Customizing Regulatory Templates

n Compliance Manager, regulatory templates consist of a set of improvement actions derived from the requirements of a law or a standard. Some of these actions must be implemented by the organization itself, while others are already implemented by Microsoft. You can read more about premium templates in a separate article.

Although the improvement actions are defined by Microsoft, there may be a need to adjust the wording of certain actions or to add additional ones. With the ability to customize regulatory templates, we can now tailor them to our own needs.

It is not possible to create an entirely new regulatory template from scratch. Instead, customization must be based on one of the existing templates. Keep in mind that when you customize a template, it is activated and consumes a regulatory license (E5 Purview Suite licenses include access to three regulatory templates).

Customizing the NIS2 regulation template

Let’s use the EU NIS2 Directive template as an example. The first step is to locate the template and customize it. Once the customization is complete and the template is published, we create an assessment based on the customized template. This is the point where the improvement actions are instantiated and start contributing to the Compliance Score.

To get started, we search for the EU NIS2 Directive under Regulations and select Customize regulation. Compliance Manager then creates a copy of the template and appends “Extension” to the title (the title can be changed before the template is published).

Now we can customize the template.

To add this template, we can select the template from the list of regulations, and then click Create Assessment.

Compliance Manager will then create a copy of the template and append “Extension” to the title (the title can be changed after the template has been published).

Now we can customize!

A particularly important provision in the NIS2 Directive is Article 21, which defines the security requirements organizations must comply with. These requirements represent the core obligations for organizations covered by the directive:

However, when we select this control in the template, we see that it does not have any improvement actions associated with it. This is a problem, as the security requirements in Article 21 should clearly be reflected in the template.

At this point, we have two options. We can either define the security requirements as new controls and then associate relevant improvement actions with each control, or we can add improvement actions directly under the existing control. The latter approach is simpler, so let’s focus on that.

The first requirement in Article 21 is point (a): policies on risk analysis and information system security. If you are familiar with information security management systems, you will recognize this as a requirement for top-level policies that define principles for information security and risk assessment.

We can attempt to reuse existing improvement actions by selecting Import actions and searching for “policy”. While several policy-related actions are available, none of them fully address the specific requirement in Article 21. Therefore, we create a new improvement action.

We assign this action 27 points, as it represents a mandatory preventive control. The new improvement action is now part of the customized template. Existing customer-specific actions can be edited or deleted, but Microsoft-implemented actions cannot be modified.

Once we are finished customizing the template, we publish it. At this point, we should expect the Compliance Score to drop, as the newly added improvement actions must now be implemented and tested.

A final word of caution

While customizable regulatory templates are a powerful feature, they also introduce a degree of risk if used without sufficient discipline. It can be tempting to simply add new improvement actions to cover perceived gaps, without first reviewing the actions that already exist in the template.

In practice, this often leads to overlapping or duplicated actions that address the same underlying requirement from slightly different angles. Over time, this can make assessments harder to manage, inflate the number of actions to track, and blur the link between regulatory requirements and actual risk reduction.

Before adding new improvement actions, it is therefore important to carefully review the existing ones, understand their intent, and assess whether the requirement can be addressed by refining or extending what is already there. Customization should be used to clarify and strengthen compliance—not to create unnecessary complexity.