DORA NIS2 EU AI Act Notion workspace

GRC EU Platform

DORA (EU 2022/2554) · NIS2 (EU 2022/2555) · EU AI Act (EU 2024/1689)

The documents tell you what to comply with. This workspace proves you are doing it.

8
Databases
40+
Views
27
Country packs
7
Report templates

Organisation licence

€490

one-time · single organisation · internal use

All 8 databases + 40+ views
Executive dashboard with 8 KPIs
7 report templates
Seed data - Meridian Bank scenario
Get Organisation Licence →

Not sure yet? GRC EU Starter Plan — 3 databases, free, no credit card required.

Get free on Notion Marketplace →

8 databases — everything connected

Every database in GRC EU Platform is linked bidirectionally. A risk links to controls. Controls link to requirements, evidence and audit findings. Incidents link to vendors, risks and regulatory timelines.

Compliance requirements
All DORA, NIS2 and EU AI Act obligations pre-mapped. Gap status and priority views per regulation.
🛡
Controls catalogue
Controls linked bidirectionally to requirements, risks, incidents and audit findings.
Risk register
ICT and operational risks with likelihood x impact scoring and treatment tracking.
Incident register
DORA 4h/24h/72h timelines built in. NIS2 24h/72h/1-month timelines. Nothing improvised under pressure.
🏪
Vendor risk register
DORA Art. 30 clause tracking per ICT provider. Criticality classification. Contract expiry calendar.
🤖
AI systems register
EU AI Act classification - High-Risk, Limited, Minimal. Registration status and human oversight tracking.
📋
Audit
Audit plans and findings linked to controls and corrective actions. Owner and deadline tracking.
📄
Evidence and policy library
Policies with version control and review calendar. Evidence tagged by control, requirement and audit finding.

Also included: Executive dashboard with 8 KPIs · 7 report templates · Settings & Organisation Profile · Documentation & User Guide · Seed data — Meridian Bank scenario

Operational in minutes

01

Purchase and receive link

After purchase, you receive a Notion template link. Click it to duplicate the entire workspace to your account.

02

Replace seed data

The workspace ships with a realistic pre-populated scenario (Meridian Bank). Update the Organisation Settings page with your details.

03

Run your first gap assessment

Open the Compliance Requirements database, filter by your regulation, and mark each requirement status. Dashboard updates automatically.

04

Share with your team

Invite colleagues to your Notion workspace. Assign ownership of controls, risks and actions directly in the platform.

Licence details

Organisation Licence — €490

one-time · single organisation

  • All 8 databases + 40+ views
  • Executive dashboard with 8 KPIs
  • 7 report templates
  • Seed data - Meridian Bank scenario
  • Documentation and User Guide (5 sections)
  • 1 NIS2 Country Pack of your choice
  • All v1.x regulatory updates
  • Unlimited internal users
Get Organisation Licence →

All v1.x updates included. Major version upgrades (v2.0+) offered at discounted pricing for existing licence holders. Full licence terms →

Built for

Compliance and risk teams At EU financial entities and NIS2 obligated organisations
In-house compliance officers Managing ongoing DORA and NIS2 programmes
GRC consultants Deploying DORA/NIS2 workspaces across multiple client engagements
Fractional CISOs Operational compliance system per client without managing infrastructure

Frequently asked

Do I need a paid Notion account?

No. Notion's free plan is sufficient for a single user. For team collaboration you may need Notion Plus - check Notion's current plan limits before purchase.

I already have the DORA/NIS2 document systems. Do I need this too?

They serve different purposes. The document systems are what you produce and present to auditors. The GRC Platform is where your team operates the compliance programme on an ongoing basis - tracking live risks, logging incidents, managing vendor contracts, building evidence.

Can I use this for multiple clients?

Yes, with the Consultant Licence. You duplicate the workspace for each client engagement. There is no per-client fee. The Organisation Licence is for internal use only.

What happens when DORA or NIS2 regulations change?

All v1.x updates are included at no additional cost. When DORA RTS/ITS are revised or NIS2 transpositions are updated, we distribute the updated workspace to all licence holders. Major structural changes (v2.0) are offered at discounted upgrade pricing.

Where is my compliance data stored?

Entirely in your own Notion workspace. AltShift has no access to the data you enter into the system.

Is this legal or regulatory advice?

No. AltShift GRC EU Platform is a structured operational workspace. It does not constitute legal or regulatory advice and does not guarantee regulatory compliance.

Pair with document systems

The workspace that runs the compliance programme you documented.

The DORA and NIS2 document systems produce the policies, procedures and audit evidence. The GRC Platform is where your team operates the programme.

Delivered as a Notion workspace — requires an active Notion account. Notion is a trademark of Notion Labs, Inc. AltShift is not affiliated with or endorsed by Notion Labs, Inc.