Komplyo
Self-assessment security & compliance · SMEs & scale-ups

Your cyber maturity, assessed once, projected everywhere. Built on NIST CSF 2.0.

Assess your security and compliance posture on NIST CSF 2.0 and generate 30+ audit-ready deliverables (policies, ISO 27001 SoA, DPIA, GDPR register, incident response pack, vendor kit, prioritised action plan). Self-service, at your own pace.

23 questions · ~5 min · No credit card

Compliance dashboard

Your posture, tracked continuously

92%
  • GDPR & records of processingCompliant
  • Security policiesUp to date
  • Customer security questionnairesCovered
  • NIS2 · scope analysisIn progress
  • Cyber Resilience Act · product readinessIn progress
NIST CSF 2.0 assessment points
106
frameworks projected: ISO 27001, SOC 2, GDPR, NIS2, CRA, ANSSI
6
generated deliverables, auditor-ready
30+
to a first score with the free diagnostic
5 min

What changes with Komplyo

Turn growing obligations into a clear advantage.

GDPR, security questionnaires from your enterprise customers, NIS2 widening its scope, the AI Act. Obligations keep growing. Komplyo turns them into a documented posture, up-to-date policies and a prioritised roadmap.

01

Security, run with a method

Your security representative (founder, tech lead or part-time référent) gets a structured method and ready-made deliverables.

02

Documented customer reviews

Security policies, DPAs and completed questionnaires are generated on demand to answer your customers' compliance checks.

03

Always up to date

As regulations evolve, your assessment, policies and roadmap follow. You keep a current, defensible posture without chasing every change.

How it works

A clear framework, in three steps.

From diagnostic to continuous oversight, self-service: a single tool, a single method, your deliverables at hand.

01

Diagnostic

Answer 23 questions about your security and GDPR posture. You get a teaser score by NIST CSF 2.0 function and your GDPR status, free, in 5 minutes.

02

Full assessment

Complete the assessment (106 CSF 2.0 points + GDPR). Activate the lenses that match your goal (ISO 27001, SOC 2, NIS2, CRA or the ANSSI hygiene guide): your answers are projected automatically, no question is ever asked twice.

03

Deliverables & follow-up

Generate 30+ documents (policies, ISO 27001 SoA, DPIA, GDPR registers, incident response pack, vendor kit…) in .docx, .xlsx and .pptx from your library, and prioritise your remaining actions. Resume anytime: your score tracks your progress over time.

The deliverables library

30+ documents, generated from a single assessment.

Every answer feeds all your documents: policies, registers, SoA, GDPR templates, NIS2 and CRA notes, executive material. They are personalised with your scores, bilingual FR/EN, and regenerable whenever your posture changes.

Policies & charters

.docx
  • Global security policy + 12 domain policies
  • Signable acceptable-use charter
  • Information classification
  • Remote work & BYOD
  • Vulnerability disclosure (CVD) + security.txt

ISO 27001

.docx
  • Statement of Applicability (SoA), FR/EN
  • Risk treatment plan
  • Internal audit programme & report
  • Management review minutes
  • CSF organisational profile (current vs target)

GDPR

.docx · .xlsx
  • Records of processing (Art. 30)
  • DPIA template (CNIL methodology)
  • DPA & processor security annex (Art. 28)
  • Data-subject rights templates (Art. 15 to 22)
  • Breach register (Art. 33.5)

NIS2 & CRA

.docx · .xlsx
  • NIS2 entity self-classification + obligations note
  • ANSSI notification templates (24h / 72h / final report)
  • Notifiable incident register
  • CRA technical file (Annex VII) + EU declaration

SOC 2

.docx · .xlsx
  • System description (Description Criteria)
  • TSC controls matrix (38 criteria)
  • Readiness per CC / A / C / PI / P criterion

Steering & operations

.pptx · .xlsx · .docx
  • Board-ready roadmap deck (executive summary included)
  • Scored risk register (heat map)
  • Awareness kit (17 slides, FR/EN)
  • TPRM vendor kit with automatic scoring
  • Asset inventory · Business continuity plan + BIA

All documents live in your library, with an "up to date / regenerate" status the moment your answers change.

NIS2 · Loi résilience

Are you ready for NIS2?

NIS2 widens its scope to thousands of EU SMEs and scale-ups, with management accountability and 24h/72h incident-notification duties. Measure your readiness in 5 minutes built on the same NIST CSF 2.0 backbone we project onto NIS2.

  • Management accountability and security governance
  • Risk-management measures (NIS2 Art. 21)
  • 24h/72h incident notification to the authority
  • Supply-chain and supplier security

CRA · Cyber Resilience Act

Is your product ready for the Cyber Resilience Act?

The Cyber Resilience Act sets EU-wide cybersecurity obligations for products with digital elements (secure-by-design, vulnerability handling and incident reporting, enforced through CE marking). Gauge your product readiness in 5 minutes built on the same NIST CSF 2.0 backbone we project onto the CRA.

  • Secure-by-design product properties (Annex I)
  • Vulnerability handling and security updates throughout support
  • CE marking, Declaration of Conformity and technical file
  • 24h early-warning reporting of exploited vulnerabilities (ENISA)

The product in action

One platform, every framework.

