Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient - No AI Slop!
Secure Controls Framework
No items found.
PSP Bundle 2: ISO 27001 / 27002
$ 5,344.00 USD
$ 6,680.00 USD
This is a bundle that includes two (2) ComplianceForge products that are focused on operationalizing NIST SP 800-53 R5 (low, moderate & high baselines).
Product Category:
Policies, Standards & Procedures
SKU:
PSP-B2
Availability:
Email Delivery Within 1-2 Business Days
ComplianceForge documentation is written to follow industry-recognized secure practices, but you are still expected to tailor the documentation to suit your organization's specific security, compliance & resilience requirements. By providing your company name and your logo (your logo is optional), we tailor the documentation to include this information.
How Do I Request A Quote?
To request a quote, select the "Request a Quote" button beside the "Add To Cart" button. This will direct you to a page where you can request a custom quote.
Can I Pay By Invoice?
Yes. To pay by invoice, add the product to your cart, go through the checkout process, and fill out your billing information. Once you get to the payment method, select "Offline Payment via Invoice / Purchase Order (PO)" and then select "Place Order."
Can I Pay By Wire / ACH?
Yes. To pay by Wire / ACH, you can request an invoice by following the instructions above. Once you have the invoice, it will contain the necessary info for you to finalize payment by Wire / ACH.
No logo uploaded. Maximum file size: 5 MB. Acceptable file types: PNG, JPG, JPEG, GIF, BMP, TIFF, WEBP, SVG.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Bundle Summary: PSP Bundle #2   (2 Products)
  • Policies & Standards - ISO 27001 / 27002
  • Procedures - ISO 27001 / 27002
Product Overview

Don't Write It From Scratch.

If a certification auditor or customer asked for your ISO 27001 policies, standards, and procedures today, could you hand them over, or would you be writing from a blank page? PSP Bundle 2 gives you a running start: the foundational documentation layer for an ISO 27001 ISMS, ready to tailor rather than author, getting you roughly 80 to 90 percent of the way there from day one.

An ISO 27001 ISMS is built on documented policies, standards, and procedures: the layer that defines what your program requires and proves how the ISO 27002 controls are actually performed. Writing that foundation from scratch, mapped to the ISO 27002:2022 control set, is exactly the slow, specialized work most teams want to avoid.

PSP Bundle 2 is ComplianceForge's foundational Policies, Standards and Procedures bundle for ISO 27001:2022 and ISO 27002:2022. It pairs the ISO version of the Cybersecurity & Data Protection Program (CDPP), which provides the policies and standards, with the matching Cybersecurity Standardized Operating Procedures (CSOP), which provides the procedures, so your governance and operational documentation line up out of the box.

It is the most efficient starting point for organizations pursuing ISO 27001:2022 certification or aligning with ISO 27001/27002, particularly those operating internationally where ISO is the dominant framework. Your team tailors the templates to your environment and reaches a defensible ISMS foundation in far less time than writing it from scratch.

What Is The PSP Bundle 2?

What Is The PSP Bundle 2?

PSP Bundle 2 is the foundational tier of ComplianceForge's ISO 27001/27002 documentation: the policies and standards (CDPP) plus the matching procedures (CSOP) in one coordinated set. Where the CFD bundles extend across the full program (risk, incident response, continuity, configurations, supply chain, and privacy), the PSP tier focuses on the policies, standards, and procedures layer an ISMS is built on.

It is built for organizations that need ISO 27001:2022 and ISO 27002:2022-aligned documentation, whether for formal ISO 27001 certification, internationally focused operations, or alignment with what is widely treated as the de facto cybersecurity framework outside the United States.

Both documents are tailored to ISO 27001:2022 and ISO 27002:2022 and cross-reference NIST 800-53, NIST CSF, and other leading frameworks, so the documentation supports ISO certification while staying flexible if your obligations later include US-based frameworks.

How It's Delivered

No Software To Install

This bundle is a one-time purchase of editable Microsoft Office-based documentation templates. There is no software to install, no agent to deploy, no account to provision, and no cloud environment to configure. If your organization can open and edit Microsoft Word or Excel files (or compatible tools like OpenOffice and Google Workspace), you can use both products in this bundle.

Microsoft Word and Excel

Delivered as fully editable .docx and .xlsx files. Compatible with Word 2016 and newer, Microsoft 365, OpenOffice, LibreOffice, and Google Docs/Sheets.

