Komplyo blog
Documentation and governance
The documentation an auditor or a customer asks for comes down to a limited set of policies and evidence, provided they all derive from a single assessment. This section covers the NIST CSF 2.0 framework, writing an information security policy, security budgeting and awareness training. The aim is documentation that gets used internally, not documentation produced for the audit.
Coordinated vulnerability disclosure (CVD): the policy the CRA requires, in practice
Annex I, Part II of Regulation (EU) 2024/2847 requires manufacturers to have a coordinated vulnerability disclosure policy. What the policy must contain, the ISO/IEC 29147 and 30111 standards that structure it, the French framework (L. 2321-4 and L. 2321-4-1) and a proportionate implementation for an SME.
- CRA
- CVD
- Vulnerability management
- NIST CSF
30 compliance documents from a single assessment: how it works
Security policy, ISO 27001 SoA, risk register, business continuity plan, DPIA, records of processing, NIS2 scope memo… How one assessment aligned on NIST CSF 2.0 generates 30+ deliverables ready for your customers and auditors.
- Compliance
- NIST CSF
- ISO 27001
- GDPR
- NIS2
NIST CSF 2.0 for SMEs: the six functions and how to implement them
The NIST Cybersecurity Framework 2.0 organizes cyber risk management into six functions: Govern, Identify, Protect, Detect, Respond, Recover. What each function expects from an SME, category by category, and a 90-day implementation sequence based on the NIST SP 1300 guide.
- NIST CSF
- Compliance
- Cybersecurity
Get the security policy template
An information security policy template in .docx format, structured around NIST CSF 2.0 and ISO 27001. Delivered by email, usable as a documentation baseline.