CISO Compliance Request a demo

Cybersecurity governance platform  ·  Act 69/2018  ·  NIS2

Cybersecurity as a governed process — not a one-off project.

CISO Compliance turns statutory cybersecurity duties into one connected system. Assets feed risks, risks feed controls and policies, incidents feed reports with tracked statutory deadlines, and training feeds measurable human resilience.

Built for any organisation that must demonstrate compliance continuously — companies, hospitals, schools, municipalities and essential service operators — with evidence, not with a folder of spreadsheets assembled the week before an inspection.

24 functional modules, enabled per organisation
§ 69/2018 plus NIS2 and GDPR in a single system
AES-256 envelope encryption of every sensitive value
100 % of changes written to an immutable audit log

Simulated incident · autoplay

An attack on the left. The system answering on the right.

A condensed replay of a real-world evening: a scan, a phishing wave and a blinded endpoint — and what CISO Compliance does about each within seconds, without waiting for anyone to log in.

incident-replay · #2026-0814 · condensed timeline LIVE

Attacker

    CISO Compliance — automated response

      Detection latency
      Residual risk 11
      Tasks opened 0
      § 24 initial report idle
      Audit log entries 0

      What this replay shows. Detection comes from the platform’s own sensors — HoneyGrid decoys, e-mail checks and endpoint agents. Assessment, deadlines and the draft report are automatic; the decision to send remains with the responsible person, and every step lands in the immutable audit log.

      Regulatory mandate

      Every function maps to a duty someone can be inspected on

      CISO Compliance is not a general-purpose register. Each capability exists because a specific legal provision requires it — and the system is designed to produce the evidence that provision expects.

      InstrumentAreaHow the system covers it
      Cybersecurity Asset and risk management, ISMS documentation, incident reporting, business continuity, staff education
      Incident reporting Assessment of the reporting obligation, tracked statutory deadlines, generated report for the national authority
      Security measures Policy and control templates aligned to the current decrees, plus a readiness GAP analysis
      EU framework Supply-chain risk management, security measures and reporting in NIS2 structure
      Data protection Personal data breach notification to the supervisory authority within 72 hours
      Right to erasure Cryptographic destruction (crypto-shred) of the record inside the encrypted vault
      Compliance evaluation Catalogue of provisions scored continuously from real evidence in the system

      A note on interpretation. The system helps an organisation meet and demonstrate its duties. It does not replace the professional responsibility of the cybersecurity manager or the decision of the statutory body. Automated assessments — such as whether an incident is reportable — are prepared as a basis for a decision that a responsible person confirms.

      System architecture

      Modules never call each other — they publish events

      A thin core carries tenancy, permissions, encryption, audit and the module registry. Everything else is an independent module that publishes domain events and resolves interfaces, which is what makes a switched-off module harmless.

      Event flow

      M02 · assets M05 · registers M10 · training Agent marks a control Incident recorded Course completed AssetControlChanged IncidentRecorded CourseCompleted Event bus domain events + dependency-injected contracts — the only way modules communicate recalculate risk start § 24 deadlines re-score compliance M03 · risks M08 · directives — disabled M07 · compliance Residual score updated no-op contract · nothing breaks Posture recalculated CORE — APPLIES TO EVERY MODULE Tenancy Permissions Encryption Audit Module registry
      Why it matters. Because nothing is wired module-to-module, an organisation can run five modules or all twenty-four without a different build. A disabled module is replaced by an empty implementation of its contract, so the surrounding chain keeps working instead of failing.

      Functional modules

      Twenty-four modules, six divisions, one connected record

      A thin, stable core handles security, tenant isolation and messaging. Functionality arrives as independent modules that an organisation switches on as its obligations grow. A disabled module is replaced by a no-op implementation of its contract, so the rest of the system keeps working.

      A

      Foundation and security governance

      The core of every deployment — from the organisation record and its assets through risk calculation to an initial readiness assessment. These modules form the data foundation every other module draws on.

      M01 · organization

      Organisation, people and roles

      Organisation profile, employees, groups, users, essential services.

