Each module generates DOCX templates (catalog 2026.08.2). The universal core combines with the frameworks that apply to your project context.
Core
Universal project core
Base pack: cross-framework traceability manifest, context, applicability, requirements matrix, charter, evidence, verification, remediation, exceptions, RACI and executive summary.
Who it is for: For any digital project: a governance baseline, evidence and a verification plan you can reuse across frameworks.
11 DOCX templates · free sample included
- • Pack manifest and cross-traceability matrix
- • Project context
- • Applicability memo
- • Requirements matrix
- + 7 more documents
AI Act
EU AI Act — documentation pack
Advisory memorandum on applicability and readiness (Digital Omnibus 2026), plus operational templates for inventory, roles, classification, risks and a 30–60–90 plan.
Who it is for: If you build, integrate or place AI systems on the EU market: inventory, roles, classification and a 30–60–90 plan.
11 DOCX templates · free sample included
- • Memorandum on applicability, obligations and readiness
- • Inventory of AI systems and use cases
- • Preliminary role record
- • Classification and exclusions
- + 7 more documents
CRA
Cyber Resilience Act — documentation pack
Advisory memorandum on applicability and readiness (digital product, economic roles, essential requirements, SBOM and post-market), plus operational templates.
Who it is for: If you sell software or products with digital elements in the EU: CRA perimeter, SBOM, vulnerabilities and lifecycle.
11 DOCX templates · free sample included
- • Applicability, obligations and readiness memorandum
- • Digital product fact sheet
- • Classification and economic roles
- • Secure development plan
- + 7 more documents
NIS2
NIS2 — documentation pack
Advisory memorandum on applicability and readiness (governance Art. 20, measures Art. 21, incidents Art. 23), plus scope, risk, continuity and supplier templates.
Who it is for: If you operate as an essential or important entity: management-level governance, incidents, supply chain and evidence.
9 DOCX templates · free sample included
- • Applicability, obligations and readiness memorandum
- • Scope fact sheet
- • Risk management policy
- • Incident process
- + 5 more documents
GDPR
GDPR / privacy — document pack
Advisory memorandum on applicability and readiness (roles, legal bases, DPIA, rights, breaches, transfers), plus RoPA and processor templates.
Who it is for: If you process personal data of EU/EEA residents: legal basis, DPIA, data-subject rights and the record of processing.
7 DOCX templates · free sample included
- • Memorandum on applicability, obligations and readiness
- • Record of processing activities (RoPA)
- • Legal bases
- • DPIA screening
- + 3 more documents
BR LGPD
Brazil — LGPD (privacy)
Advisory memorandum on applicability and readiness for the Lei Geral de Proteção de Dados (Lei 13.709/2018): roles, legal bases, rights, DPO/encarregado and ANPD.
Who it is for: Operations in Brazil or involving Brazilian data subjects: roles, legal bases and LGPD security measures.
6 DOCX templates · free sample included
- • Memorandum on applicability, obligations and readiness — LGPD
- • Inventory of processing activities
- • Legal bases and purposes
- • Data subject rights procedure
- + 2 more documents
CL 21.719
Chile — Ley 21.719 (privacy)
Advisory memorandum on Ley 21.719 on personal data protection and the Agencia de Protección de Datos Personales: applicability, obligations and readiness.
Who it is for: Operations in Chile or involving Chilean data subjects under Law 21,719.
6 DOCX templates · free sample included
- • Applicability, obligations and readiness memorandum — Ley 21.719
- • Processing inventory
- • Lawful bases
- • Data subject rights procedure
- + 2 more documents
CO 1581
Colombia — Ley 1581 (privacy)
Advisory memorandum on the general personal data protection regime (Ley 1581 de 2012 and decrees): applicability, obligations and readiness before the SIC.
Who it is for: Operations in Colombia or processing of personal data under Law 1581.
6 DOCX templates · free sample included
- • Applicability, obligations and readiness memorandum — Ley 1581
- • Database inventory
- • Authorisations and purposes
- • Queries and complaints procedure
- + 2 more documents
MX LFPDPPP
Mexico — LFPDPPP (privacy)
Advisory memorandum on the Federal Law on the Protection of Personal Data Held by Private Parties (2025 update): privacy notices, ARCO rights and obligations of private parties.
