Choosing ISMS software: the four ways to run ISO 27001
Anyone building or replacing an ISMS usually chooses between four ways: Excel and SharePoint built in-house, a point tool covering only ISO 27001, a large GRC suite, or a consulting retainer billed by the hour. Each carries in a specific situation, and each has a point where it breaks. This page compares the four honestly and lists the questions to settle before you decide.
The four ways, compared honestly
The same three questions for every option: What does it carry, where does it break, and what does switching cost once it does?
Excel and SharePoint built in-house
What it carries
For a first certification with a small scope, building it yourself is a legitimate start: full control, no licence cost, no rollout hurdle. Auditors accept clean spreadsheets.
Where it breaks
The cost arrives in operations. Version states, owners, follow-ups and the record of who decided what remain manual work forever. From the second site or legal entity onwards, maintenance turns into archaeology, and every surveillance audit brings similar preparation effort again.
Switching cost later
Instead of a data model there are documents. A later migration therefore resembles a rebuild, and history often only partly comes along.
Point tool covering only ISO 27001
What it carries
Guided structure, a pre-built catalogue, a fast start. If you want to run exactly one standard and nothing else, this is often the shortest path to the certificate.
Where it breaks
As obligations grow, the cut reaches its limits: BCM becomes a second tool, supplier risk a third, awareness a fourth, and sector catalogues wait for the vendor to add them. The data foundation splinters into islands kept in sync by hand.
Switching cost later
One export per island, mapping by hand. Feasible, but every island migrates separately.
Large GRC suite
What it carries
Suites are built for corporations with a dedicated GRC team and group-wide processes: deep workflows and role models for large organisations.
Where it breaks
Rollout and operations assume a dedicated specialist team, and the mid-market quickly pays for complexity it does not use. A known risk: after the rollout, the actual ISMS lives in Excel again because the suite is too heavy for daily work.
Switching cost later
High: suites are strategic commitments with a long horizon. Leaving one is a project of its own.
Consulting retainer by the hour
What it carries
Targeted expertise where it is missing: audit preparation, gap analysis, hard individual questions. Good advice accelerates any of the other options.
Where it breaks
As a permanent operating model, evidence is produced in the project rather than in operations: the report is current on handover day and ages from then on. Open hourly budgets make cost unplannable, and the knowledge about your ISMS lives outside your house.
Switching cost later
The knowledge has to come back in-house. Without a tool to receive it, documentation starts over.
Where the Cybervize platform sits in this comparison
The platform is the fifth way: modules on one data foundation instead of islands, built for operations rather than a one-off audit.
ISMS, BCM, assessment, TPRM and awareness share one data foundation: assessment gaps create measures, BIA data validates continuity plans, training rates become audit evidence.
More than 50 frameworks kept as a catalogue, from ISO 27001 and BSI IT-Grundschutz to sector rules. New catalogues arrive via OSCAL import or are created directly in the platform, without waiting for a vendor.
Operated in Germany. The AI layer runs sovereign on self-operated models, with your own keys, or managed: three operating modes, configurable per tenant.
Multiple sites and legal entities on one data foundation, with site comparison and consolidated evidence. Self-assessments relieve plants during audits, including IEC 62443.
Licensed per module at a fixed annual price. The metric is digitally connected people, with no named-user limit. Entry prices per tier are published on the pricing page.
Senior CISO guidance is bookable where no CISO function is staffed in-house. It complements the product; it is not an hourly model as a permanent state.
These questions separate the options faster than any feature list. Ask every vendor, including us.
1.Where does the control catalogue come from, and how do new standards get in?
Purchased catalogues age with the vendor's release cycle. What matters is whether you can load new or custom catalogues yourself, for instance via OSCAL, the official NIST format.
2.Does the tool carry multiple sites and legal entities on one data foundation?
Retrofitting tenants, plants and subsidiaries is among the most expensive rebuilds. If you have one site today and two tomorrow, ask the question today.