      • Organisation profile — name, registration and VAT identifiers, address, statutory body, cybersecurity manager, data protection officer; the single source of truth that fills every generated policy and report.
      • Onboarding wizard — completes the profile on first run and optionally records the website, email domain and IP ranges, pre-populating the monitoring modules.
      • Employees and groups — the people who own assets and attend training, plus user groups.
      • Essential services — the junction that links assets, continuity and incidents, and the carrier for the reporting-obligation assessment.
      • Users and roles — accounts created with a temporary password and forced change, or invitations for an existing user; membership of several organisations with a switcher.
      • Public registration — an organisation can register itself; the record is created suspended and activates only after provider approval.

      M02 · assets

      Assets and inventory

      Asset register, CIA classification, assignment, QR labels, import, agents.

      • Governed lifecycle — in stock, assigned, in service, decommissioned — with links to owner, room and essential service.
      • CIA classification of confidentiality, integrity and availability plus RTO and RPO recovery parameters — the basis for both risk calculation and continuity planning.
      • Handover with proof — assignment to a person carries an eight-character confirmation code, acknowledged publicly from the email without any login.
      • QR codes and printed labels generated locally, with no data sent to a third party.
      • Bulk import from CSV or XLSX with a template, row-by-row validation, deduplication and a summary report.
      • Device agents — a one-way agent reports operating system, antivirus, encryption, backup software and pending updates. The first report creates the asset, marks the controls it detects, and triggers a risk recalculation.

      M03 · risks

      Risks and controls

      The calculation core — inherent and residual risk, acceptance, expert decisions.

      • Methodology as a parameter — scales, weights, control effectiveness coefficients and risk bands belong to the organisation, not to the vendor.
      • Inherent risk derived from the highest impact severity and the likelihood of the threat.
      • Residual risk accounts for the effectiveness of implemented and planned controls and never exceeds the inherent value; calculated and estimated residual scores are kept distinct.
      • Automatic threat assignment by asset type, with risks materialised in the background — idempotently, and respecting manual edits.
      • Acceptance and override — the cybersecurity manager may accept or override a final value, always with a mandatory justification written to the professional decision log.
      • Above-limit risk beyond a defined band can be configured to require acceptance by the statutory body.

      M04 · bcm

      Business continuity management

      Continuity and disaster recovery plans, testing evidence, impact analysis.

      • BCP and DRP plans with a record of every test — result, date, and automatic return to revision when a test fails.
      • Backup strategies with verification that the backups are actually restorable.
      • RTO and RPO overview across all assets in one view.
      • Business impact analysis with scaled impacts per process.

      M05 · gap

      Initial GAP analysis

      Structured readiness questionnaire tied to specific legal provisions.

      • Questions bound to the law — each item references the section of the act or decree it verifies.
      • Readiness percentage overall and per area, with non-applicable questions excluded from the calculation rather than scored as failures.
      • Identified gaps listed as concrete findings, not as a score alone.
      • Direct remediation — where a required policy is missing, the analysis offers to generate it from the template immediately.

      M03 · how a risk score moves

      INPUTS Highest impact (CIA)confidentiality · integrity · availability Threat likelihoodassigned by asset type RISK BANDS lowmediumhighabove limit Inherent risk 20 − effectiveness of implemented and planned controls (45 %) Residual risk 11 Within bandrecorded, monitored, no further sign-off required Above the limitacceptance by the statutory body, with a written justification
      Residual risk can never exceed inherent risk. Only the effectiveness of controls moves the bar. The manager may override the final value — but the override and its justification are written to the professional decision log, so the number always has a traceable reason.
      B

      Documentation, vault and compliance

      From automatically generated security documentation, through an encrypted vault for documents and credentials, to a single continuously computed compliance score.

      M08 · directives

      Policy generator

      Security documentation produced from live data — without manual drafting.

