Vironix Comply

Every obligation tracked.
Every audit ready.

A single system for managing regulatory obligations across NDPA, ISO 27001, CBN, AML/CFT, and more. Maintain a continuous ROPA, prepare for audits, and log DPO activity without a last-minute scramble.

Multi-Framework Coverage

Six regulatory frameworks in one platform, mapped to your obligations.

Most Nigerian organisations face obligations under several frameworks simultaneously. NDPA, the CBN Risk-Based Cybersecurity Framework, ISO 27001, AML/CFT, the Cybercrimes Act, and PCI DSS each carry specific requirements, deadlines, and evidence standards. Vironix Comply maps every obligation in every framework you operate under into a single obligation register.

Obligations are maintained by Vironix as frameworks are updated. When a framework changes, your obligation register updates accordingly. You are not managing a static spreadsheet. The platform reflects what is currently required of you.

Frameworks Covered
NDPACBN Risk-Based Cybersecurity FrameworkISO 27001AML/CFTCybercrimes ActPCI DSS
Compliance Frameworks View
Vironix Comply compliance frameworks view showing NDPA and CBN obligations mapped to their current status and evidence requirements

Continuous Record of Processing Activities

A live ROPA that stays accurate beyond the audit preparation window.

Most organisations update their Record of Processing Activities in the weeks before an audit and then leave it to drift. Vironix Comply maintains your ROPA as a live document, updated as processing activities are added, changed, or discontinued.

Each processing activity record captures the legal basis, data categories, retention periods, third-party processors, and cross-border transfer status. Changes are version-controlled with the date and the user who made the update. The ROPA is audit-ready at any point in the year, not just in Q4 preparation.

Features
Live processing activity records with version historyLegal basis, retention, and transfer status per activityThird-party processor linkingExport in NDPC-standard ROPA format

Breach Notification Generator

Meet the 72-hour notification requirement without building a process from scratch.

A data breach triggers a 72-hour notification obligation to the NDPC under NDPA. Most organisations have no documented process for producing that notification. The Breach Notification Generator walks your team through every required element.

Input the incident details, the categories of data affected, the number of data subjects, and any containment actions taken. The generator produces a draft notification document that meets NDPC requirements, with all required fields completed and nothing omitted. Legal review before submission is still recommended. The generator ensures nothing is missed in the draft.

Features
NDPC-standard breach notification templateStep-by-step incident data collection72-hour clock with notification deadline trackerDraft export for legal review prior to submission

DPO Activity Tracking

A structured record of everything your Data Protection Officer has done.

The NDPA requires organisations above certain thresholds to designate a Data Protection Officer and ensure they carry out defined activities. DPO Activity Tracking maintains a log of every formal DPO action: audits conducted, policies reviewed, staff training delivered, complaints handled, and regulatory correspondence filed.

Each activity is timestamped, categorised, and linked to supporting evidence. The log generates a summary report exportable for regulatory submission, demonstrating that the DPO role is substantive and not nominal.

Features
Structured log of all DPO activities by typeEvidence attachment per activity recordSummary report for regulatory submissionDPO appointment and renewal documentation
Platform Dashboard
Vironix Comply main dashboard showing overall compliance status across active frameworks with obligation counts and completion rates

Policy Generator

Draft compliant policies without starting from a blank page.

Vironix Comply includes a policy generator for the documents NDPA and related frameworks require. Input your organisation details, processing scope, and specific configurations, and the generator produces a draft policy document that meets the regulatory minimum.

Available policies include the Privacy Notice, Data Retention Schedule, Acceptable Use Policy, Data Breach Response Procedure, and Data Processing Agreement template. Each draft is structured for legal or compliance review before adoption. The generator eliminates the blank-page problem. A reviewer ensures it reflects your actual practice.

Features
Privacy Notice generatorData Retention Schedule generatorAcceptable Use Policy templateData Breach Response ProcedureData Processing Agreement template

CAR Preparation

Produce your annual NDPC submission without a last-minute scramble.

The NDPC requires organisations to file an annual Compliance Audit Report. Vironix Comply draws on your live ROPA, DPO activity log, breach records, and policy documentation to pre-populate the CAR template with information already held in the platform.

A checklist tracks which CAR elements are complete, which are in progress, and which require additional evidence. The output is a fully populated draft report ready for legal or compliance sign-off before submission.

Features
Pre-population from existing platform recordsCAR completion checklist with status trackingEvidence gap identification per CAR sectionDraft export for sign-off prior to NDPC submission

External Auditor Portal

Give auditors what they need without giving them access to everything.

When an external auditor or regulatory inspector requires access to your compliance records, the External Auditor Portal generates a time-limited, read-only view scoped to the relevant frameworks and date ranges. The auditor sees what is needed for the engagement. Nothing more.

Access is granted by invitation. The portal session is logged, including which documents were accessed and when. When the session expires, access closes automatically. The internal record of the audit visit, what was shared and with whom, is retained permanently.

Features
Time-limited read-only access by invitationScope-limited to relevant frameworks and recordsFull session log: documents accessed and timestampsAutomatic access revocation on session expiry
Pricing

Simple, transparent pricing.
No hidden fees.

Starter
NGN49,900
per month
Start Free Trial
What's Included
Up to 5 users3 regulatory frameworksROPA managementBreach notification generatorPolicy generatorEmail support
Most Popular
Growth
NGN99,900
per month
Start Free Trial
What's Included
Up to 20 usersAll 6 regulatory frameworksROPA managementBreach notification generatorDPO activity trackingPolicy generatorCAR preparationExternal auditor portalPriority email and phone support
Enterprise
NGN199,900
per month
Start Free Trial
What's Included
Unlimited usersAll 6 regulatory frameworksAll Growth featuresExternal auditor portal (full access)Dedicated customer success managerCustom framework additionsOn-site onboarding sessionSLA-backed support
Questions

Frequently asked

NDPA, the CBN Risk-Based Cybersecurity Framework, ISO 27001, AML/CFT, the Cybercrimes Act, and PCI DSS, and you only enable what genuinely applies to your institution.

From real, confirmed records across whichever frameworks you have active, never from a draft still waiting for a human to check it.

Every AI-drafted policy or notification is exactly that, a draft, reviewed and approved by you before it becomes a real record. Nothing gets submitted or sent on the platform's own authority.

Yes, a scoped, time-limited link that shows only confirmed data, never anything still pending review.

Yes, framework selection is self-service from your own settings, no re-onboarding needed.

Free Tool

Not sure where you stand on data risk? Take the free diagnostic first.

Fifteen questions, scored instantly. Understand your current compliance and data protection exposure before committing to a platform.

Take the Free Diagnostic
Insider risk doesn't wait.
Neither should your defences.

Book a confidential 30-minute consultation. No obligation, no sales pitch.

Book a Consultation