Requirements broken down into work
Do the baseline assessment against a requirement catalog and see which requirements are not met. The NIS2 catalog is ready, and you add your own requirements yourself.
For compliance and risk
See where you stand against requirements, identify gaps and assign actions with an owner and deadline. Track what is open, what is overdue and how the work is progressing.

A baseline assessment shows where work is needed. Link gaps and risks to actions so that each follow-up has a clear next step.
Do the baseline assessment against a requirement catalog and see which requirements are not met. The NIS2 catalog is ready, and you add your own requirements yourself.
Create actions for identified gaps with an owner, deadline and status. Assign the work and follow up with the right person.
Requirement, risk and action status shows what is in progress and what remains. Review open and overdue actions before the next follow-up.
Assess your current position, decide what needs doing and follow up on the actions. The next review builds on the work you have already done.
Carry out a baseline assessment with the ready-made NIS2 requirement catalog. Add your own requirements for other frameworks or for your business.
Register risks and gaps and link them to the requirements they concern and to the assets affected.
Create actions for the gaps you need to address. Set an owner and a deadline and track status as the work progresses.
Review open and overdue actions, follow up on the results and update the baseline assessment. The history stays available for the next review.
Work on requirements needs to continue after the baseline assessment. With owners, deadlines and status in one place, you can follow up with the right person and see what remains. Audit evidence builds up through the same work.

You record gaps and risks, link them to the relevant requirements and create actions with an owner, a deadline and a status. The actions and their history let you follow what has been done and what is still open.
The NIS2 requirement catalog with its ten security areas is ready to use. You can add your own requirements and carry out a baseline assessment to see which requirements need more work. You can work with other frameworks by entering your requirements.
You can show the status of requirements, risks and actions, documents you have uploaded as evidence and the history of the work. This helps you explain how a gap has been followed up and what remains to be done.
No. Data protection is an add-on to Risk and requirements for an asset register, information sets and an Article 30 record of processing activities. GRC builds on the supplier module with security assessments and Risk and requirements; you add Data protection when you need that part.
We start from your work and show how to assess your current position, assign ownership and follow up on actions.