      • 19 policy templates (SM-01 to SM-19) — from the security policy through asset, risk, access and supplier management to backup, incident handling and effectiveness review.
      • Live content — organisation data is inserted automatically and tables are generated from real records: assets, risks, continuity, backups, incidents, vulnerabilities, obligations and suppliers.
      • Versions and states — draft, approved, superseded — with an automatic flag when the underlying template changes and the policy becomes outdated.
      • PDF export mirrored into the vault. The statutory signature and effective date appear on the document only after actual approval; drafts carry a prominent marking.
      • Approval workflow from cybersecurity manager to statutory body.

      M09 · documents

      Cyber Vault — repository and password vault

      Encrypted document storage, credentials, qualified signing, crypto-shred.

      • Envelope-encrypted files — AES-256-GCM with a per-file key and an organisation key derived through HKDF; files are stored outside the web root.
      • Password vault with a built-in strong generator; every credential encrypted separately and per organisation, and never rendered in a list view.
      • Reveal on verification — a sensitive value is decrypted only after a one-time code by email or SMS, for a limited time, with a record of who opened it and when.
      • Document locking — opening a protected document requires a one-time code.
      • Qualified electronic signature of documents via eID chip card in PAdES format.
      • Crypto-shred — destroying the key renders the record permanently unreadable, satisfying the right to erasure.
      • Approval workflow and per-document access control.

      M07 · compliance

      Compliance and security posture

      One score, computed from evidence rather than from self-assessment.

      • Compliance score calculated continuously from real artefacts — generated policies, implemented controls, approved documents and resolved incidents.
      • Live security posture scored 0–100 with an A–E grade, weighting compliance, risks above threshold, vulnerabilities, incidents, education, operational hygiene and backups.
      • Catalogue of provisions mapped directly to the decree, so a score can always be traced back to the requirement behind it.

      M07 · live security posture

      E D C B A 0 100 78 GRADE B · IMPROVING WEIGHTED INPUTS Compliance provisions met22% Risks above threshold18% Open vulnerabilities16% Incidents resolved in time14% Training completion12% Operational hygiene10% Backup verification8%
      Illustrative values. The score is never entered by hand — every input is read from live records elsewhere in the system, so an organisation cannot improve its grade without improving the underlying evidence.
      C

      Incidents and mandatory reporting

      From recording an event, through assessing whether it must be reported, to a generated submission for the authority — with tracked deadlines and an immutable trail.

      M05 · registers

      Registers and incidents (§ 24)

      Cyber events, reporting-obligation assessment, submissions to the authorities.

      • Event register covering incidents, critical threats, averted events and vulnerabilities, each linked to the affected assets and essential services.
      • Reporting-obligation assessment under § 24 — a deterministic rule (event type, affected essential service, severity) combined with an expert assessment that applies the precautionary principle and escalates serious events. The output is a plain-language justification, not technical jargon.
      • Tracked statutory deadlines — initial, interim and final reports, counted from the moment of detection.
      • Generated submissions — a report for the national cybersecurity authority in the prescribed A–H structure, and a personal data breach notification for the data protection authority within 72 hours, rendered to PDF and mirrored into the vault; a preview is available without saving.
      • Irreversible dispatch — the report is sent by email with its attachment, protected against duplicate submission, and the incident is marked as reported.
      • Remediation tasks raised from incidents and vulnerabilities close automatically when the underlying finding is resolved.

      M06 · vulnerabilities

      Vulnerabilities

      Vulnerability register, automatic remediation, public threat intelligence.

      • Register with CVE identifier, severity and a link to the specific affected asset.
      • Automatic response on a severe finding — a remediation task with a deadline is created and the risk of the affected asset is recalculated.
      • Public intelligence in-module — the catalogue of vulnerabilities known to be actively exploited, together with advisories from national authorities.

      M05 · statutory clock under § 24

      ALL DEADLINES COUNT FROM DETECTION — NOT FROM RESOLUTION Detection T₀ Reportable? deterministic rule + expert assessment YES Initial report Interim report Final A–H, sent to the authority progress and scope NO Recorded, not reported with the written reasoning kept for inspection Personal data involved? parallel 72-hour notification to the data protection authority
      The assessment is a proposal, not a verdict. The system applies the precautionary principle and escalates serious events, and produces a plain-language justification — the responsible person confirms the decision before anything is sent.
      D

      Security controls and monitoring

      Automated checks that verify the organisation's exposure from the outside and from within, feeding every finding into a single alert view.

      ip-addresses

      IP addresses and port scanning

      External exposure of public addresses.

