
- Policies & Standards - ISO 27001 / 27002
- Procedures - ISO 27001 / 27002
- C-SCRM Strategy & Implementation Plan (C-SCRM SIP)
- Risk Management Program (RMP)
- Cybersecurity Risk Assessment (CRA) Template
- Vulnerability & Patch Management Program (VPMP)
- Integrated Incident Response Program (IIRP)
- Continuity of Operations Plan (COOP)
- Secure Baseline Configurations (SBC)
- Information Assurance Program (IAP)
- Data Privacy Program (DPP)
Don't Write It From Scratch.
If a certification auditor asked for your complete ISO 27001 documentation today, could you produce it, or would you be assembling it one product at a time? CFD Bundle 2 gives you a running start: a coordinated set of editable templates that cover ISO 27001/27002 end to end, so your team tailors rather than authors and reaches roughly 80 to 90 percent of the way there from day one.
Achieving ISO 27001 certification is not just a policy exercise. An ISO 27001 ISMS requires documented governance, risk management, and operational controls drawn from ISO 27002, and a certification auditor expects each one to be backed by procedures and evidence that the work actually happens. Most organizations start with policies and standards, then realize the ISMS also expects a risk program, incident response, continuity planning, vulnerability management, secure configurations, and privacy documentation.

CFD Bundle 2 is ComplianceForge's near-turnkey documentation stack for ISO 27001/27002. It brings together the full set of editable ComplianceForge products that, used together, cover the breadth of an ISO 27001 ISMS, from the foundational policies and standards down to the procedures and program-level documentation that prove how each control is run. Because every product is built on the same Secure Controls Framework (SCF) taxonomy, the pieces cross-reference cleanly and present one consistent program rather than a stack of templates that contradict each other.
It is built for organizations pursuing ISO 27001 certification or proving ISO 27002 alignment to customers, and that want a complete, coordinated documentation set instead of disconnected templates. Your team tailors the specifics to your environment and reaches a defensible, certification-ready ISMS in far less time than building it from scratch.
What Is The CFD Bundle 2?
CFD Bundle 2 is ComplianceForge's enterprise-class solution for organizations aligning with ISO 27001:2022 and ISO 27002:2022. Where the PSP-tier bundle provides the foundational layer of policies, standards, and procedures, CFD Bundle 2 extends coverage across the entire program: governance and risk management, vulnerability and patch management, incident response and continuity of operations, secure baseline configurations, supply chain risk, and data privacy. Instead of a pile of standalone documents, it is a single coordinated documentation set built on one control framework, so the components reference each other and tell one coherent story to a certification auditor.
We assembled this bundle, based on client feedback, to make ISO 27001/27002 attainable without sourcing every piece separately. When you break the standard down into what it actually expects, each component maps to a specific need: the policies and standards that define your ISMS, the procedures that prove it operates, and the program-level documentation that supports the Annex A control areas. The result is comprehensive coverage that stays internally consistent as your program evolves.
No Software To Install
This bundle is a one-time purchase of editable Microsoft Office-based documentation templates. There is no software to install, no agent to deploy, no account to provision, and no cloud environment to configure. If your organization can open and edit Microsoft Word or Excel files (or compatible tools like OpenOffice and Google Workspace), you can use every product in this bundle.
Microsoft Word and Excel
Delivered as fully editable .docx and .xlsx files. Compatible with Word 2016 and newer, Microsoft 365, OpenOffice, LibreOffice, and Google Docs/Sheets.
Email Delivery
All products in the bundle are delivered via email download link within 1-2 business days of purchase. There is no installer, no license server, and no activation step.
One-Time Purchase
A single-entity license is included with purchase. The bundle price is a one-time charge. No subscriptions required for any product in the bundle.

This deployment model is intentional. Cybersecurity documentation belongs in the organization's own document management systems, not locked inside a vendor's SaaS tool. Once delivered, every document in this bundle belongs to the buyer.
What Problems Does The CFD Bundle 2 Solve?
Organizations pursuing ISO 27001 certification or aligning with ISO 27001/27002 quickly run into a problem: policies and procedures alone are not enough. ISO 27001 certification auditors, customer security reviews, and TPRM evaluations ask about risk management, incident response, vulnerability management, business continuity, and supply chain. The CFD Bundle 2 is designed to close these gaps with a single coordinated bundle.
Scattered Documentation
Most organizations have policies in one place, procedures in another, and program-level documents (if they exist at all) written by different people in different styles. CFD Bundle 2 delivers them all in a coordinated, consistent format with shared vocabulary and structure.
ISO 27001 Audit Completeness
CFD Bundle 2 pairs the CDPP and CSOP with program-level documentation so ISO 27001 certification auditors get a complete picture across every Annex A control domain, not just policies and procedures.
Faster Program Stand-Up
Building this level of documentation in-house typically takes 2,500+ hours over 12-18 months. The CFD Bundle 2 provides a professionally-written baseline that can be customized in a fraction of that time.
How Does The CFD Bundle 2 Solve These Problems?
The CFD Bundle 2 delivers a pre-assembled, coordinated set of ISO 27001:2022 and ISO 27002:2022-aligned products covering policies, procedures, and all major program-level domains expected of a certifiable Information Security Management System (ISMS).
Coordinated Content
All products are written by ComplianceForge using a single voice, shared vocabulary, and consistent structure. The CSOP provides 1-to-1 procedure mapping to CDPP standards, and program documents (RMP, VPMP, IIRP, COOP, SBC, C-SCRM SIP, DPP) reference the CDPP and CSOP.
Certification-Ready Documentation
All 10 documents are written to withstand scrutiny by ISO 27001 certification auditors, external assessors, and TPRM evaluations. Every document maps to ISO 27001:2022 and cross-references NIST 800-53, NIST CSF, CMMC, and other leading frameworks.
Same-Day Delivery
ComplianceForge processes most orders the same business day. Expect delivery within 1-2 business days of purchase, with all products arriving together via email download link.
What Is Included In The CFD Bundle 2?
The CFD Bundle 2 includes 10 ComplianceForge products delivered together as a discounted bundle. Each product listed below is a complete, standalone deliverable. The bundle discount applies because these products are frequently purchased together by organizations building a complete ISO 27001:2022-aligned ISMS.











