BSI IT-GrundschutzBSI 200-1 · 200-2 · 200-3 How do you map the requirements quickly onto your organisation’s structure? Complaica BSI IT-Grundschutz Modules and requirements from IT-Grundschutz, ISO 27002, NIS2 etc. are assigned automatically to your organisation’s target objects – processes, applications, systems, sites. Modelled on your structureRequirements per target objectAll relevant catalogues
Grundschutz++GS++ · OSCAL Can you move quickly from classic IT-Grundschutz to Grundschutz++? Complaica Grundschutz++ Complaica supports the transition to Grundschutz++ – your modelling, controls and evidence from classic IT-Grundschutz remain usable. Plan the switchKeep using existing workAutomated
ISO 27001ISO 27002 · 27005 How do you tell how far you already meet the standard today? Complaica ISO 27001 The degree of fulfilment is rolled up from the single requirement to the organisation – you always see what is met, what is open and where evidence is missing. Fulfilment at a glanceOpen requirements visibleSoA always up to date
NIS2Regulation (EU) 2024/2690 Which measures must you implement – and how do you document incidents? Complaica NIS2 Complaica holds the NIS2 risk-management measures as requirements with controls and evidence; incidents are recorded with deadlines and reporting channel. Measures clearly structuredIncidents logged with deadlinesEvidence for the authorities
GDPRBDSG · DSG Which processes are mandatory – and which are optional? Complaica GDPR The processing register, DPIA, data subject rights and data breaches are set up as records; the system shows what is mandatory for your processing activities. Mandatory records visibleLinked recordsProof under Art. 5(2)
DORAEU 2022/2554 How do you keep your ICT service providers under control? Complaica DORA Providers are held as assets with contracts, criticality and dependencies – requirements, risks and reviews per third party in the same system. Providers in the registerSelf-assessmentsRisks per third partyReviews and evidence
BSI 200-4 (BCM)BCM · ISO 22301 How do you determine dependencies and the tolerable downtime? Complaica BSI 200-4 (BCM) The business impact analysis builds on the register: dependencies between processes and systems are visible, and tolerable downtimes are set per process. Dependencies as a graphDependencies as a matrixDowntimes per systemEmergency plans current
Cyber Resilience ActEU 2024/2847 What else must you keep in view besides open-source components? Complaica Cyber Resilience Act The CRA demands more than a bill of materials: security across the lifecycle, vulnerability handling, reporting and documentation – held as requirements per product. Requirements per productHandle vulnerabilitiesReporting duties in view
Process & asset registerScope How do you record processes, systems and suppliers so that every standard can build on them? Complaica Process & asset register Organisation, business processes, applications, systems and suppliers sit in one register with their dependencies – the basis for every standard. Import: Excel or REST APIOne register, all standardsDependencies: graph, matrixOwners per asset
Requirements & controlsCatalogues How do you assign requirements to assets – and which control meets several standards at once? Complaica Requirements & controls Requirements from the standards catalogues are assigned to the assets automatically; controls are described once and referenced wherever they take effect. Catalogues includedAssignment per assetDescribe once, reuse oftenImport: Excel or REST API
Risk analysisBSI 200-3 · ISO 31000 How do you assess risks consistently – and which controls really reduce them? Complaica Risk analysis Threats, assessments and controls follow one consistent pattern across modules – for data protection and information security. Consistent risk assessmentControls linked to risksRisk matrix per scopeGross and net risk
Audit managementISO 19011 How do you keep audits, findings and their follow-up in view in one place? Complaica Audit management Internal and external audits are run with scope, dates, findings and actions – from plan to completion. Audits planned and documentedFindings with actionsStatus visible at any time
Data visualisationDWH · BI · AI How do you show implementation status – per standard, per area, per system? Complaica Data visualisation Dashboards roll up the degree of fulfilment from the single requirement to the organisation – as a chart, not just a table. Fulfilment per standardDrill-down to the requirementDependencies as a graph
Fast data searchSemantic search How do you find the information on a particular application or business process in seconds? Complaica Fast data search One search across all modules finds assets, requirements, controls and records – with filters by standard, status and owner. One search for it allFilter by standard and statusEdit results directly
OSCAL supportNIST How do you exchange machine-readable catalogues and assessments with auditors and other tools? Complaica OSCAL support Catalogues, profiles and assessments can be exchanged in OSCAL format – machine-readable, between tools and auditors. Import cataloguesExport assessmentsMachine-readable for auditsAudit-proof
MCP supportAI How do you let an AI assistant work with your compliance data? Complaica MCP support Through the Model Context Protocol, an AI assistant accesses assets, requirements and records – with the rights of the signed-in user. AI assistant connectedRead and write via MCPThe user’s rights apply
Inventory data integrationREST API How do you take assets over from your asset management and your CMDB instead of maintaining them twice? Complaica Inventory data integration Assets arrive via REST API or file exchange from i-doit, GLPI, FNT Command, Azure and other sources – synchronised one-way or both ways. i-doit, GLPI, FNT, AzureOne-way or two-wayNo double maintenance
Standards integrationISO · BSI · NIST How quickly is a new standard or a new version in the system? Complaica Standards integration Standards catalogues are loaded as data, not programmed – new standards and new versions in days, mapped to existing controls. New standards in daysVersions kept currentControls stay mapped