      A register of the organisation's public IP addresses with parallel scanning of open ports against a catalogue of dozens of risky services, including service version detection and an exception system for ports that are open by design. Risky findings surface as alerts.

      websites

      Websites

      Transport security and web hygiene.

      Verification of HTTPS and TLS certificate validity, server and runtime versions, security headers and cookie flags, plus technology detection. The result is a grade and a list of findings ordered by severity.

      email-security

      Email security

      Protection against sender spoofing.

      Continuous verification that the organisation's domain cannot be abused for fraud — SPF, DKIM, MX and MTA-STS configuration, together with a check for the domain's presence on blacklists.

      backup-nas

      Backup monitoring

      Oversight of network backup jobs.

      Job success rates and history for network-attached backup appliances, with alerting deliberately narrowed to a new failure or a missing report — so the signal is not lost in a daily stream of successful runs.

      honeygrid

      HoneyGrid probes

      Network decoys and intrusion detection.

      Probes that imitate real services and capture intrusion attempts, with immediate alerts, an escalation matrix and a status map of the deployed grid. The channel between probe and system is cryptographically signed.

      agents

      Endpoint agents

      Device state reported from the inside.

      A lightweight agent on workstations reports antivirus, operating system and backup state. Findings such as a missing antivirus or an outdated or unsupported system appear among the alerts and feed the asset and risk registers.

      E

      People, resilience and suppliers

      Security is also about people and partners. This division builds and measures the resilience of employees and governs supply-chain risk.

      M10 · training

      Training and testing

      Courses, tests, certificates, completion overview.

      • Courses with slides and a test — the system can generate course content for a chosen topic; publication remains exclusively with the provider.
      • Assignment to individuals or to all employees at once, with test evaluation by score, a pass threshold and a limited number of attempts.
      • PDF certificate with a serial number, issued on successful completion and stored in the vault.
      • Completion overview for the whole organisation, while every employee sees their own training without needing any special rights.

      M17 · simulations

      Attack simulation — phishing and smishing

      Training campaigns that measure real employee resilience.

      • Two channels — simulated phishing by email and smishing by SMS, launched from scenarios and templates.
      • Masked link and interaction tracking — opening, clicking and submission of the training form are all recorded.
      • Nothing sensitive is retained. A password typed into a simulated form is never stored; only the fact that the action occurred.
      • Resilience evaluation — open, click and submission rates, with a clear outcome per person: those who clicked failed, those who did not resisted.

      M16 · suppliers

      Suppliers and supply chain

      Third parties with access to systems and data.

      • Third-party register recording criticality, the scope of access granted, and an automatically derived risk score.
      • Security questionnaires that a supplier completes publicly through a link, without needing an account.
      • Agreed commitments captured with PDF evidence stored in the vault.
      • Supply-chain governance structured to the expectations of NIS2.

      M16 · consultations

      Consultations

      Recorded expert dialogue between the roles that decide.

      • Threaded discussion between the cybersecurity manager, the statutory body and internal IT, with tree-structured replies and explicit states.
      • Approved conclusions — the statutory body can formally approve the outcome of a thread.
      • Fully audited — every action in a consultation is written to the audit trail, so the reasoning behind a decision survives staff turnover.
      F

      Management and operations

      The tools that keep the agenda moving — deadlines, planning, support, and, on the provider side, the management of field service.

      M11 · obligations

      Statutory obligations calendar

      Recurring legal duties with a legal basis and a reminder schedule.

      • Pre-filled obligations — the statutory duties arrive with their period and legal basis already recorded, rather than being typed in by hand.
      • Drift-free recalculation of due dates, so a recurring duty does not slide out of alignment over years.
      • Reminders at 30, 7 and 1 day before, on the day itself, and daily after the deadline passes — to the cybersecurity manager and the responsible person.

