A logical journey, from the first question to the audit.
Komplyo guides you through four steps: run the free diagnostic, choose your depth, activate the frameworks you need, then steer and prove your compliance.
- 1
Free diagnostic
23 questions, ~5 minutes. A score per CSF function and a GDPR status, no credit card.
- 2
Choose your path
Best practices (light) to build hygiene, or certification (full) to target ISO 27001 / SOC 2.
- 3
Activate your lenses
ISO 27001, SOC 2, NIS2, CRA, ANSSI: activated by objective, never by score. GDPR is a parallel axis, on by default.
- 4
Steer and prove
Prioritized action plan, risk register, 30+ generated documents and vendor questionnaires.
Start with the free diagnostic.
23 questions covering the six NIST CSF 2.0 functions and GDPR. You immediately get a score per function and a privacy status. Your answers carry over into the full assessment.
Two depths, one assessment.
After signing up, pick your target. You can switch between them at any time without losing your answers.
Best practices (light)
The NIST CSF 2.0 small-business subset (~43 subcategories), designed to build solid security hygiene with a small team.
- Step-by-step guidance per function: understand, assess, prioritize, communicate
- 3-state markers (done / partial / to do) per control
- Essential deliverables: IT charter, awareness kit, light TPRM

Certification (full)
All 106 CSF 2.0 subcategories plus the GDPR axis plus your lens deltas. The defensible base to target ISO 27001 or SOC 2.
- Tier 1 to 4 maturity per subcategory, capping by critical items
- Persisted score history (audit defensibility)
- Unlocks the certification workspaces and 30+ deliverables

The light ↔ full switch is reversible and non-destructive: your answers are preserved.
Per-function steering, in both depths
Each CSF function (Govern, Identify, Protect, Detect, Respond, Recover) has its own page: actions to take on the left, guides and resources on the right.


Activate frameworks when you're ready.
The ISO 27001, SOC 2, NIS2, CRA and ANSSI lenses plug into the same assessment. Every CSF answer projects automatically through the mapping table. You only activate a lens when the objective exists, never because a score demands it.
- Activation by objective: enterprise sales, certification, legal obligation
- Two readiness readings: derived from your CSF answers, then deepened with the delta questions
- GDPR stays a parallel axis, on by default and deactivable

Assess once, project everywhere
Your CSF 2.0 answers automatically feed ISO 27001, SOC 2 (TSC), GDPR Article 32, NIS2, the CRA and the ANSSI hygiene guide through the mappings table. We never ask the same question twice.
- One implemented control → N compliances (coverage badges)
- Six lenses: ISO 27001, SOC 2, GDPR, NIS2, CRA, ANSSI hygiene guide (42 measures)
- Lenses activated by objective, never by score
- Derived then comprehensive readiness per framework

ISO 27001 Statement of Applicability & SOC 2 workspace
A dedicated certification workspace: per-control readiness, inline gap answering, and an editable, exportable ISO 27001 SoA. SOC 2 covers the CC / A / C / PI / P criteria.
- Editable, exportable ISO 27001 SoA
- Coverage of all 93 Annex A controls + ISMS clauses
- SOC 2 system description (DC 200) and TSC matrix (.xlsx)
- Inline gap answering, persisted on every entry

NIS2 scope analysis
Determine whether NIS2 applies to your organisation (essential or important entity) and what it implies, from the same assessment answers. The Cyber Resilience Act is covered by the same mechanics.
- NIS2 entity self-classification (essential / important) with an explanatory note
- ANSSI incident notification templates (24 h / 72 h / final report)
- CRA technical file (Annex VII) and CVD policy + security.txt
- Two dedicated free diagnostics: NIS2 and CRA

GDPR conformity by article & Art. 30 register
A parallel privacy axis (not a maturity score): compliance status per article, gaps to close, and a record of processing activities (Art. 30).
- Compliant / partial / missing / not-applicable per article
- Structured records of processing (Art. 30)
- Generated DPIA, processor DPA and data-subject-rights templates
- GDPR axis toggle per assessment

Steer, fix, prove.
Once the assessment is in place, Komplyo becomes your steering tool: prioritized action plan, scored risks, always-current generated documents and vendor answers.
Prioritised roadmap & risk register
A roadmap ranked by priority (Risk × 0.4 + Urgency × 0.3 + Ease × 0.3) and a 16-scenario scored risk register. xlsx / pptx exports for your committees.
- Transparent prioritisation of the actions to take
- 16-scenario scored risk register
- xlsx and pptx exports ready for the steering committee
- Persisted roadmap selections

Generated policies & incident-response pack
30+ deliverables generated from your gaps: a global policy and 12 domain policies, an IT charter, an incident-response pack, an awareness kit, in .docx, .xlsx and .pptx, gathered in your document library.
- 30+ ready-to-customise .docx / .xlsx / .pptx documents, bilingual FR/EN
- CSF / ISO / SOC 2 / GDPR coverage badges per control
- Library with an “up to date / regenerate” status on every answer change
- EU-resident file storage, org-guarded download

Vendor security questionnaires (TPRM)
Answer your customers' security questionnaires and assess your own vendors, reusing the evidence from your assessment.
- Vendor kit: questionnaire, contractual clauses, assessment procedure
- Reuse assessment answers as evidence
- Centralised third-party tracking
