Downloadable Word/Excel template kits for the EU Cyber Resilience Act, DORA, NIS2, PCI DSS and the AI Act. Built and maintained by a practicing CISO, version-stamped against the regulation text with a public changelog. Buy once, download instantly, adapt.
No reviews yetBe the first to leave a review for VARVICO
Maker
π
Hi Product Hunt π
I run security at an EU-regulated fintech. Every regulation that lands on my desk β DORA, NIS2, now the Cyber Resilience Act β needs the same thing before any
real security work starts: a pile of documents. Policies, registers, runbooks, declarations. Everyone writes them from scratch, badly, under deadline pressure.
Some of you may remember my DORA Toolkit launch here β VARVICO is its successor, expanded to five EU frameworks.
VARVICO is that pile of documents, already written: editable Word/Excel kits for the CRA, DORA, NIS2, PCI DSS and the EU AI Act. You buy once, download
instantly, and adapt them to your business.
The timely one is the CRA: Article 14 incident reporting starts 11 September 2026 for anyone selling products with digital elements in the EU β and importers and
distributors have real duties that almost nobody writes templates for. That gap is why this exists.
Three honest things:
1. These are practitioner-built templates, not legal advice β every document says so, and the high-liability ones have sign-off fields for your own legal review.
2. Every kit carries a Currency Stamp β a version and "current as of" date backed by a public changelog β so you know exactly what regulation text it tracks.
3. There's a β¬24 quick-start if you want to see the quality before committing to a full kit. 30-day money-back either way.
I'd especially love to hear from anyone wrestling with the CRA as an importer or distributor β that's the corner of this nobody talks about. Ask me anything.
Report
Congratulations on the launch! A question on the AI Act kit specifically: does it cover the lighter end, a small company that doesn't ship AI features but uses AI for things like generated images or marketing content?
Yes, that lighter-end scenario is covered. If a small company is not shipping AI features, but is using tools like image generators, copywriting tools, or marketing/content assistants, it is usually acting as a deployer rather than a provider.
In practice, that normally means a much lighter AI Act footprint than a company building or selling AI systems. The main things to document are usually:
AI literacy: making sure staff who use AI tools understand the basics, risks and limits.
Transparency: checking whether AI-generated or manipulated content needs disclosure, especially if it could be mistaken for authentic content.
Boundary checks: making sure the company is not accidentally using AI in higher-risk areas such as recruitment, worker monitoring, credit/customer scoring, education access, or other Annex III-style use cases.
That is exactly why the kit starts with the Risk-Classification Workbook and the Provider/Deployer Obligations Matrix. For a company that only uses AI for marketing content, the output will often be a light deployer record rather than a heavy compliance programme.
Honest buying advice: if that is the whole AI footprint, they probably do not need the Complete kit. The Risk-Classification Workbook + Obligations Matrix is usually the right starting point
Congratulations on the launch! A question on the AI Act kit specifically: does it cover the lighter end, a small company that doesn't ship AI features but uses AI for things like generated images or marketing content?
@alieksiaΒ Thanks Anastasiia β great question.
Yes, that lighter-end scenario is covered. If a small company is not shipping AI features, but is using tools like image generators, copywriting tools, or marketing/content assistants, it is usually acting as a deployer rather than a provider.
In practice, that normally means a much lighter AI Act footprint than a company building or selling AI systems. The main things to document are usually:
AI literacy: making sure staff who use AI tools understand the basics, risks and limits.
Transparency: checking whether AI-generated or manipulated content needs disclosure, especially if it could be mistaken for authentic content.
Boundary checks: making sure the company is not accidentally using AI in higher-risk areas such as recruitment, worker monitoring, credit/customer scoring, education access, or other Annex III-style use cases.
That is exactly why the kit starts with the Risk-Classification Workbook and the Provider/Deployer Obligations Matrix. For a company that only uses AI for marketing content, the output will often be a light deployer record rather than a heavy compliance programme.
Honest buying advice: if that is the whole AI footprint, they probably do not need the Complete kit. The Risk-Classification Workbook + Obligations Matrix is usually the right starting point