Email Delivery

Both products in the bundle are delivered via email download link within 1-2 business days of purchase. There is no installer, no license server, and no activation step.

One-Time Purchase

A single-entity license is included with purchase. The bundle price is a one-time charge. No subscriptions required for the CDPP or CSOP ISO version.

This deployment model is intentional. Cybersecurity documentation belongs in the organization's own document management systems, not locked inside a vendor's SaaS tool. Once delivered, every document in this bundle belongs to the buyer.

The Problem

What Problems Does The PSP Bundle 2 Solve?

Organizations pursuing ISO 27001 certification or aligning with ISO 27001/27002 typically need policies and procedures that work together and map directly to ISO 27001:2022 Annex A controls. The PSP Bundle 2 is designed to solve these challenges.

ISO 27001:2022 Alignment

Both documents map directly to ISO 27001:2022 and ISO 27002:2022 Annex A controls - reflecting the updated 2022 control set that reorganized ISO 27002 from fourteen sections down to three. No bolt-on work is required for ISO alignment.

Coordinated Policies and Procedures

The CDPP and CSOP are designed to work together, with the CSOP providing 1-to-1 procedure mapping to CDPP standards. There are no orphan controls and no inconsistencies between the policy and procedure layers - critical for ISO 27001 certification audits.

Faster Program Stand-Up

Building ISO-aligned documentation in-house typically takes 1,000+ hours. The PSP Bundle 2 provides a professionally-written baseline that can be customized in a fraction of that time, accelerating ISMS stand-up.

The Solution

How Does The PSP Bundle 2 Solve These Problems?

The PSP Bundle 2 delivers a pre-assembled, coordinated set of two ISO 27001:2022 and ISO 27002:2022-aligned products that together establish the policy, standards, and procedure foundation for an Information Security Management System (ISMS).

ISO 27001:2022 and ISO 27002:2022-Aligned Documentation

Both products are tailored to the 2022 versions of ISO 27001 and ISO 27002 and cross-reference NIST 800-53, NIST CSF, and other leading frameworks for flexibility as compliance obligations evolve.

Certification-Ready Documentation

Both documents are written to withstand scrutiny by external assessors and ISO 27001 certification auditors. The CDPP provides policy and standard guidance and the CSOP provides 1-to-1 procedure-to-standard mapping for evidence of implementation.

Same-Day Delivery

ComplianceForge processes most orders the same business day. Expect delivery within 1-2 business days of purchase, with both products arriving together.

What You Get

What Is Included In The PSP Bundle 2?

The PSP Bundle 2 includes 2 ComplianceForge products delivered together as a discounted bundle. Each product listed below is a complete, standalone deliverable. The bundle discount applies because these products are frequently purchased together by organizations pursuing ISO 27001 alignment or certification.

$ 1,980.00 USD
Policies & Standards - ISO 27001 / 27002
This version of the Cybersecurity & Data Protection Program (CDPP) is based on the ISO 27001 / 27002 framework. It contains the necessary ISO 27001 / 27002 policies and standards that help achieve compliance. You get fully-editable Microsoft Word and Excel documents that you can customize for your specific needs.
Contains:
Word
Excel
PowerPoint
PDF
Examples:
Word Example
Excel Example
$ 4,700.00 USD
Procedures - ISO 27001 / 27002
This version of the Cybersecurity Standardized Operating Procedures (CSOP) is based on the ISO 27001 / 27002 framework. It contains the necessary ISO 27001 / 27002 procedures that help achieve compliance with ISO 27001 / 27002. You get fully-editable Microsoft Word documents that you can customize for your specific needs.
Contains:
Word
Excel
PowerPoint
PDF
Examples:
Word Example
Excel Example
Your ROI

Cost Savings Estimate - PSP Bundle 2

When you look at the costs associated with either (1) hiring an external consultant to write cybersecurity documentation for you or (2) tasking your internal staff to write it, the cost comparisons paint a clear picture that buying from ComplianceForge is the logical option. Compared to hiring a consultant, you can save months of wait time and tens of thousands of dollars. Whereas, compared to writing your own documentation, you can potentially save hundreds of work hours and the associated cost of lost productivity. Purchasing this bundle from ComplianceForge offers these fundamental advantages when compared to the other options for obtaining quality cybersecurity documentation:

Internal Staff Cost

For your internal staff to generate comparable documentation, it would take them an estimated 1,000 internal staff work hours, which equates to a cost of approximately $94,500 staff-related expenses. This is about 12-24 months of development time where your staff would be diverted from other work.

