Skip to content
Privacy by design: answers are evaluated in your browser and the DOCX sample is generated locally. The full paid pack is generated on the server after payment verification and is not retained. Answers are stored to give you the permanent link (/r/…); name and email only if you provide them.
Regulatory documentation packs

Which documentation packs does your project need?

Answer closed, non-sensitive questions. Get potentially applicable frameworks, list prices for your market and DOCX templates.

Loading wizard…
Document catalog

What each documentation pack includes

Each module generates DOCX templates (catalog 2026.08.2). The universal core combines with the frameworks that apply to your project context.

Core

Universal project core

Base pack: cross-framework traceability manifest, context, applicability, requirements matrix, charter, evidence, verification, remediation, exceptions, RACI and executive summary.

Who it is for: For any digital project: a governance baseline, evidence and a verification plan you can reuse across frameworks.

11 DOCX templates · free sample included

  • Pack manifest and cross-traceability matrix
  • Project context
  • Applicability memo
  • Requirements matrix
  • + 7 more documents
AI Act

EU AI Act — documentation pack

Advisory memorandum on applicability and readiness (Digital Omnibus 2026), plus operational templates for inventory, roles, classification, risks and a 30–60–90 plan.

Who it is for: If you build, integrate or place AI systems on the EU market: inventory, roles, classification and a 30–60–90 plan.

11 DOCX templates · free sample included

  • Memorandum on applicability, obligations and readiness
  • Inventory of AI systems and use cases
  • Preliminary role record
  • Classification and exclusions
  • + 7 more documents
CRA

Cyber Resilience Act — documentation pack

Advisory memorandum on applicability and readiness (digital product, economic roles, essential requirements, SBOM and post-market), plus operational templates.

Who it is for: If you sell software or products with digital elements in the EU: CRA perimeter, SBOM, vulnerabilities and lifecycle.

11 DOCX templates · free sample included

  • Applicability, obligations and readiness memorandum
  • Digital product fact sheet
  • Classification and economic roles
  • Secure development plan
  • + 7 more documents
NIS2

NIS2 — documentation pack

Advisory memorandum on applicability and readiness (governance Art. 20, measures Art. 21, incidents Art. 23), plus scope, risk, continuity and supplier templates.

Who it is for: If you operate as an essential or important entity: management-level governance, incidents, supply chain and evidence.

9 DOCX templates · free sample included

  • Applicability, obligations and readiness memorandum
  • Scope fact sheet
  • Risk management policy
  • Incident process
  • + 5 more documents
GDPR

GDPR / privacy — document pack

Advisory memorandum on applicability and readiness (roles, legal bases, DPIA, rights, breaches, transfers), plus RoPA and processor templates.

Who it is for: If you process personal data of EU/EEA residents: legal basis, DPIA, data-subject rights and the record of processing.

7 DOCX templates · free sample included

  • Memorandum on applicability, obligations and readiness
  • Record of processing activities (RoPA)
  • Legal bases
  • DPIA screening
  • + 3 more documents
BR LGPD

Brazil — LGPD (privacy)

Advisory memorandum on applicability and readiness for the Lei Geral de Proteção de Dados (Lei 13.709/2018): roles, legal bases, rights, DPO/encarregado and ANPD.

Who it is for: Operations in Brazil or involving Brazilian data subjects: roles, legal bases and LGPD security measures.

6 DOCX templates · free sample included

  • Memorandum on applicability, obligations and readiness — LGPD
  • Inventory of processing activities
  • Legal bases and purposes
  • Data subject rights procedure
  • + 2 more documents
CL 21.719

Chile — Ley 21.719 (privacy)

Advisory memorandum on Ley 21.719 on personal data protection and the Agencia de Protección de Datos Personales: applicability, obligations and readiness.

Who it is for: Operations in Chile or involving Chilean data subjects under Law 21,719.

6 DOCX templates · free sample included

  • Applicability, obligations and readiness memorandum — Ley 21.719
  • Processing inventory
  • Lawful bases
  • Data subject rights procedure
  • + 2 more documents
CO 1581

Colombia — Ley 1581 (privacy)

Advisory memorandum on the general personal data protection regime (Ley 1581 de 2012 and decrees): applicability, obligations and readiness before the SIC.

Who it is for: Operations in Colombia or processing of personal data under Law 1581.

6 DOCX templates · free sample included

  • Applicability, obligations and readiness memorandum — Ley 1581
  • Database inventory
  • Authorisations and purposes
  • Queries and complaints procedure
  • + 2 more documents
MX LFPDPPP

Mexico — LFPDPPP (privacy)

Advisory memorandum on the Federal Law on the Protection of Personal Data Held by Private Parties (2025 update): privacy notices, ARCO rights and obligations of private parties.

