180 questions, a 30-day deadline, and the contract on the table. Upload the questionnaire and know exactly where you stand in a minute.
NIS2 · ISO 27001 · DORA · ENS · TISAX · or your customer’s own format
Your file never leaves your browser. To classify the questions, only the text of each question is processed — never the document, never company names, and never any answer you’ve already filled in.
Do you have a documented information security policy approved by management?
art. 21.2.a
Is multi-factor authentication enforced for all remote access?
art. 21.2.j
State the RTO and RPO of your critical systems.
art. 21.2.c
How often do you perform vulnerability scans?
art. 21.2.e
Your customer is required to prove their suppliers are secure. They can’t audit all of you, so they send a questionnaire. If you don’t answer it — or answer it badly — you stop being a supplier.
Works for any framework
NIS2, ISO 27001, DORA, ENS, TISAX, or your customer’s own format. We work on controls, not formats: underneath, they all ask the same things.
You don’t throw it away
The evidence base we build stays. The next questionnaire you get answered in minutes, not weeks.
We don’t answer what can’t be proven
No evidence, it’s marked as a gap. A "yes" with no backing inside a contract is a false statement, and it costs far more than the original problem.
Fixed, published price
You know what it costs before talking to anyone. No custom quotes, no billable hours.
This is for you if...
This isn’t for you if...
Your customer’s email always says why they’re sending it. Find your case.
NIS2
Who sends it
A customer in energy, transport, healthcare, banking, public administration, water, waste, or digital infrastructure
You recognize it by
"supply chain obligations", "Directive 2022/2555", "essential or important entity"
If your customer is German, they’ve been required to comply since December 2025
ISO 27001
Who sends it
Any certified company that has you as a supplier
You recognize it by
references like A.5.1, A.8.8, "Annex A", "ISMS"
DORA
Who sends it
A bank, insurer, fund manager, or fintech
You recognize it by
"ICT third-party provider", "Regulation 2022/2554", "third-party risk"
Applies even if you’re not in the financial sector — providing them an ICT service is enough
ENS (Spain)
Who sends it
A Spanish public administration or a public contract awardee
You recognize it by
"Esquema Nacional de Seguridad", "RD 311/2022", codes like op.acc.1, mp.info.3
Usually comes with a public procurement contract behind it
TISAX
Who sends it
An automotive manufacturer or a Tier 1 supplier
You recognize it by
"VDA-ISA", "TISAX label", AL1/AL2/AL3 levels, "ENX Association"
The most demanding one, usually with a short deadline
Customer’s own format
Who sends it
Any large company with its own security department
You recognize it by
cites no regulation, or mixes several
Underneath, they ask the same things. We work on controls, not formats
Regulations like NIS2, DORA, ISO 27001 and Spain’s ENS require large companies to control the security of their supply chain. Since they can’t audit hundreds of suppliers, they send questionnaires. The consequence of not answering usually isn’t a penalty: it’s that the contract doesn’t get renewed. There’s no case file, no notice — you just stop being on the list, and often you don’t even know why.
An email with a spreadsheet attached and a deadline. Nobody negotiated it with you. If you don’t return it on time, your customer has to look for another supplier — their own regulation requires it.
RTO, RPO, network segmentation, patch management, MFA, log retention. You make parts. Your IT guy handles the printers and email.
Ticking "yes" isn’t enough. They want the document, the report, the screenshot. And signing a "yes" you can’t prove is a false statement inside a commercial contract.
54% of companies report having lost business for not completing security questionnaires on time, and 88% take more than two weeks doing it by hand, according to industry data. You don’t lose out by failing the questionnaire — you lose out by being slow.
Breakdown starting from scratch
(most of it is drafting what doesn’t exist yet)
Those 2-3 hours are yours, answering our questions about how you work. We handle everything else.
We leave you a reusable base: the next questionnaire gets answered in minutes, not weeks.
Doing it in-house
12-70 h of your team’s time
Between €480 and €2,800 of internal cost at €40/h, depending on whether you already have the documentation (12-18 h) or you’re starting from scratch (40-70 h) — and on someone at your company knowing the right answer.
Traditional consulting
€3,000-8,000
4 to 8 weeks.
Complision
€1,200-2,400
48-72h from your evidence, and you’re left with a base built for the next questionnaires.