The PSP Bundle 2 is approximately 5% of the cost for your internal staff to generate equivalent documentation.

External Consultant Cost

If you hire a consultant to generate this documentation, it would take them an estimated 700 contractor work hours, which equates to a cost of approximately $222,000. This is about 9-18 months of development time for a contractor to provide you with the deliverable.

The PSP Bundle 2 is approximately 2% of the cost for an external consultant to generate equivalent documentation.

Your Effort

How Much Customization Is Remaining?

ComplianceForge aims for approximately an 80 - 90% solution across both products in the bundle. ComplianceForge did the heavy lifting, and the remaining work is to fine-tune the PSP Bundle 2 documentation with the specific information that only your organization knows.

In practice, customization is essentially filling in the blanks and following the guidance provided to identify the who, what, when, where, why, and how for your specific environment. Typical tasks include adding your company name and logo (applied automatically to both documents), tailoring parameters such as review cadences and thresholds, naming specific owner roles, defining the ISMS scope statement, and removing sections that do not apply to your organization.

Need A Hand?

Professional Services

ComplianceForge offers optional professional services to customize purchased documentation. Professional services are not required to customize ComplianceForge documentation. However, some clients want our subject matter expertise to help customize their documentation to meet their specific business needs. If you have any questions about our professional services, please contact us at:

We offer the following professional service bundles:

5-Hour Bundle

This includes five (5) hours of professional services, which may be beneficial for companies that need some guidance on getting started with how to tailor their documentation.

10-Hour Bundle

This includes ten (10) hours of professional services, which may be beneficial for companies that need additional guidance on tailoring their documentation to meet their compliance requirements.

20-Hour Bundle

This includes twenty (20) hours of professional services, which may be beneficial for companies that need robust services, beyond just 10 hours, to assist in tailoring their documentation to meet their compliance requirements.

Important Details About Professional Services

Purchased professional service hours expire 120 days (4 months) from the time of purchase if unused. Hours are intended to supplement, not replace, your own customization work, since only your organization knows the exact details to tailor your documentation. For questions regarding scoping a professional services engagement or configuring a custom package, contact ComplianceForge directly through the Contact Us page.

Framework Coverage

ISO 27001:2022 and ISO 27002:2022 Coverage

The PSP Bundle 2 is built around ISO 27001:2022 and ISO 27002:2022, the most current versions of the international cybersecurity management standard. ISO 27002 was restructured in 2022, going from fourteen sections to just three (Organizational, People, Physical, and Technological controls).

ISO 27001 is the world's most widely adopted cybersecurity standard, particularly outside the United States. Organizations can pursue formal ISO 27001 certification, which requires demonstrating that documented controls in ISO 27002 are implemented. This bundle provides both the policies/standards (CDPP) and procedures (CSOP) aligned with the 2022 control set, supporting certification efforts. Cross-references to NIST 800-53, NIST CSF, and other frameworks provide flexibility for organizations subject to multiple compliance obligations.

Custom Bundle Option

Need A Custom Bundle?

The PSP Bundle 2 covers the most common ISO 27001/27002 starter configuration, but every organization's needs are different. ComplianceForge will build a custom bundle for any combination of products if your requirements differ from the standard bundles.

If you need additional operational documentation beyond policies, standards, and procedures (such as risk management, vulnerability management, incident response, or supply chain risk to support ISO 27001 Annex A.5 and beyond), consider stepping up to a Near-Turnkey ISO bundle which adds program-level products. To request a custom bundle quote, contact ComplianceForge directly with a list of products you need and your timeline.

Testimonials

What Are Some Of Our Testimonials?

❛❛
Excellent Starting Point
ComplianceForge's SCF-based policy documentation offers consolidated coverage of security and privacy controls requirements in a single, cohesive package. Because it's built on the Secure Controls Framework, a metaframework that tracks security and privacy standards globally and releases quarterly updates, it gives organizations confidence that their documentation stays current as requirements evolve. For any organization standing up a security and privacy program from scratch, it's provides an excellent starting point.
Would You Like To Share Your Experiences?
If you are satisfied with your product and would like to leave a review, please fill out our testimonial form and share your experiences with our documentation! We enjoy hearing from satisfied customers, and we are always open to constructive feedback so that we can continue improving our products.