Resources Primary audience: Cross-cutting
Published onAugust 19, 2026
Every template cited on this site, in one place. Each links to the page that explains it and
gives its detailed content.
Qualification and classification
Template
Content
Reference page
PDE qualification sheet
Nature of the product, connection, remote data processing, commercial character, status, signatories
Scope
Exclusion sheet
Sectoral text relied on, justification, signatories
Exclusions
Classification sheet
Actual functionality, annexes examined, class retained, assessment route
Classification method
Portfolio classification register
Consolidated view, annual review
Same
Conformity and market entry
Template
Content
Reference page
Technical documentation template
Eight-section structure per Annex VII
Technical documentation
File completeness checklist
Thirteen points to tick
Same
EU declaration of conformity
Annex V template, French and English
Declaration
Simplified declaration
Annex VI template
Same
Cybersecurity notice
Ten-section Annex II template
User information
Legal checklist
Fifteen points, printable, signable
Checklist
Technical checklist
Fifteen points, printable
Technical checklist
Conformity review record
Structure and signatures
Internal process
Vulnerabilities and reporting
Template
Content
Reference page
Coordinated disclosure policy
Eleven-section structure
Disclosure policy
security.txt file
RFC 9116 template
Same
Active-exploitation qualification sheet
To pass to Legal within two hours
24-hour procedure
Early warning template (24 h)
Minimum fields
Same
Notification template (72 h)
Minimum fields
Same
Final report template (14 d / 1 month)
Minimum fields
Same
Crisis response card
A4 format, for display
Same
Reporting register
Decisions, reasoning, acknowledgements
Reporting duties
Template
Content
Reference page
SBOM quality policy
Format, depth, thresholds, waivers
Quality
Tooling sheet per product family
Tools, commands, scope, exclusions
Generating SBOMs
Annotated SBOM examples
CycloneDX and SPDX
Formats
VEX example
Statuses and justifications
VEX
Tool evaluation grid
Weighted criteria and protocol
Selection criteria
Intellectual property
Template
Content
Reference page
Licence policy
Three lists by context of use
Intellectual property
Exception register
Component, licence, conditions, expiry
Same
Open source component diligence grid
Nine criteria
Integrating open source
Steward self-qualification grid
Six questions
Steward
Open source contribution policy
Framework for employee contributions
Individual developer
Contracts
Template
Content
Reference page
Supplier clause set
SBOM, deadlines, support, compliance, reversibility, liability
Contract clauses
Customer clauses
Support, SBOM, notification, limitation
Same
Governance
Template
Content
Reference page
RACI matrix
Twenty-two activities, eight roles
RACI
Legal ↔ Cyber interface contract
Cross deliverables, deadlines, vocabulary
Interface
Support period register
Commitments and limiting components
Support period
Compliance risk register
Risks, measures, named acceptances
Exposure
Leadership dashboard
Four blocks, one page
Metrics
Back-planning
Six waves and their dependencies
Roadmap
How to use them
These templates are structures , not documents to sign as they stand. Each must be adapted to
your organisation, reviewed by the owning function, then versioned . A template reused without
adaptation produces a generic document, which is exactly what a market surveillance authority
spots first.