3.Is evidence produced in daily operations, or collected for the audit?
That is the difference between an ISMS and a folder. When measures, risks and training continuously produce audit evidence, preparation before every audit shrinks substantially.
4.Where do data and AI run, and under whose control?
Some tools route compliance data through model providers outside Europe. Clarify data residency, the operating model, and whether the AI data flow can be controlled per tenant.
5.How is the price built: a licence with a clear metric, or open hours?
Comparison starts with the metric. Ask what is counted, what happens as you grow, and whether production workers without a digital identity drive the price.
6.What does the way in cost, and what does the way out cost?
Rollout and migration from your current state are plannable projects. The export at the end is the most honest vendor question: whoever only lets data in has a reason.
What the platform is built for, and what it is not
Built for this
Mid-market and corporate organisations with several obligations at once: ISO 27001 in operation, plus BCM, supplier risk or sector rules such as NIS-2 and DORA.
Organisations with multiple sites or legal entities that need consolidated evidence instead of four island tools.
Manufacturers that want to include plants and OT environments, with self-assessments instead of an audit caravan.
Teams that want to run the ISMS themselves: with their own CISO via the licence, or without one via bookable senior CISO guidance.
Other ways are better for this
You need exactly one certificate for a small scope and as little operation as possible afterwards: a point tool or a clean in-house build is often the leaner way.
Your group has set a GRC suite strategically and group-wide: replacing it is rarely the right project. Worth examining is the assessment module as a complement for plant self-assessments.
You are looking for advisory work only, without a tool: specialised advisory firms serve that, and for crises and vacancies there is our Interim CISO.
See the platform against your requirements
In the demo we show the platform on your case, with your standards and sites. Afterwards you will know whether the fifth way fits your organisation.
A serious answer starts with the model, not a number: point tools are licensed per user or package, GRC suites come with their own rollout project, and hourly retainers have no natural end. What matters is the pricing metric: the Cybervize platform is licensed per module at a fixed annual price, counting digitally connected people with no named-user limit. Entry prices per tier are published on the pricing page. If you also need security leadership, the vCISO package starts at €3,600/month, platform included.
Is Excel enough for ISO 27001?
For a first certification with a small scope: yes. Auditors accept clean spreadsheets, and for a small organisation with one site the in-house build is a legitimate start. The bill arrives in operations: version states, follow-ups, ownership and years of evidence are manual work, and from the second site or the second obligation next to ISO 27001, the effort grows faster than the team.
What separates ISMS software from a GRC suite?
The cut. ISMS software runs a management system based on ISO 27001; a GRC suite aims to model a corporation's governance, risk and compliance, with the rollout time, role complexity and operating team that entails. Between the two sits the platform approach: several modules on one data foundation, carrying obligations such as ISO 27001, BCM and supplier risk together, without the rollout and operating weight of a suite.
How do new standards and catalogues get into the platform?
Three ways: more than 50 frameworks are kept as a catalogue, from ISO 27001 and BSI IT-Grundschutz to IEC 62443 and sector rules. New catalogues can be loaded via OSCAL import, the official NIST format for security catalogues. And custom catalogues, such as group requirements, are created directly in the platform and connected to ISO 27001 via crosswalk.
Does ISMS software also cover NIS-2, DORA and BCM?
A point tool for ISO 27001 usually does not, and that is exactly where many tool landscapes break. On the Cybervize platform, ISO 27001, NIS-2, DORA, BCM and supplier risk run on one data foundation: one measure satisfies several obligations, and evidence is derived per framework instead of being maintained per tool.
What determines rollout time?
Less than the brochures suggest on the tool side, and more on scope: number of sites, maturity of what exists, and how much has to be migrated. With the Cybervize platform, the rollout is scoped per expansion stage, your own team takes over operations, and an onboarding project is bookable rather than mandatory. We scope the specifics for your organisation in the first conversation.