Who it is for: Operations in Mexico or processing of personal data under the LFPDPPP.
6 DOCX templates · free sample included
- • Applicability, obligations and readiness memorandum — LFPDPPP
- • Inventory of processing activities
- • Privacy notices
- • ARCO rights procedure
- + 2 more documents
ISO 27001
ISO/IEC 27001 — ISMS pack
Full advisory memorandum on ISMS applicability and readiness (ISO/IEC 27001:2022) plus ten structured readiness templates —perimeter, governance, risks, SoA, evidence and internal audit— with pre-loaded guidance, for digital SMEs in the EU+LATAM. Readiness, not certification.
Who it is for: If you need an ISMS or need to show ISO 27001 maturity: scope, risks, SoA and an implementation plan sized for a smaller company.
11 DOCX templates · free sample included
- • ISMS applicability, obligations and readiness memorandum
- • Regulatory Perimeter & Applicability Memorandum
- • Executive Obligations and Supervisory Expectations Map
- • Governance and Accountability Model
- + 7 more documents
Web/ASVS
Web security — OWASP / ASVS
Advisory blueprint for ASVS adoption and verification (verifiable requirements, levels, RACI and evidence), plus templates for risk profile, checklist, testing and release gate.
Who it is for: Web, API or mobile applications: OWASP ASVS adoption by level and a control verification plan.
6 DOCX templates · free sample included
- • OWASP ASVS — Adoption & Verification Blueprint
- • Web risk profile
- • Targeted ASVS checklist
- • Security testing plan
- + 2 more documents
SOC 2
SOC 2 — readiness preparation
Pre-audit readiness for SOC 2: Type I vs II, TSC categories, scope, System Description and evidence plan. Not a certification and not a CPA report. Does not reproduce AICPA text (mapping by reference).
Who it is for: B2B SaaS/Web/API, or customers asking for attestation: SOC 2 readiness (this is not a CPA attestation).
7 DOCX templates · free sample included
- • Applicability and readiness memorandum — SOC 2
- • Scope and selection of TSC categories
- • System description outline (Section III)
- • Control matrix (Common Criteria CC1–CC9)
- + 3 more documents
ePrivacy
Cookies / ePrivacy — documentation pack
Cookies and trackers (ePrivacy Directive + AEPD/CNIL guidance) and interaction with GDPR consent: inventory, CMP and cookie policy.
Who it is for: Websites or apps with third-party cookies/trackers in the EU: inventory, CMP and cookie policy.
4 DOCX templates · free sample included
- • Applicability and readiness memo — ePrivacy/cookies
- • Cookie and tracker inventory
- • Consent design and CMP
- • Cookie policy template
DPA/SCC
DPA / SCC — processing contracts
When a DPA (Art. 28) and SCC (transfers) are required: processing agreement template, SCC/TIA guidance by reference to the Commission's official text, sub-processor register.
Who it is for: Processing on behalf of others, sub-processors or international transfers: DPA and SCC/TIA guidance.
4 DOCX templates · free sample included
- • Applicability and readiness memo — DPA/SCC
- • Processing agreement template (DPA)
- • SCC guidance and transfer assessment (TIA)
- • Sub-processor register
AR 25.326
Argentina — Ley 25.326 (privacy)
Ley 25.326 and AAIP: database inventory/registration, lawful bases, rights (habeas data), security and transfers. PROP notice of reform in progress.
Who it is for: Argentina or data of AR residents: Law 25,326 / AAIP (with a note on the pending reform).
6 DOCX templates · free sample included
- • Applicability and readiness memorandum — Ley 25.326
- • Database inventory and registration (AAIP)
- • Lawful bases and consent
- • Data subject rights procedure
- + 2 more documents
PE 29733
Peru — Ley 29733 (privacy)
Ley 29733 + D.S. 016-2024-JUS Regulation (ANPDP): data banks, legal bases, rights, security/breaches and transfers.
Who it is for: Peru or data of PE residents: Law 29,733 + Supreme Decree 016-2024-JUS / ANPDP.
6 DOCX templates · free sample included
- • Applicability and readiness memorandum — Ley 29733
- • Data bank inventory (Registro Nacional)
- • Legal bases and purposes
- • Data subject rights procedure
- + 2 more documents