Skip to main content

For compliance and risk

Turn requirements into work you can follow.

See where you stand against requirements, identify gaps and assign actions with an owner and deadline. Track what is open, what is overdue and how the work is progressing.

Gavel on a table

From requirement lists to clear ownership.

A baseline assessment shows where work is needed. Link gaps and risks to actions so that each follow-up has a clear next step.

Requirements broken down into work

Do the baseline assessment against a requirement catalog and see which requirements are not met. The NIS2 catalog is ready, and you add your own requirements yourself.

Gaps that become actions

Create actions for identified gaps with an owner, deadline and status. Assign the work and follow up with the right person.

See what needs follow-up

Requirement, risk and action status shows what is in progress and what remains. Review open and overdue actions before the next follow-up.

An ongoing workflow for compliance

Assess your current position, decide what needs doing and follow up on the actions. The next review builds on the work you have already done.

  1. Start from the requirements

    Carry out a baseline assessment with the ready-made NIS2 requirement catalog. Add your own requirements for other frameworks or for your business.

  2. Identify gaps and risks

    Register risks and gaps and link them to the requirements they concern and to the assets affected.

  3. Create actions with an owner

    Create actions for the gaps you need to address. Set an owner and a deadline and track status as the work progresses.

  4. Follow up and reassess

    Review open and overdue actions, follow up on the results and update the baseline assessment. The history stays available for the next review.

See risk management

Keep the work moving between reviews

Work on requirements needs to continue after the baseline assessment. With owners, deadlines and status in one place, you can follow up with the right person and see what remains. Audit evidence builds up through the same work.

ChainSec risk register with status and links. Sample data in Swedish.
The risk register in ChainSec. Product image with sample data in Swedish.
See where to focus your effort
The baseline assessment shows which requirements need more work. Links to risks and actions help you move from an identified gap to the next step.
Make ownership clear
Requirements, risks and actions have an owner and a status. You can see what is in progress and what is overdue, and direct follow-up to the right person.
Build on earlier follow-up
Earlier assessments, actions and uploaded evidence stay available. Use the history at the next review or when a colleague needs to take over follow-up.
Keep audit evidence close to the work
Current status, action history and documents uploaded as evidence are in the system. When management or an auditor asks, you can show what is done and what remains.

Frequently asked questions

How do we move from identified gaps to follow-up?

You record gaps and risks, link them to the relevant requirements and create actions with an owner, a deadline and a status. The actions and their history let you follow what has been done and what is still open.

Which requirement catalog is ready to use in ChainSec?

The NIS2 requirement catalog with its ten security areas is ready to use. You can add your own requirements and carry out a baseline assessment to see which requirements need more work. You can work with other frameworks by entering your requirements.

What evidence can we prepare for an audit?

You can show the status of requirements, risks and actions, documents you have uploaded as evidence and the history of the work. This helps you explain how a gap has been followed up and what remains to be done.

Do we need Data protection to work with risks and requirements?

No. Data protection is an add-on to Risk and requirements for an asset register, information sets and an Article 30 record of processing activities. GRC builds on the supplier module with security assessments and Risk and requirements; you add Data protection when you need that part.

See how to move your GRC work forward.

We start from your work and show how to assess your current position, assign ownership and follow up on actions.