Skip to content
Compliflux

NIS2 · ISO/IEC 27001:2022 · GDPR

The accountability
stays yours.
The work does not.

An ISMS your own team runs. NIS2 makes management personally accountable and that accountability cannot be delegated away - so we turn it into a system rather than a consultant retainer without an end date: on your own server, at a fixed annual price, with an approval you sign and can evidence. No AI model, no cloud, no data leaving the building.

  • ISO 27001
  • NIS2
  • GDPR
  • DORA
  • TISAX

11

Frameworks, one control set

EUR 12,900

Fixed annual price

0

Records leaving the building

Certification readinessISO 27001
87%
Implemented · 67Partial · 15Open · 11
Digital colleague · Hint

3 assets without an owner

A.5.9Rule: every asset has an owner
Create findingCreate task
RIS-014Phishing targeting executivesIn progress

Digital colleague

A colleague that reads your records, not the internet.

The digital colleague runs on your own server with no model and no network call. It answers questions from your own data and sweeps that data for gaps. Every hint names the rule behind it, so you can check the reasoning instead of trusting it.

  • Sweeps your registers and names the rule behind every hint
  • Answers questions from your own records, in plain language
  • Promote a hint to a finding or a task - the decision stays yours
  • No model, no network call, no data leaving the building
Automatic rule checkOffline · no model
  • A.5.1 Information security policiesuncheckedchecked
  • A.6.3 Awareness and traininguncheckedchecked
  • A.8.8 Management of technical vulnerabilitiesuncheckedchecked
  • A.5.23 Information security for cloud servicesuncheckedchecked

Rule check · offline, no model

Capture. Assess. Prove.

From current state to audit evidence in three steps.

One continuous flow instead of scattered spreadsheets: you capture your registers, have the maturity level assessed and export the evidence an audit demands.

01

Capture

Assets, risks, vendors and incidents come together in central registers. Controls are reused per framework, not maintained twice.

  • Risks
  • Assets
  • Vendors
  • Incidents

02

Assess

The guided gap assessment assigns every control a maturity level per COBIT. Campaigns freeze a dated pass, so the next one shows you the change rather than a fresh guess.

COBIT maturity

  • Q1 202663%
  • Q3 202687%
+24since the last pass

Two frozen passes · the delta, not a fresh guess

87 %COBIT maturity

COBIT maturity · consolidated across all controls

03

Prove

Evidence packages, maturity history and audit trail are ready to export. The auditor receives the evidence, not your login.

One proof, eleven frameworks

One proof, eleven frameworks.

A control you implement and evidence once pays into every framework that requires it. The platform maintains the mapping, so you never reassemble evidence for each audit.

  • ISO 27001
  • NIS2
  • GDPR
  • DORA
  • KRITIS
  • TISAX
  • BSI IT-Grundschutz
  • SOC 2
  • CRA
  • AI Act
  • CSRD

Synchronised automatically the moment a control changes

Deadlines and data protection

The clock starts when the incident does.

NIS2 and the GDPR both run on deadlines, and neither waits for a spreadsheet to be updated. The platform starts the clock with the record and shows what is left of it.

NIS2: 24 h, 72 h, one month

Early warning, incident notification and final report, each with its own countdown from the moment you record the incident.

GDPR Art. 33: 72 hours

The breach register runs its own clock and carries the assessment that decides whether a notification is owed at all.

Data subject requests: one month

Requests under Art. 15 to 22 are tracked with their deadline, their owner and the record of what you answered.

Records of processing, Art. 30

The ROPA and the data inventory stay linked to the assets and vendors they describe, and export as CSV.

Group ISMS

One ISMS for the entire group.

You maintain group policies once, centrally, and roll them out to subsidiaries in a controlled way. Each unit adds locally, while the consolidated maturity stays visible at group level.

  • Version and approve policies centrally
  • Controlled roll-out to subsidiaries
  • Local additions without breaking the mandate
  • Consolidated maturity across all units
GroupSubsidiary DESubsidiary ATSubsidiary FRPolicyPolicyPolicy

Group policy · rolled out to three subsidiaries

Access policy · Draft2 active

Access to personal data is granted on the principle of least privilege. Permissions are reviewed at least twice a year and adjusted without delay when a role changes.

A. Weber · CISO
J. Brandt · Data protection

Collaboration

You write policies together, not one after another.

Several roles work on the same document in real time - CISO, data protection and the business unit see each other's changes as they happen. Approvals and versions remain traceable.

  • Real-time collaboration in the document with visible contributions
  • Versions and approvals documented as evidence
  • BPMN process designer for the workflows that belong to a policy

Security

Security is the prerequisite, not the extra.

The platform that carries your ISMS follows the same principles that make it auditable: multi-tenant isolation, fine-grained permissions and an end-to-end audit log.

Multi-tenant isolation

Every organisation is separated server-side - data never leaves the tenant boundary.

RBAC and 2FA

Role-based permissions and two-factor authentication are standard, not a surcharge.

SSO and SCIM

Connect to your identity management, with automated provisioning and de-provisioning of access.

Operated in the EU

Processing and data storage in the EU, encrypted in transit and at rest.

See your ISMS in 30 minutes.

We show the platform on your framework and your structure - no sales pressure, with concrete answers.