      M12 · activities

      Activity planner

      Planning and evidencing security activities.

      • Planned activities — courses, exercises, audits and reviews scheduled ahead of time.
      • Status tracking from planned through in progress to completed.
      • Linked to deadlines and compliance evidence, so a completed activity counts towards the score rather than sitting in a separate calendar.

      M15 · helpdesk

      Helpdesk and release notes

      Support tickets and a transparent record of system changes.

      • Support tickets with priority and status, visible according to the requester's role.
      • Changelog giving every organisation a clear view of what changed in each release.

      dispatching

      Dispatching — provider layer

      Field service management for the organisation delivering the platform.

      • Service cases with a state workflow, assigned to technicians and teams.
      • Appointment calendar and deployment map across all served organisations.
      • Handover protocols generated to PDF at the close of a case.
      • Administrator credentials handled safely — encrypted at rest, released to the technician through a verified one-time code, and never visible to the person who sent them.

      The differentiator is the wiring, not the count. An agent marks a control, which lowers a risk, which changes a generated policy and moves the compliance score. An incident starts a statutory clock and produces a submission. A vulnerability opens a task. The organisation stops maintaining dozens of disconnected registers and maintains one living, consistent picture of its security.

      Security model

      A system that governs security has to be exemplary itself

      Data is protected on several layers at once — encryption, tenant isolation, strict access control and an immutable record of every change.

      Envelope encryption

      Every password, API key and confidential document is encrypted with its own random key (AES-256-GCM, which also verifies integrity). That key is sealed by a master key bound to the server, so a leak of the database alone reveals nothing.

      Per-organisation key derivation

      Keys are derived separately for each purpose and each organisation using HKDF-SHA256. One organisation's data is cryptographically separated from every other organisation's data, not merely filtered apart.

      Decryption on demand

      A sensitive value is decrypted at the moment it is displayed, after an additional verification step, and every access is recorded — including who opened it last and when.

      Crypto-shred

      Destroying the key renders a record permanently unreadable. This is how the right to erasure is satisfied without leaving recoverable fragments behind in backups.

      Tenant isolation

      Organisation membership is enforced by a global filter at the database query level and is never taken from the browser request — so it cannot be forged. Provider-managed global catalogues are held separately from organisation data.

      Immutable audit

      Every change records who, when, what, from which address, and both the previous and the new value. Professional decisions are additionally written to their own decision log.

      Envelope encryption

      KEK — MASTER KEY BOUND TO THE SERVER ORGANISATION KEY — HKDF-SHA256, PER PURPOSE DEK — ONE RANDOM KEY PER RECORD Password · API key · document AES-256-GCM — authenticated, so tampering is detected stored outside the web root WHAT EACH LAYER BUYS A stolen database is inert record keys are sealed by a key that never leaves the server Tenants are cryptographically apart one organisation’s key cannot open another’s record Crypto-shred destroy the record key and the data is unreadable for good — including in every backup that already holds it
      Three keys, three different jobs. The record key protects the value, the organisation key keeps tenants apart, and the server-bound master key means the ciphertext alone is worthless. This is what makes the right to erasure enforceable rather than merely promised.

      Access control — deny by default

      Access to any function is denied unless it is explicitly granted. A permission exists only when all three conditions hold at the same time.

      CONDITION 1

      The module is enabled

      The organisation has switched the relevant module on.

      CONDITION 2

      The role permits the action

      The user's role — or an individual exception — allows this specific action.

      CONDITION 3

      No individual prohibition

      The user carries no explicit ban on that action.

      Permission resolution

      Module enabled Role or exception permits No individual prohibition AND ALL TRUE Action permitted any condition false Action denied also the state before any grant exists
      Deny is the resting state. Nothing is permitted until all three conditions are satisfied, so switching a module off removes its permissions everywhere at once — no orphaned rights left behind.

      Two-factor authentication

      Time-based one-time codes at sign-in, with email one-time codes for sensitive reveals.

