A customer security questionnaire. An ISO 27001 audit. A data-protection authority inquiry. A NIS2 compliance assessment. Each involves different stakeholders and uses distinct terminology. In many SMBs, this process leads to duplication of work by the security lead, who must address the same requirements across different forms.
These documents all describe the same reality: the organization's security practices. If that reality is captured once in a structured way, other documents can be derived from it rather than drafted separately.
The principle: assess once, project everywhere
Komplyo uses NIST CSF 2.0 as its backbone: 106 subcategories, one maturity question each. Every answer is then projected through a mapping table onto ISO 27001, SOC 2 (TSC), GDPR Article 32, NIS2, the CRA, and the ANSSI hygiene guide. We never ask the same question twice under two different labels.
Every generated document cites its sources: which answers, which requirements covered, on what date. That is what makes the deliverables defensible in front of an auditor, not merely presentable.
Assessment deliverables
Governance and steering: global information security policy (ISP), acceptable-use charter, information classification policy, teleworking policy, training and awareness materials, documentation of management reviews and internal audit programme.
Risk and continuity: risk register with pre-modelled scenarios and Excel export, business impact analysis (BIA), business continuity plan, incident response procedures and log.
ISO 27001 and SOC 2: exportable Statement of Applicability (SoA), SOC 2 compliance description, certification roadmap with priorities calculated via risk, urgency, and ease-of-implementation factors, exportable as a presentation.
GDPR: records of processing activities (RoPA), data protection impact assessment (DPIA), data processing agreement (DPA) template, data subject request (DSAR) handling procedure.
NIS2 and CRA: classification memo (essential or important entity, see our guide), Article 21 coverage table, 24-hour and 72-hour notification procedures, CRA technical documentation, and vulnerability disclosure policy.
Over 30 deliverables in total, in French and English, as Word or Excel files. Each document can be modified, as compliance documents evolve with the organization's practices.
Advantage over standard templates
A downloaded template describes a generic organization. Generated documents describe your specific organization: the measures you declared in place appear as such, and gaps appear in the roadmap rather than being hidden. An auditor quickly identifies a generic template. A document consistent with your assessment maintains its relevance.
When your practices evolve, you update the relevant answer, and documents are regenerated. Score history documents progression over time. This traceability satisfies NIS2 requirements for management accountability and ISO 27001 requirements for continual improvement.
Where to start
The free diagnostic (23 questions, around 5 minutes) gives a first score per CSF function and a GDPR snapshot. Answers carry over: moving on to the full assessment picks up where the diagnostic left off.