Cost Savings Estimate - CFD Bundle 2
When you look at the costs associated with either (1) hiring an external consultant to write cybersecurity documentation for you or (2) tasking your internal staff to write it, the cost comparisons paint a clear picture that buying from ComplianceForge is the logical option. Compared to hiring a consultant, you can save months of wait time and tens of thousands of dollars. Whereas, compared to writing your own documentation, you can potentially save hundreds of work hours and the associated cost of lost productivity. Purchasing this bundle from ComplianceForge offers these fundamental advantages when compared to the other options for obtaining quality cybersecurity documentation:
Internal Staff Cost
For your internal staff to generate comparable documentation, it would take them an estimated 2,700 internal staff work hours, which equates to a cost of approximately $255,250 in staff-related expenses. This is about 15-30 months of development time where your staff would be diverted from other work.
The CFD Bundle 2 is approximately 8% of the cost for your internal staff to generate equivalent documentation.
External Consultant Cost
If you hire a consultant to generate this documentation, it would take them an estimated 1,800 contractor work hours, which equates to a cost of approximately $566,500. This is about 18-24 months of development time for a contractor to provide you with the deliverable.
The CFD Bundle 2 is approximately 4% of the cost for an external consultant to generate equivalent documentation.

How Much Customization Is Remaining?
ComplianceForge aims for approximately a 90% solution across all 10 products in the bundle. ComplianceForge did the heavy lifting, and the remaining work is to fine-tune the CFD Bundle 2 documentation with the specific information that only your organization knows.
In practice, customization is essentially filling in the blanks and following the guidance provided to identify the who, what, when, where, why, and how for your specific environment. Typical tasks include adding your company name and logo (applied automatically to all documents), tailoring parameters such as review cadences and thresholds, naming specific owner roles for each program, defining the ISMS scope statement, completing program-specific scoping (RPO/RTO targets in COOP, severity tiers in IIRP, patching SLAs in VPMP), and removing sections that do not apply to your organization.
Professional Services
ComplianceForge offers optional professional services to customize purchased documentation. Professional services are not required to customize ComplianceForge documentation. However, some clients want our subject matter expertise to help customize their documentation to meet their specific business needs. If you have any questions about our professional services, please contact us at:
We offer the following professional service bundles:
5-Hour Bundle
This includes five (5) hours of professional services, which may be beneficial for companies that need some guidance on getting started with how to tailor their documentation.
10-Hour Bundle
This includes ten (10) hours of professional services, which may be beneficial for companies that need additional guidance on tailoring their documentation to meet their compliance requirements.
20-Hour Bundle
This includes twenty (20) hours of professional services, which may be beneficial for companies that need robust services, beyond just 10 hours, to assist in tailoring their documentation to meet their compliance requirements.
Purchased professional service hours expire 120 days (4 months) from the time of purchase if unused. Hours are intended to supplement, not replace, your own customization work, since only your organization knows the exact details to tailor your documentation. For questions regarding scoping a professional services engagement or configuring a custom package, contact ComplianceForge directly through the Contact Us page.
ISO 27001:2022 and ISO 27002:2022 Coverage
The CFD Bundle 2 is built around ISO 27001:2022 and ISO 27002:2022, the most current versions of the international cybersecurity management standard. ISO 27002 was restructured in 2022, going from fourteen sections to just three (Organizational, People, Physical, and Technological controls). The 10 products in this bundle collectively address the ISMS clauses in ISO 27001 and the Annex A controls catalogued in ISO 27002.
Where the PSP-tier bundle (PSP Bundle 2) covers policies and procedures, the CFD Bundle 2 expands to deliver the full operational picture: risk management (ISO 27005), incident response (ISO 27035), business continuity (ISO 22301), supply chain risk, and privacy (ISO 27701). ISO 27001 is the world's most widely adopted cybersecurity standard, particularly outside the United States. Organizations can pursue formal ISO 27001 certification - and this bundle provides the documentation foundation to support that certification effort. Cross-references to NIST 800-53, NIST CSF, CMMC, and other frameworks provide flexibility for organizations subject to multiple compliance obligations.
Need A Custom Bundle?
The CFD Bundle 2 covers the most common ISO 27001 near-turnkey configuration, but every organization's needs are different. ComplianceForge will build a custom bundle for any combination of products if your requirements differ from the standard bundles.
If you need different framework alignment (NIST CSF, NIST 800-53, or SCF), consider one of the other CFD bundles or the SCF/DSP bundles. If you need fewer products, consider the PSP-tier bundle. To request a custom bundle quote, contact ComplianceForge directly with a list of products you need and your timeline.



