Home/FAQ

Frequently asked questions

If your question is not here, the contact form goes to a person who will answer it.

About the products

What exactly do I receive?

A download link to a ZIP containing every document listed on the product page, as editable Word (.docx) files and, where relevant, Excel (.xlsx) workbooks. Your organisation's name is already inserted. A document register lists every file with a suggested owner and review date.

Are the documents complete, or templates with blanks?

Complete. They are written as finished documents to the framework's current edition. Placeholders exist only for things we cannot know: system names, role titles, tool names, timelines and similar. There are no empty sections to write.

Who writes them?

Practitioners with audit and implementation experience across the frameworks we cover. Every set is reviewed against the current framework text before release and again whenever the framework changes.

How current are they?

Each product page shows the last revision date. Sets track the current editions: ISO/IEC 27001:2022, NIST CSF 2.0, NIST SP 800-53 R5, NIST SP 800-171 R3, PCI DSS v4.0.1, ISO/IEC 42001:2023, plus NIS2 and DORA as transposed and their technical standards.

Can I see an example before I buy?

Yes. Ask us and name the product; we will send a representative document from the set.

Do the sets work together?

Yes, by design. All products share one structure and one vocabulary, so a standard from one set cites the same control identifiers as a procedure from another. Buying a bundle gets you a single document register across all included sets.

Buying and delivery

How do I pay?

Add products to your basket and send an order request. We reply with an invoice payable by card or bank transfer, and we accept purchase orders from established organisations. Files are delivered by email once payment clears, normally the same business day.

Do prices include VAT?

No. VAT is added where applicable based on your location and VAT status. Business customers in [jurisdiction] will see VAT on the invoice; customers elsewhere are generally not charged VAT but may need to account for it locally.

Is there a refund policy?

Because these are digital documents that cannot be returned, we do not offer refunds once files have been delivered. That is why we offer samples before purchase. If a set is materially different from its product page description, tell us within 14 days and we will put it right or refund you.

What do updates include?

When we revise a set you own, for example for a new framework edition or a regulatory change, you receive the new version by email at no charge for 12 months from purchase (24 months for the Complete Library). Minor corrections are also pushed. After the update period you can renew for a reduced fee.

Licensing

How many people can use the documents?

As many as you like within the licensed organisation. The licence is per organisation, not per user.

We are a consultancy or MSP. Can we use these for clients?

Not under the standard licence, which covers internal use only. We offer a multi-client licence for consultancies, MSPs and MSSPs that tailor documentation for their customers. Contact us for pricing.

Can we share the documents with our auditor or customers?

Yes. Sharing your tailored documents with auditors, assessors, regulators, customers and suppliers as part of normal business is permitted. Redistributing the unedited templates, or selling them, is not.

Do we own the tailored documents?

You own the content you add and your tailored versions for your own use. The underlying template content remains ours and licensed to you. The full terms are on the terms page.

Compliance questions

Will these make us ISO 27001 certified / CMMC compliant / SOC 2 ready?

They will give you the documentation those assessments require. They will not implement the controls or generate the evidence. Assessors check that what the documents say is what you actually do. Plan for the documentation to be roughly a quarter of the work.

Our auditor wants to see procedures, not just policies. Which product?

The Procedures Library. It exists for exactly that request.

We need to comply with several frameworks. Do we need several sets?

Usually one policies-and-standards set (choose the most demanding framework) plus the mapping workbook it includes, then programme documentation for the areas each regulation emphasises. The start here page walks through it.

Do you offer implementation or consulting?

Yes. Gap assessments, implementation, internal audit, CMMC readiness and virtual CISO retainers are the core of what we do; the services page describes each. Documentation customers get email support on the products as standard and can add a fixed-scope implementation package at any time.

Ask something else