Komplyo
Features

Everything you need to run security and compliance.

Komplyo turns a single NIST CSF 2.0 assessment into an executive dashboard, projections onto six frameworks, 30+ audit-ready documents and a prioritised action plan. Assess once, project everywhere.

The journey

A logical journey, from the first question to the audit.

Komplyo guides you through four steps: run the free diagnostic, choose your depth, activate the frameworks you need, then steer and prove your compliance.

  1. 1

    Free diagnostic

    23 questions, ~5 minutes. A score per CSF function and a GDPR status, no credit card.

  2. 2

    Choose your path

    Best practices (light) to build hygiene, or certification (full) to target ISO 27001 / SOC 2.

  3. 3

    Activate your lenses

    ISO 27001, SOC 2, NIS2, CRA, ANSSI: activated by objective, never by score. GDPR is a parallel axis, on by default.

  4. 4

    Steer and prove

    Prioritized action plan, risk register, 30+ generated documents and vendor questionnaires.

Step 1

Start with the free diagnostic.

23 questions covering the six NIST CSF 2.0 functions and GDPR. You immediately get a score per function and a privacy status. Your answers carry over into the full assessment.

  • 23 questions, about 5 minutes, no credit card
  • Instant score per CSF 2.0 function + GDPR status
  • Your answers carry over into the full assessment, nothing to re-enter
Step 2

Two depths, one assessment.

After signing up, pick your target. You can switch between them at any time without losing your answers.

Best practices (light)

The NIST CSF 2.0 small-business subset (~43 subcategories), designed to build solid security hygiene with a small team.

  • Step-by-step guidance per function: understand, assess, prioritize, communicate
  • 3-state markers (done / partial / to do) per control
  • Essential deliverables: IT charter, awareness kit, light TPRM
Komplyo dashboard in light depth (SME best practices)

Certification (full)

All 106 CSF 2.0 subcategories plus the GDPR axis plus your lens deltas. The defensible base to target ISO 27001 or SOC 2.

  • Tier 1 to 4 maturity per subcategory, capping by critical items
  • Persisted score history (audit defensibility)
  • Unlocks the certification workspaces and 30+ deliverables
Komplyo dashboard in full depth (certification path)

The light ↔ full switch is reversible and non-destructive: your answers are preserved.

Per-function steering, in both depths

Each CSF function (Govern, Identify, Protect, Detect, Respond, Recover) has its own page: actions to take on the left, guides and resources on the right.

CSF function page in light depth: actions and resources
CSF function page in full depth: controls and maturity
Step 3

Activate frameworks when you're ready.

The ISO 27001, SOC 2, NIS2, CRA and ANSSI lenses plug into the same assessment. Every CSF answer projects automatically through the mapping table. You only activate a lens when the objective exists, never because a score demands it.

  • Activation by objective: enterprise sales, certification, legal obligation
  • Two readiness readings: derived from your CSF answers, then deepened with the delta questions
  • GDPR stays a parallel axis, on by default and deactivable
ISO 27001 workspace: derived and comprehensive readiness

Assess once, project everywhere

Your CSF 2.0 answers automatically feed ISO 27001, SOC 2 (TSC), GDPR Article 32, NIS2, the CRA and the ANSSI hygiene guide through the mappings table. We never ask the same question twice.

  • One implemented control → N compliances (coverage badges)
  • Six lenses: ISO 27001, SOC 2, GDPR, NIS2, CRA, ANSSI hygiene guide (42 measures)
  • Lenses activated by objective, never by score
  • Derived then comprehensive readiness per framework
SOC 2 workspace: readiness projected from the CSF 2.0 assessment

ISO 27001 Statement of Applicability & SOC 2 workspace

A dedicated certification workspace: per-control readiness, inline gap answering, and an editable, exportable ISO 27001 SoA. SOC 2 covers the CC / A / C / PI / P criteria.

  • Editable, exportable ISO 27001 SoA
  • Coverage of all 93 Annex A controls + ISMS clauses
  • SOC 2 system description (DC 200) and TSC matrix (.xlsx)
  • Inline gap answering, persisted on every entry
ISO 27001 Statement of Applicability (SoA) editor in Komplyo

NIS2 scope analysis

Determine whether NIS2 applies to your organisation (essential or important entity) and what it implies, from the same assessment answers. The Cyber Resilience Act is covered by the same mechanics.

  • NIS2 entity self-classification (essential / important) with an explanatory note
  • ANSSI incident notification templates (24 h / 72 h / final report)
  • CRA technical file (Annex VII) and CVD policy + security.txt
  • Two dedicated free diagnostics: NIS2 and CRA
NIS2 scope and applicability analysis

GDPR conformity by article & Art. 30 register

A parallel privacy axis (not a maturity score): compliance status per article, gaps to close, and a record of processing activities (Art. 30).

  • Compliant / partial / missing / not-applicable per article
  • Structured records of processing (Art. 30)
  • Generated DPIA, processor DPA and data-subject-rights templates
  • GDPR axis toggle per assessment
Record of processing activities (Art. 30) in Komplyo
Step 4

Steer, fix, prove.

Once the assessment is in place, Komplyo becomes your steering tool: prioritized action plan, scored risks, always-current generated documents and vendor answers.

Prioritised roadmap & risk register

A roadmap ranked by priority (Risk × 0.4 + Urgency × 0.3 + Ease × 0.3) and a 16-scenario scored risk register. xlsx / pptx exports for your committees.

  • Transparent prioritisation of the actions to take
  • 16-scenario scored risk register
  • xlsx and pptx exports ready for the steering committee
  • Persisted roadmap selections
Komplyo prioritised action plan and risk register

Generated policies & incident-response pack

30+ deliverables generated from your gaps: a global policy and 12 domain policies, an IT charter, an incident-response pack, an awareness kit, in .docx, .xlsx and .pptx, gathered in your document library.

  • 30+ ready-to-customise .docx / .xlsx / .pptx documents, bilingual FR/EN
  • CSF / ISO / SOC 2 / GDPR coverage badges per control
  • Library with an “up to date / regenerate” status on every answer change
  • EU-resident file storage, org-guarded download
Generated security policies in .docx with coverage badges

Vendor security questionnaires (TPRM)

Answer your customers' security questionnaires and assess your own vendors, reusing the evidence from your assessment.

  • Vendor kit: questionnaire, contractual clauses, assessment procedure
  • Reuse assessment answers as evidence
  • Centralised third-party tracking
Vendor security questionnaires (TPRM) in Komplyo

Ready to see where you stand?

Start the free diagnostic: 23 questions, ~5 minutes, no credit card. Your answers carry over into the full assessment.