Regulatory Templates

A core part of compliance management in Microsoft Purview is the use of regulatory templates. The purpose of these templates is to help organizations establish and document compliance with relevant laws, regulations, and standards. A regulatory template consists of a set of improvement actions derived from a specific law or standard. By implementing these improvement actions, the organization can demonstrate compliance.

The list of regulatory templates expands over time as new laws and standards are adopted. A complete and up-to-date list of available templates can be found on Microsoft’s website. Only the Data Protection Framework template is included by default in Compliance Manager.

E5 subscribers have access to three premium templates

If your organization has Microsoft Purview E5 Compliance licenses or Microsoft 365 E5 licenses, you can enable up to three premium templates. Only admins who work with compliance management need such licenses.

You can verify this by navigating to Compliance Manager → Regulations. Here you will see the number of free regulatory licenses available, for example 0/3. Regulatory licenses represent the ability to add additional templates. Here we can se an organization that has enabled two of the three available templates:

Popular regulations in Europe include:

  • ISO 27001:2022
  • EU GDPR
  • EU NIS2
  • EU Artificial Intelligence Act
  • NIST CSF 2.0

Let’s take a closer look at the top three on this list.

ISO 27001:2022 regulation

This regulatory template is relevant for organizations that have implemented an ISO 27001–based Information Security Management System (ISMS). In this context, it is useful to gain a structured overview of what should be configured and implemented in the Microsoft 365 tenant to support compliance with the standard.

Below, we see the ISO 27001 regulation and the improvement actions related to clause 4 (Context of the organization).

As of January 2026, the regulation consists of 265 improvement actions, of which 110 can be implemented by the organization (yes, this is a big one!).This covers the requirements in chapter 4-10, and the security controls in Annex A.

EU GDPR regulation

GDPR imposes obligations on data controllers and data processors, and grants rights to data subjects. As of January 2026, the regulation consists of 49 improvement actions, of which 24 can be implemented by the organization.

NIS2 regulation

Unlike GDPR, which is a regulation that applies directly, NIS2 is a directive. Directives set minimum requirements that Member States must transpose into national legislation, while allowing each country to introduce stricter or more detailed national provisions.

As a consequence, premium regulatory templates in Microsoft Purview cannot fully capture the national adaptations that will emerge when NIS2 is implemented at the national level. As of January 2026, the regulation consists of 96 improvement actions, of which 11 can be implemented by the organization. In practice, these improvement actions are somewhat difficult to interpret, and they do not fully reflect the substantive security requirements of the directive. For example, the security measures set out in Article 21 are not explicitly covered by the improvement actions.

As we can see, premium regulatory templates help organizations work systematically toward compliance with various laws and standards. Each template consists of a set of improvement actions that organizations can implement and track over time.

These templates are also customizable! Organizations can mark improvement actions as not applicable where they are clearly irrelevant, rename customer-managed actions for clarity, and add their own improvement actions to reflect organization-specific or national requirements. I´ve covered customizable premium templates in another article.