From the free diagnostic to the executive dashboard, from the ISO 27001 SoA to the GDPR register: everything is generated from a single NIST CSF 2.0 assessment.

Komplyo prioritised action plan with risk, urgency and effort scores
Editable ISO 27001 Statement of Applicability in Komplyo
GDPR conformity by article with compliance status
16-scenario risk register with scoring

One plan, two cadences

The Komplyo plan.

The full product, one price: full assessment, ISO 27001 / SOC 2 / NIS2 / CRA / ANSSI lenses, 30+ generated deliverables (policies, SoA, DPIA, registers, kits), prioritised roadmap and time-series follow-up.

KomplyoThe single plan

The Komplyo plan

The full assessment, defensible documents and follow-up, without a firm.

€99 excl. VAT / month or €999 excl. VAT / year (2 months free)

  • Free diagnostic: 23 questions, 5 min, no commitment
  • Full assessment: 106 NIST CSF 2.0 points + GDPR
  • ISO 27001, SOC 2, NIS2, CRA and ANSSI hygiene-guide lenses, no question is asked twice
  • 30+ generated deliverables: policies, IT charter, ISO 27001 SoA, DPIA, DPA, GDPR registers, incident response pack…
  • Certification workspaces (editable SoA, SOC 2 system description, TSC matrix)
  • NIS2 self-classification and CRA technical file
  • TPRM vendor kit + awareness kit (FR/EN)
  • Prioritised roadmap + scored risk register, .xlsx / .pptx exports
  • Document library with “up to date / regenerate” status
  • Time-series score follow-up (maintenance)
  • Document updates on every framework version change

VAT applies per country of residence. Secure payment via Stripe. Monthly: no commitment, cancel anytime. Annual: pre-paid, 2 months free.

Get started now

A ready-to-use security policy, on us.

A generic template, structured around the baseline expectations of a customer or an auditor, that you can use right away as a foundation.

A generic template only protects you halfway. Adapting your policies to your actual risks creates value. Your diagnostic identifies your gaps, the assessment refines them, and the generated policies reuse your scores. The template is the starting point. Komplyo structures the rest.

Security policy template

.docx format · Delivered by email

No spam. Unsubscribe in one click.

Why Komplyo

Recognised frameworks, defensible deliverables.

Assess once, project everywhere

Your NIST CSF 2.0 answers are projected automatically onto ISO 27001, SOC 2, GDPR Art. 32, NIS2, the CRA and the ANSSI hygiene guide through an official mapping table. No question is asked twice; the framework version is pinned per assessment.

Pragmatic, SME-sized

The roadmap prioritises actions by risk, urgency and ease of implementation.

Auditor-ready deliverables

30+ documents (policies, ISO 27001 SoA, DPIA, GDPR registers, incident response pack, TPRM and awareness kits), each generated from your assessment, with pinned version and timestamp, gathered in a library with an “up to date / regenerate” status.

  • Built on NIST CSF 2.0
  • ISO 27001 · SOC 2 · GDPR projections
  • NIS2 · CRA · ANSSI hygiene-guide lenses
  • Framework version pinned per assessment

Frequently asked

What we get asked most.

How does the free diagnostic work?

23 questions, ~5 minutes, no commitment. You get a teaser score by NIST CSF 2.0 function and your GDPR status. Your answers are kept for 7 days: by creating an account, they carry over to the full assessment.

Do I need an account to start?

No: the diagnostic is open and free, no credit card required. Creating an account unlocks the dashboard; the full assessment, certification lenses and document generation are part of the Komplyo plan (€99/month or €999/year excl. VAT, cancel anytime).

What documents does Komplyo generate?

30+ deliverables, generated from your answers: a global security policy and 12 domain policies, an IT charter, the ISO 27001 SoA, a risk treatment plan, an internal audit programme, a management review record, the Art. 30 records of processing, a DPIA, a DPA, data-subject-rights templates, an incident response pack, a TPRM vendor kit, an awareness kit, a prioritised roadmap and a risk register, in .docx, .xlsx and .pptx, bilingual FR/EN, gathered in your document library.

Do you cover NIS2, the CRA and the ANSSI hygiene guide?

Yes. Your NIST CSF 2.0 answers are projected onto NIS2 (with essential/important entity self-classification and ANSSI notification templates), onto the Cyber Resilience Act (Annex VII technical file, CVD policy) and onto the 42 measures of the ANSSI hygiene guide. Two dedicated free diagnostics exist: NIS2 and CRA.

Do my diagnostic answers carry over to the full assessment?

Yes: the 23 diagnostic questions are a subset of the full assessment. By creating an account, your answers carry over automatically, and only the remaining questions appear (43 on the best-practices path, or the full set on the certification path).

Is my data kept in Europe?

Yes. The database is hosted on Neon in Frankfurt (Germany), the application on Netlify, and transactional emails go through Resend. No data leaves the EU; your framework version is pinned per assessment for reproducibility.

Ready to see where you stand on compliance?

Start the free diagnostic: 23 questions, ~5 minutes, and you leave with a teaser score by NIST CSF 2.0 function and your GDPR status. No commitment.