      Controlled impersonation

      A provider administrator can act as another user only with a stated reason, a visible banner, and both identities recorded.

      No permanent deletion

      Records are deactivated rather than removed, and can be restored at any time. The single exception is a controlled crypto-shred.

      Statutory approval

      Documents and their versions are prepared by the professional administrator and confirmed by the statutory body.

      Asynchronous by design

      Risk recalculation, document generation and bulk imports run on a queue — idempotently and inside transactions.

      Data-safe deployment

      Strictly incremental migrations and a mandatory backup before any significant change; no destructive operations on production data.

      Roles and access

      Who does what in the system

      The platform distinguishes the provider — which maintains methodology and serves all organisations — from the individual organisations with their own users. Rights are granular and granted at the level of a module and an action.

      RoleScopeTypical permissions
      Head administratorAll organisationsMethodology, global catalogues, module registry, management of organisations and accounts across the system, controlled impersonation
      Organisation administratorOwn organisationAccounts and rights, organisation profile and settings, every enabled module
      Statutory bodyOwn organisationApproval of documents and policies, a dedicated executive dashboard, account management
      Cybersecurity managerOwn organisationProfessional management of assets, risks, incidents, policies and controls
      Contact personOwn organisationAssigned agendas and communication with the authorities
      EmployeeOwn organisationOwn training, asset acceptance confirmations, own profile
      AuditorOwn organisationRead-only access to the relevant data
      Dispatcher / technicianProvider service layerService cases, calendar, handover protocols, controlled access credentials

      Every user additionally has a self-service profile — personal details, password change, two-factor authentication and interface language — independent of their module rights. Permissions can be tuned with an individual exception beyond the role, always within the deny-by-default principle.

      Integrations and interfaces

      Connected to the tools an organisation already uses

      Integrations are designed so that an organisation can configure them itself, safely, without a vendor engagement for every change.

      SMS gateways, per organisation

      Each organisation chooses its own SMS provider and enters its API credentials, or points the system at a generic HTTP gateway. Keys are encrypted; the organisation's own gateway is used when configured, otherwise the global one.

      Central email channel

      A single mail channel for approvals, deadlines and alerts across the whole system, built to tolerate outages — a failed send never brings down the operational flow behind it.

      Identity and sign-in

      Local sign-in with two-factor authentication and email one-time codes, with an interface prepared for corporate identity providers.

      Qualified electronic signature

      Documents can be signed with a qualified electronic signature using an eID chip card, producing a PAdES-format signed PDF.

      Sensors — probes and agents

      Network decoys and lightweight endpoint agents report state and intrusion attempts into one central view, over a signed channel.

      Programmatic API

      A secured token-based API for integration and automation, with consistent conventions and fields hidden from callers that lack the permission to see them.

      Deployment model

      One system, two vantage points

      The platform runs as multi-tenant software. The provider maintains methodology, templates and catalogues centrally; each organisation works inside its own isolated space.

      Provider

      Central methodology and service

      A single update to a policy template, a threat catalogue or the risk methodology reaches every organisation at once. The dispatching layer additionally allows the provider to run service interventions, handover protocols and controlled access credentials for its clients.

      Organisation

      Its own protected space

      An organisation sees only its own data, enables only the modules it needs, adapts the interface — language, type size, content width — and manages its own users and permissions. The interface is fully bilingual and includes explanations for professional abbreviations.

      Tenant isolation

      PROVIDER Risk methodology · 19 policy templates · threat catalogue · module registry · published courses one update reaches every organisation COMPANY A HOSPITAL B MUNICIPALITY C own assets, risks, incidentsown derived keys7 modules enabled own assets, risks, incidentsown derived keys24 modules enabled own assets, risks, incidentsown derived keys12 modules enabled Tenant filter enforced at the database query level — never read from the browser request, so it cannot be forged
      Shared methodology, separated data. The provider improves one template and every organisation benefits; no organisation can reach another’s records, because the separation is both a query filter and a difference in encryption keys.