IAM integrationAzure · Keycloak · authentik How do users sign in with their company account – and where do their rights come from? Complaica IAM integration Sign-in via single sign-on through your identity management; roles and groups are taken from the directory. Single sign-onRoles from the directoryNo second password
Tasks & ticketsJira · Planner How do actions land as tickets where your teams already work? Complaica Tasks & tickets Tasks are exchanged with Jira, Teams, SharePoint and other systems – the status comes back, the evidence stays in Complaica. Exchange with Jira and co.Status flows backEvidence in one place
NotificationsTeams · Email How do the owners learn in time that a deadline is running? Complaica Notifications Complaica notifies the owners as soon as a record needs their attention – instead of email chains and reminder notes. Alerts on deadlines and status changesOwnership per recordLess chasing by email
ApprovalsFour-eyes principle How do you record who approved what – and when? Complaica Approvals Approvals are part of the record: reviewers and approvers are named, their decisions documented. Named approversDecision with timestampApproval as status change
WorkflowsState model How do you make sure every record takes the same path? Complaica Workflows Every record type follows a defined state model. Everyone knows what comes next and whose turn it is. State models per record typeClear handoversConsistent across all modules
Audit-proof recordsAudit Trail How do you show later, without gaps, who changed what? Complaica Audit-proof records Changes and status changes are logged traceably – for audits, supervisory authorities and internal audit. Traceable changesHistory per recordFit for audits
ReportsISO · BSI · GDPR How do management and the auditor get their report without anyone compiling it? Complaica Reports Reports on implementation status, risks and controls are generated from the maintained data – as PDF or for other systems. Standard-specific reportsFrom current dataFor board and auditorPDF, Excel, Word
Team AI assistantAI Where can an AI assistant take work off your team? Complaica Team AI assistant An AI assistant works in the same system via MCP: it answers questions on status, drafts controls and summarises records. Can be switched on or offLocal or cloudAnswer status questionsDraft controlsWithin the user’s rights
Externals & partnersAccess by link How do you involve consultants, auditors and suppliers without showing them everything? Complaica Externals & partners Externals and partners work with exactly the rights their role needs – from the external data protection officer to the auditor. Role-based accessInvolve externals preciselyEditing and approval separated
Audit planningISO 19011 How do you plan which areas are audited when and by whom? Complaica Audit planning The audit programme sets scope, dates and auditors; internal audits, supplier audits and certifications sit in one calendar. Audit programme on calendarScope and auditors namedInternal and external audits
Audit executionISO 19011 How do you run an audit where the evidence already is? Complaica Audit execution The audit runs along the requirements: evidence, rating and remark per checkpoint – right where the controls are documented. Checkpoints from the requirementsRating per checkpointEvidence linked directly
Evidence managementISO 19011 How do you gather evidence all along, not the day before the audit? Complaica Evidence management Evidence is attached to controls and requirements and arises along the way – not on the day before the audit. Evidence per controlWith date and ownerReady for audit and regulator
Tracking findingsISO 19011 How do you track findings until the action is effective? Complaica Tracking findings Every finding becomes an action with an owner, deadline and status – open, in progress, effective. Finding becomes actionDeadline and ownerEffectiveness checked
Complete PDCAISO 19011 · ISO 9001 How do you close the loop from planning to improvement? Complaica Complete PDCA Plan, do, check, act: every step has its place in the system, and the check leads back into the next plan. All four phases coveredChecks lead to actionsContinual improvement
Platform-independentLinux · Windows · macOS Which operating systems does operation require? Complaica Platform-independent Complaica runs on common operating systems and is used in the browser – with nothing to install on the desktop. Common operating systemsUsed in the browserNo client installation
SaaS or on-premisesDocker Compose How do you run the platform when your data must not leave the building? Complaica SaaS or on-premises Complaica runs in your own infrastructure or as SaaS in the cloud – whichever your requirements allow. Run in your own data centreSaaS availableOne platform, two operating models
MCP interfaceAI Which interface does your AI tool get – and what may it do with it? Complaica MCP interface The MCP server makes the platform’s data and functions available to AI tools – through the same permission check as the user interface. MCP server includedSame rights as in the interfaceFor any AI client
Secure by DesignOWASP Top 10 How secure is the tool you use to demonstrate security? Complaica Secure by Design Role-based rights, encrypted connections, logged changes and regular testing – security is part of the architecture. Roles and rights at the coreEncryption and loggingRegularly testedPen-tested by third parties
Fast with large data volumesSQL · NoSQL How does the system stay fast with thousands of assets, tens of thousands of requirements? Complaica Fast with large data volumes Register, search and dashboards are built for large inventories – groups with many sites work in the same instance. Built for large inventoriesSearch and dashboards stay fastMany sites, one instance
ContainerisedDocker · Kubernetes How does the application fit into your container platform? Complaica Containerised Complaica ships as a container and runs under Docker or Kubernetes – reproducible, updatable, scalable. Docker and KubernetesReproducible updatesScales as needed