Who it is for: Operations in Mexico or processing of personal data under the LFPDPPP.

6 DOCX templates · free sample included

  • Applicability, obligations and readiness memorandum — LFPDPPP
  • Inventory of processing activities
  • Privacy notices
  • ARCO rights procedure
  • + 2 more documents
ISO 27001

ISO/IEC 27001 — ISMS pack

Full advisory memorandum on ISMS applicability and readiness (ISO/IEC 27001:2022) plus ten structured readiness templates —perimeter, governance, risks, SoA, evidence and internal audit— with pre-loaded guidance, for digital SMEs in the EU+LATAM. Readiness, not certification.

Who it is for: If you need an ISMS or need to show ISO 27001 maturity: scope, risks, SoA and an implementation plan sized for a smaller company.

11 DOCX templates · free sample included

  • ISMS applicability, obligations and readiness memorandum
  • Regulatory Perimeter & Applicability Memorandum
  • Executive Obligations and Supervisory Expectations Map
  • Governance and Accountability Model
  • + 7 more documents
Web/ASVS

Web security — OWASP / ASVS

Advisory blueprint for ASVS adoption and verification (verifiable requirements, levels, RACI and evidence), plus templates for risk profile, checklist, testing and release gate.

Who it is for: Web, API or mobile applications: OWASP ASVS adoption by level and a control verification plan.

6 DOCX templates · free sample included

  • OWASP ASVS — Adoption & Verification Blueprint
  • Web risk profile
  • Targeted ASVS checklist
  • Security testing plan
  • + 2 more documents
SOC 2

SOC 2 — readiness preparation

Pre-audit readiness for SOC 2: Type I vs II, TSC categories, scope, System Description and evidence plan. Not a certification and not a CPA report. Does not reproduce AICPA text (mapping by reference).

Who it is for: B2B SaaS/Web/API, or customers asking for attestation: SOC 2 readiness (this is not a CPA attestation).

7 DOCX templates · free sample included

  • Applicability and readiness memorandum — SOC 2
  • Scope and selection of TSC categories
  • System description outline (Section III)
  • Control matrix (Common Criteria CC1–CC9)
  • + 3 more documents
ePrivacy

Cookies / ePrivacy — documentation pack

Cookies and trackers (ePrivacy Directive + AEPD/CNIL guidance) and interaction with GDPR consent: inventory, CMP and cookie policy.

Who it is for: Websites or apps with third-party cookies/trackers in the EU: inventory, CMP and cookie policy.

4 DOCX templates · free sample included

  • Applicability and readiness memo — ePrivacy/cookies
  • Cookie and tracker inventory
  • Consent design and CMP
  • Cookie policy template
DPA/SCC

DPA / SCC — processing contracts

When a DPA (Art. 28) and SCC (transfers) are required: processing agreement template, SCC/TIA guidance by reference to the Commission's official text, sub-processor register.

Who it is for: Processing on behalf of others, sub-processors or international transfers: DPA and SCC/TIA guidance.

4 DOCX templates · free sample included

  • Applicability and readiness memo — DPA/SCC
  • Processing agreement template (DPA)
  • SCC guidance and transfer assessment (TIA)
  • Sub-processor register
AR 25.326

Argentina — Ley 25.326 (privacy)

Ley 25.326 and AAIP: database inventory/registration, lawful bases, rights (habeas data), security and transfers. PROP notice of reform in progress.

Who it is for: Argentina or data of AR residents: Law 25,326 / AAIP (with a note on the pending reform).

6 DOCX templates · free sample included

  • Applicability and readiness memorandum — Ley 25.326
  • Database inventory and registration (AAIP)
  • Lawful bases and consent
  • Data subject rights procedure
  • + 2 more documents
PE 29733

Peru — Ley 29733 (privacy)

Ley 29733 + D.S. 016-2024-JUS Regulation (ANPDP): data banks, legal bases, rights, security/breaches and transfers.

Who it is for: Peru or data of PE residents: Law 29,733 + Supreme Decree 016-2024-JUS / ANPDP.

6 DOCX templates · free sample included

  • Applicability and readiness memorandum — Ley 29733
  • Data bank inventory (Registro Nacional)
  • Legal bases and purposes
  • Data subject rights procedure
  • + 2 more documents

How the packs work

  1. 1
    Non-sensitive context

    Tell us geography, sector, product type and whether you use AI or process personal data. No secrets, no code.

  2. 2
    Preliminary applicability

    NaviComp flags potentially applicable or recommended frameworks and lets you choose which modules to include.

  3. 3
    DOCX ZIP

    The sample is generated in your browser; the full pack on the server once payment is verified. Download it and edit it with your team.

The templates are an operational starting point and do not constitute legal advice. Complete and validate them with your legal or compliance team before presenting them to an auditor or an authority.