Scope and organisation
Set up scope, roles, ISMS committee and responsibility matrix to ISO 27001:2022, from templates or adapted to your existing structure.
ISMS operations with organisational structure, BIA, incident management, asset inventory, dual risk assessment, measure tracking and Statement of Applicability, all in one platform, sharing data with BCM, TPRM and Assessment. Hosted in Germany.
Request an ISMS module demoThe ISMS module implements ISO 27001:2022 as an operating system. No Excel spreadsheet, no Word manual.
Scope, roles, ISMS committee, responsibility matrix. Default templates per ISO 27001:2022 or customisable to existing organisational charts.
Assets, asset owners, data classification, dependencies across applications, servers and suppliers. Cross-module data flow to BCM (BIA) and TPRM (supplier risk).
Inherent vs. residual risk with measure linkage. Likelihood and impact per customer-specific matrix. Acceptance workflow with four-eyes principle.
ISO 27001 Annex A controls from assessments or audits, measure maintenance, deadline and responsibility tracking. Statement of Applicability auto-generated.
Incident registration, classification, escalation. GDPR 72-hour deadline, NIS-2 reporting obligations (24h early warning, 72h incident report, one-month final report), KRITIS reports. Templates with data fields for the responsible authorities.
Auto-populated KPIs from live ISMS operations. Templates for board reporting, supervisory board, auditors and insurers. Snapshots for auditors with revision-safe versioning.
The same register in three views: residual risk after controls, current state from evidence, inherent risk before. The configured risk appetite marks what is accepted and what escalates.

Behind it sits the register itself. Every risk carries its origin: NIST SP 800-82, MITRE ATT&CK ICS, ENISA Threat Landscape, or an incident of your own. The figures at the top say what sits above appetite and what has no treatment yet.

Clicking a risk highlights its causal chain: which assets it affects, which controls act on it, and which standard it hangs from. That is the difference between a list and a register that can answer questions.

In a vCISO mandate, your vCISO works with OdySecure and the platform is included. From €3,600/month.
Still comparing? The honest comparison of the four ways to ISO 27001 shows when Excel, a point tool or a GRC suite is the better way.
The ISMS module takes your management system from first inventory to audit-ready evidence in eight steps, and then into continuous operation. Each step is created in the platform, not in spreadsheets and Word manuals.

Set up scope, roles, ISMS committee and responsibility matrix to ISO 27001:2022, from templates or adapted to your existing structure.
Asset inventory with owners, data classification and a dependency graph. The same data feeds BCM (BIA) and third-party risk (TPRM).
Capture your current state against ISO 27001 Annex A, maturity per control and a prioritised gap list, from the Assessment module.
Dual assessment of inherent and residual risk on your own matrix, with a four-eyes acceptance workflow.
Choose and justify Annex A controls; the Statement of Applicability is generated automatically from those decisions.
Actions with due dates and owners, evidence status per control. Progress stays visible at all times.
KPIs fill automatically from live operation; templates for internal audit, management review and board reporting.
Export a tamper-evident snapshot for the certification body; the platform then keeps operating the ISMS continuously.
Three milestones, three timelines. The numbers describe different things, not one contradictory range.
Import a grown Word/Excel ISMS via the assessment module with OSCAL import, including handover of maintenance to internal owners.
Under a vCISO mandate, a senior CISO leads the rollout from first inventory to certification-ready operation and works with this module.
Platform licence, with an onboarding project if you want one; after that, your internal team runs the platform itself.
Open incidents grouped by due date, with severity, ID, owner and status. From the software, not a mock-up.

The ISMS module covers the ISO 27001 family and integrates the complementary standards relevant for DACH. No fragmented multi-tool architecture.
Three constellations in which the ISMS module replaces the Excel-Word-SharePoint approach economically.
200 to 500 employees, NIS-2 affected, wants to certify rather than merely be compliant. Without in-house ISMS practice: under a vCISO mandate, a senior CISO leads the rollout through to the audit and works with this module; the platform is included in the mandate. Audit-ready in 6 to 9 months.
About the vCISO mandateExisting Excel/Word/SharePoint solution grown organically, multi-site hard to map, auditors challenge revision safety. Migration via the Assessment module: existing controls imported, gaps flagged, maintenance from day 1 in the platform.
vCISO consultancies with 5 to 30 clients need multi-tenancy without mixing data. ISMS module with strict tenant isolation, RBAC for cross-client consultant view, without cross-contamination.
The ISMS module shares the data layer, permission model and audit trail with the BCM module (Business Continuity, ISO 22301), TPRM (third-party risk management) and Assessment (OSCAL import and custom catalogues). There are no mandatory modules: licensing is modular, modules build on each other without forcing each other.
See the full platform