Maurice Müller
Senior Content Manager
Maurice Müller is a journalist and content strategist with experience across print and digital media. At Formalize, he translates complex compliance and regulatory topics into clear, practical content for compliance, risk, and security professionals across Europe.
Key takeaways:
Formalize is opening its GRC platform to partners, consultancies, law firms, and specialist advisors, so they can co-build ready-to-deploy compliance blueprints instead of every organization starting from a blank page.
The Marketplace launches with two blueprints: a NIS2 blueprint for Denmark, built with Implement Consulting Group, and a CSG/CSV (NIS2-Liechtenstein) blueprint, built with Bonafide Partners Group AG.
A blueprint arrives pre-mapped: requirements, controls, tasks, and policies already in place, and depending on the blueprint, questionnaires, workflows, and a compliance dashboard too.
Blueprints don't replace the judgment a compliance team brings to its work. They remove the blank-page problem of translating a regulation into daily operations.
Two blueprints are live today. More partners, regulations, and markets are already in motion behind them.
What is the Formalize Marketplace?
The Formalize Marketplace is a way for partners, consultancies, law firms, and other domain experts, to co-build compliance blueprints directly on Formalize's platform, and make them available to organizations that need them.
A blueprint is a structured, expert-built starting point for a specific regulation in a specific market, built directly into the platform rather than bolted on as a separate integration or plug-in: requirements mapped to concrete tasks, policies already drafted, a risk register already populated, and depending on the blueprint, supporting questionnaires, workflows, and dashboards. An organization deploys the blueprint into its own Formalize instance and adapts it, instead of starting the mapping work from a blank page.
This matters because most regulations don't specify how compliance should look in practice. NIS2 is a useful example. It's an EU directive, so the underlying obligations are common across member states, but each country transposes it into its own national law, with its own documentation expectations and its own supervisory approach. Two organizations facing "the same" regulation can end up with very different operational requirements, depending on where they're based.
Why build a marketplace for compliance blueprints?
Generic compliance software is built to flex across industries, countries, and frameworks. That flexibility is useful, but it also means the hardest part of the work, deciding what's critical, what needs to be documented, and what a specific market's supervisory authority actually expects to see, still lands on the compliance team, or gets outsourced to a one-off consulting engagement.
That work doesn't scale well. A consultancy that has already built a rigorous interpretation of a regulation for one client is, in the current model, mostly starting over for the next one. Meanwhile, organizations facing the same regulation in the same market are independently reaching similar starting points, each spending their own time and budget to get there.
The Marketplace is built to change that dynamic on both sides. Partners can turn work they've already done, their interpretation of a regulation, structured as tasks, policies, and controls, into something reusable, instead of re-delivering it as billable hours on every engagement. Organizations get a vetted, expert-built starting point instead of building one from scratch or commissioning it individually.
What's in the first two blueprints?
The Marketplace launches with two live blueprints, both addressing national implementations of NIS2. Both are fully built, tested, and live inside the platform today. Here's what's in each one:
NIS2 for Denmark, built with Implement Consulting Group
NIS2 covers an estimated 6,000 organizations in Denmark, but only a fraction have completed implementation. The blueprint built with Implement Consulting Group translates the Danish law's 17 requirements into 95 concrete, documentable points, the level of detail an organization needs to be able to show a supervisory authority during an inspection.
The work is broken down into 79 individual tasks, each with a named owner, along with ready-drafted policies, a populated risk register, and an implementation guide, so teams aren't left guessing what to tackle first.
CSG/CSV (NIS2-Liechtenstein), built with Bonafide Partners Group AG
The second blueprint addresses Liechtenstein's national implementation of NIS2: the Cyber-Sicherheitsgesetz (CSG) and its accompanying ordinance, the Cyber-Sicherheitsverordnung (CSV), built together with Bonafide Partners Group AG.
It's a larger, more granular package: 174 requirements mapped to 38 controls and 42 tasks, supported by 6 questionnaires and 7 workflows, an implementation guide, and a compliance dashboard to track progress against the requirements in one view.
Together, the two blueprints show the range the Marketplace is built to support, from a leaner, task-first setup to a more extensive one with dedicated assessment and monitoring tooling, depending on what a given regulation and market require.
How does a blueprint fit into the Formalize platform?
Blueprints aren't a separate product bolted onto Formalize. They run on the same infrastructure organizations already use for NIS2, DORA, ISO 27001, the GDPR, and other frameworks. Deploying a blueprint means the tasks, policies, and risk register land inside the same platform where a team already manages its broader compliance program, not in a separate tool that needs to be reconciled with everything else.
For organizations already running Formalize, that means a blueprint is additive. It accelerates the specific regulation it covers without changing how the rest of the compliance program is managed.
What's next for the Marketplace?
The goal from here is a growing library: more European frameworks, more markets, built over time by partners who know the specific regulation inside and out. As more partners join, more industries and regions gain access to blueprints built by the people closest to that regulatory reality.
None of this is about replacing the judgment a compliance team brings to its work. It's about removing the busywork that stands between that judgment and the regulation, without cutting corners on the safeguards the regulation exists to protect.
How to get started
If your organization needs to operationalize NIS2 in Denmark or Liechtenstein, both blueprints are available now inside Formalize. Book a walkthrough to see how a blueprint deploys into your instance, or explore the NIS2 compliance platform to see how it fits into your broader compliance program.
If you're a consultancy, law firm, or advisory practice interested in co-building a blueprint, the Formalize Partner Program is the place to start.