      The economics. Shared methodology and automation cut the cost of external consulting and the time of internal staff. An organisation pays for what it uses, and as its obligations grow it simply enables further modules — without a migration and without a new project.

      In practice

      What the people who carry the duty say

      Compliance managers, executives and IT teams — from private companies to public institutions.

      sample
      The inspection asked for four years of decisions. We exported them in an afternoon, with the reasoning attached to each one.
      MK Martin Krajčí
      Cybersecurity manager · city administration
      sample
      The work now leaves a trace. Nothing depends on one person remembering what was agreed and why.
      EW Emma Whitfield
      Head of IT · regional hospital
      sample
      We are a private company — NIS2 hit us like everyone else. This turned a legal text into a to-do list our team could actually execute.
      JC James Carter
      CEO · manufacturing company
      sample
      The first phishing simulation was uncomfortable reading. Six months later the click rate was a fifth of what it was — and I could show the board the curve.
      LV Lucia Vargová
      Compliance officer · energy distribution
      sample
      Policies used to be documents we wrote once and feared opening. Now they regenerate from live data and the signature step is the only manual part.
      DB Daniel Brooks
      IT administrator · secondary school
      sample
      When the auditor asked who approved a risk override two years ago, the answer was one click. That was the moment the system paid for itself.
      KB Katarína Bieliková
      Executive director · logistics company

      Note. The quotes above are illustrative samples — swap them for real, attributed customer quotes before the site goes live.

      Ecosystem

      Works with the estate you already run

      CISO Compliance does not replace your security tooling — it reads its state and turns it into evidence. These are the environments the platform is built to observe and document.

      ESET Endpoint protection state reported by the device agent
      Microsoft 365 Mail domain, sharing and tenant hygiene as compliance evidence
      Entra ID Single sign-on and identity, formerly Azure AD
      Fortinet Perimeter controls mapped to the measures they satisfy
      MikroTik Network segmentation and exposed services in the asset register
      Cisco Network infrastructure recorded with owners and recovery targets

      On logos. The names above are the trademarks of their owners and appear here as plain text to describe interoperability. Use an official logo only for a vendor whose partner programme you are actually enrolled in, and follow that vendor’s brand rules.

      Licensing

      Priced per organisation, billed once a year

      No per-seat maths, no hidden add-ons. Every tier ships with the full evidence chain; higher tiers unlock more divisions, deeper automation and faster response.

      Essential

      A single team getting its obligations in order.

      €1,000

      per year

      • Governance & risk divisions
      • GAP analysis against Act 69/2018
      • Evidence export (PDF)
      • Community support
      Start with Essential

      Sovereign

      Whole-organisation coverage with every module live.

      €6,000

      per year

      • All 24 modules, all six divisions
      • SSO & audit-grade logging
      • Guided onboarding
      • Priority response SLA
      Choose Sovereign

      Bespoke

      Group structures, state administration, on-premise.

      Individual offer

      scoped to you

      • Isolated or self-hosted instance
      • Custom integrations
      • Procurement-ready contract
      • Named account team
      Talk to us

      Next step

      See the evidence chain on your own organisation

      A guided walkthrough takes about forty minutes: your obligations, a live GAP analysis, and the documentation the system would generate from your data on day one.

      Glossary

      Abbreviations used above

      ISMSInformation security management system
      CISOChief information security officer — the statutory cybersecurity manager role
      CIAConfidentiality, integrity, availability — asset classification
      RTO / RPORecovery time objective / recovery point objective
      BIA / BCMBusiness impact analysis / business continuity management
      BCP / DRPBusiness continuity plan / disaster recovery plan
      CVEPublic identifier of a known vulnerability
      SLAAgreed deadline or service level
      2FA / TOTPTwo-factor authentication / time-based one-time code
      DEK / KEKData encryption key / key encryption key — envelope encryption
      HKDFKey derivation function
      PAdESStandard for qualified electronic signatures in PDF
      SPF / DKIMMechanisms verifying the authenticity of a domain's email
      MTA-STSPolicy enforcing encrypted mail transport to a domain