it also satisfies.

incident response the honest way: what actually matters

The single most important thing to understand is when each clock starts. Most of these regimes run their deadlines from the moment you become aware of an incident, not the moment a tool first detects it, so the awareness timestamp is the one auditors scrutinise.

Under GDPR, Article 33 requires you to notify the supervisory authority no later than 72 hours after becoming aware of a personal data breach. Where the breach is likely to result in a high risk to individuals, Article 34 adds a duty to inform those individuals.

NIS2 splits the obligation into stages under Article 23: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month.

DORA is the tightest at the front end. For a major ICT-related incident, the initial notification is due within 4 hours of classifying the incident as major, and in any case no later than 24 hours from awareness. An intermediate report follows within 72 hours, and the final report within one month.

The EU AI Act, Article 73, covers serious incidents involving high-risk AI systems. The outer limit is 15 days, tightening to 10 days if a person has died, and 2 days for a widespread infringement or a serious disruption to critical infrastructure.

Two closing points. First, these regimes overlap: one event can trigger several at once, which is why a single view of every clock beats four separate runbooks. Second, confirm which regimes actually apply to your organisation before you rely on any deadline here.

incidents control health tracked in one dashboard
Track incidents readiness continuously instead of in a point-in-time spreadsheet.

How to use the Incident Response and Notification Template

  1. Download the workbook and save a copy for each entity or environment you are responsible for.
  2. On the deadlines reference sheet, add your own supervisory authority and regulator contact details next to each regime.
  3. Confirm which regimes apply to you, and mark the rows that do not so nobody chases a clock that never started.
  4. When an incident occurs, open the incident log and record the detection time and, critically, the awareness time straight away.
  5. Classify the incident, read off which clocks are now running, and assign a named owner to each notification.
  6. Keep the log as your evidence trail: what you sent, to whom, and exactly when.
A live incidents posture for the board
A live posture keeps the incidents picture current for leadership and auditors.

Do this automatically in Venvera

A spreadsheet is a good starting point, but it does not update itself. When guidance shifts or a new obligation lands, someone has to remember to edit the file, and someone else has to trust that they did. In Venvera the same work stays current: the notification clocks live in the product, incidents route to the right regime, and the evidence you capture once is reused across frameworks instead of re-entered. If NIS2 is your first priority, start with the NIS2 framework page and the NIS2 compliance checklist, then layer GDPR, DORA and the EU AI Act on top without duplicating the effort. Plans start from EUR 399/month.

Frequently Asked Questions

Does the reporting clock start at detection or at awareness?

For most of the EU regimes covered here, it starts at awareness, not detection. That is why the template logs both timestamps separately. The gap between them is often where a response programme quietly loses hours it cannot get back.

Can one incident really trigger more than one regulator?

Yes. A single breach can engage GDPR, NIS2, DORA and the EU AI Act at the same time, each with its own deadline. The deadlines reference sheet exists so you can see every clock in one place, rather than discovering a missed one after the fact.

Is this incident response plan template really free?

Yes. The Excel workbook downloads through the form on this page at no cost, and you can adapt it for internal use. Fill in your own contacts, thresholds and escalation paths before you rely on it.

What is the shortest deadline I need to worry about?

Among the regimes here, DORA is tightest at the front end, with an initial major-incident notification due within 4 hours of classification. The EU AI Act can require notice within 2 days for a widespread infringement or a serious disruption to critical infrastructure. Always confirm which regimes apply to you.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

RELATED POSTS