We don’t do the same thing as a full NIS2 implementation consultancy — they implement compliance with an entire regulation. We solve this specific problem: answering the questionnaire you’ve just received, backed by real evidence.
| Compliance consultancy | Complision | |
|---|---|---|
| What it solves | Implementing a complete management system | Answering the questionnaire you received |
| When you hire it | When you decide to get certified | When your customer gives you a deadline |
| Scope | The whole organization | What they’re asking you |
| Duration | 4-8 weeks or more | 48-72h from your evidence |
| Typical price | €3,000-8,000 | €1,200-2,400 |
| What you’re left with | An implemented management system | Your questionnaire answered and a reusable base |
| Next questionnaire | Start over | Minutes |
A compliance consultancy and Complision don’t compete: they solve different problems. If your goal is to get ISO 27001 certified or implement a full management system, you need a consultancy, and we don’t replace that. If what you have is a questionnaire on the table with a deadline, that’s us. In fact, many customers start here because the deadline is tight, and hire a consultancy afterward with the gap map already done.
Excel or PDF, exactly as your customer sent it. Analyzed inside your browser — the file never travels to any server, ours or anyone else’s.
Every question classified by control and by the relevant framework, plus the exact list of documents you’re missing to answer with real backing.
We draft what doesn’t exist, gather what does, and answer the questionnaire. From then on, the next customer who asks gets answered in minutes.
Your questionnaire might cite very different articles, annexes or acronyms depending on who sends it — or cite no regulation at all and just use your customer’s own format. It doesn’t matter: we classify every question by control, not by the name of the regulation.
Supplier questionnaire, NIS2, ISO 27001, DORA, ENS or TISAX.
The hard work is building your evidence base once. After that, keeping it alive is cheap. Fixed, published prices — no custom quotes, no negotiation.
Start for free
Upload your questionnaire and see the full result on screen, no card, no signup. The PDF report is free in exchange for your email.
| With maintenance | Without maintenance | |
|---|---|---|
| Annual fee | €490 | €0 |
| First questionnaire of the year | Included | €600 |
| Next questionnaires | €300 | €600 |
| Expiry alerts | Yes | No |
| Regulatory updates | Yes | No |
Your case
1 questionnaire per year
€490 vs €600
Worth it
2 questionnaires per year
€790 vs €1,200
Clearly worth it
None that year
€490 vs €0
Not worth it
The exact list of what you’re missing, which document you need for each thing, in what order, and how many hours it’ll take. You execute it.
See what’s includedNo — and be wary of anyone who says otherwise. Neither NIS2, nor ISO 27001, nor DORA, nor Spain’s ENS get "approved" through us: none of them has an exam or a certificate issued via a third party like Complision. What does exist, and is very real, is the questionnaire your customer sends. That’s what we answer.
The file itself, nowhere: the analysis happens inside your browser and the document is never uploaded to a server. To classify each question, only its text is processed — never the file, your company’s name, or any answer already filled in. Close the tab and nothing of yours remains. We only store the aggregated result if you request the report.
Yes. ISO 27001, DORA, ENS, TISAX, your customer’s own format, or a mix of everything: underneath, they ask the same things, only the wording changes. Our system works on controls, not on the format.
Your customer’s email usually says why. If it’s not clear, upload the questionnaire: we detect it from the content itself.
Yes, that’s the most common case. We detect several at once and classify by controls, not by format.
No. A consultancy implements a full management system; we answer the questionnaire you received and build your evidence base. They’re different things, and often complementary.
No. The service is a one-time payment. Maintenance is annual and optional: if you don’t hire it, your evidence base stays saved and you only pay when another questionnaire arrives.
If you get at least one questionnaire a year, yes: €490 versus the €600 it costs to answer one without maintenance. If you don’t expect to get any, don’t hire it — your base stays saved regardless, and you only pay when you need it.
Because there’s more work involved. With maintenance, your documentation is up to date and answering is nearly immediate. Without it, after a year much of the evidence has expired and has to be redone.
No. It stays saved. When another questionnaire arrives, we answer it using that base.
It’s answered using the base we already built, so it costs far less than the service. With maintenance, the first one each year is included and the next ones cost €300. Without maintenance, €600.
It counts for more than you’d think. A well-configured Microsoft 365 or Google Workspace already covers MFA, email encryption, and activity logging. The work isn’t implementing anything new — it’s organizing it, documenting it, and being able to show it. A good part of what we do is exactly that.
No signup, no card, and the file never leaves your computer. If you then want us to answer it for you, let’s talk.
Analyze my questionnaire