ISMS Tool —
all the norms you need,
at once
Complaica is a modern, fast and affordable AI-enabled information security management system — ISMS solution and data protection management (DPMS) in a single tool.
- 01ISMS and DPMS within a single system
- 02All compliance aspects addressed — scope, requirements, risks, evidence
- 03Software solution plus integration and consulting services
- 04Multiple supported norms, from ISO 27001 to NIS2 and IT-Grundschutz
- 05Time-efficient with AI control over MCP
Supported norms and standards
Complaica is an integrated software solution combining governance, risk and compliance management, information security and data protection into a single tool — for regulatory as well as company-specific standards, policies and best practices.
Complaica ISMS is highly customizable: additional norms and internal requirement catalogues can be added at any time.
Why choose the Complaica ISMS tool
Complaica ISMS gives you a set of working solutions for governance, risk and compliance management — one software for ISMS compliance across every norm that applies to you.
One platform, many standards
NIS2, ISO 27001, IT-Grundschutz, ISO 21434, DSGVO and further norms run on one data set.
Ready-to-use compliance kits
Prepared structures for specific industries — energy, education, healthcare, automotive and others.
Compliance as a service
Compliance software and expert consulting from one supplier, not two contracts.
Optional AI-boosted compliance work
Structures, assignments and status updates are created in natural language instead of by hand.
Integration with the systems you run
Jira, Teams, Microsoft Azure, FNT Command, i-doit, asset management software and others, in both directions.
Automated compliance routines
Deadlines, notifications, change tracking and reports generated on time.
Six views on the same data
Outlook, grid, list, matrix, map and graph — user-centred navigation, not one fixed table.
Customizable functionality and pricing
Both the data model and the licence are fitted to your case.
Quick migration to new standard versions
When a norm is revised, your existing evidence moves with it.
Use Complaica with your AI assistant
The Complaica ISMS solution supports MCP and can be securely connected to ChatGPT, Claude or a locally hosted AI service. Structures are created, statuses updated and data verified an order of magnitude faster than by mouse click.
Access follows your own information security policy — the assistant reads and writes only what you permit.
Commonly used AI features
- 01Document process and asset structures with natural language messages
- 02Get concrete tasks for implementing requirements
- 03Ask questions about information security and data protection standards and regulations
- 04Ask about your own company policies, regulations and documents
- 05Ask how a function of the Complaica information security tool works
Information security and data protection in one software
Complaica combines a data protection management system (DPMS) and an information security management system (ISMS) in one compliance and risk management platform. The same processes, assets and threats are maintained once.
Information security and data protection management obligations are recorded, assigned and evidenced in the same place.
Close both obligations in one system
Technical and organizational measures documented for the ISMS count for data protection as well.
Reuse your ISMS TOM for the DPMS
Identical threats are assessed once, in one risk matrix, with one set of countermeasures.
One risk management system
AI support and information security consulting shorten the way from empty system to running compliance processes.
Consistent processes, defined with AI
ISMS tool — what compliance aspects are addressed
01 / 07 · Organization management
The whole organization in one model
Complaica represents your entire organization — group structure, branches and units — in a single model. All data about the organization sits in one place, while access permissions stay per person and per object.
02 / 07 · Scope analysis
Processes, assets and their dependencies
Investigate asset structures, business processes and the dependencies behind them. The information security tool lets you define protection goals, add custom attributes, classify assets by type and tag, connect external systems and define workflows and lifecycles.
03 / 07 · Compliance checks
Multiple norms evaluated on one scope model
The ISMS compliance management space allows you to evaluate standards, norms and regulations in a single platform. Assets and business processes are assessed at different levels and their statuses accumulate bottom-up. Custom requirements, protection needs and custom implementation levels are supported.
04 / 07 · Risk analysis
Threats, controls and risk appetite
Identify threats related to specific assets and processes, and record countermeasures against them. Risk matrices and assessment scales are configurable, threat and risk catalogues are tailored to your organization, and gross versus net risk can be followed over time.
05 / 07 · Compliance reporting
Audit-ready reports generated by the system
Our information security software automates report generation — usually the first step of every audit or certification. Every norm is delivered with the set of documents required to demonstrate compliance, and Complaica produces them from your own data.
06 / 07 · Activities and collaboration
Who does what, and by when
Work with internal and external contributors in the same system. Access to individual assets and data is granted per object, activities carry owners and deadlines, and every status change is recorded with its author and date.
Moreover, it is possible to define and manage additional compliance-related records, such as incidents, lessons learned or findings. Every such record type may have an individually defined workflow.
07 / 07 · Data analytics and visualization
Dashboards, Excel and your own BI
Complaica provides an integrated system of dashboards and widgets. Application data can be analysed in Excel or read by external analytics and reporting systems, so ISMS and DPMS data reach the tools your management already uses.
Information security consulting services
Our compliance experts support you at each stage of your information security compliance processes, where you need it. You are not left alone with the ISMS software.
We support companies in identifying risks, developing policies and procedures, and continuously monitoring and improving their security status.
ISMS as a service
For a new project we identify risks, implement protective measures and cover the compliance aspects that apply to its scope.
Information security as part of a project
A comprehensive analysis of your data processing activities, with the potential risks named and assessed.
Data protection analysis
Individual data protection policies and procedures, employee training, and regular reviews and updates so the concept stays current.
Data protection concept and monitoring
Smooth transition to the Complaica ISMS solution
Migration is quick and free of charge — whatever compliance management tool you used before, or if you used none at all. Find your starting point:
I use Microsoft Excel or another general-purpose tool
Managing compliance activities in office software turns out to be slow and error-prone as the scope grows. Complaica migrates the data — and you can always export back to Excel.
- Easy export from and to Excel
- A familiar grid layout inside the ISMS tool
- Cross-links between Complaica records and Office documents
I already use an ISMS tool
Our team moves your existing ISMS data across so you can evaluate the full feature set on your own records rather than on a demo data set.
- Rich data import and export
- Integration over AI / MCP
- Integration over REST API
- Support from our specialists for the whole migration
I use CMDB or asset management software
Connecting your asset management software to the ISMS tool avoids duplicated data and keeps the compliance scope in step with reality.
I am a beginner at compliance
You get a full ISMS solution plus turn-key compliance services: we help you set up and maintain an ISMS and DPMS and prepare audits or certifications.
- ISMS tool and compliance services in one contract
- Free onboarding with a compliance expert
- Compliance routines covered by AI
- Ready-to-use compliance kits for many industries
ISMS solution for Microsoft Azure-based infrastructures
Complaica lets organizations build their ISMS and DPMS around an existing Azure IT infrastructure instead of describing it a second time by hand.
- Read assets directly from Azure
Virtual machines, applications, services and users are extracted as compliance objects.
- Assign requirements and threats
BSI C5, NIS2, BSI IT-Grundschutz, ISO/IEC 27001, Grundschutz++ and other regulations are mapped onto Azure IT assets for compliance and risk management.
- Monitor infrastructure changes
Changes in the Azure infrastructure are summarized and the responsible people are notified.
- Connect assets into dependency graphs
Logical dependencies between assets carry business continuity management.
Frequently asked questions
What is an ISMS (information security management system)?
An ISMS is a set of policies, guidelines and procedures with which a company manages its information security. It guards the three fundamental properties of information: integrity, confidentiality and availability.
What are ISMS controls?
ISMS controls are the policies, processes and steps you set up to reduce risks in your organization.
How do you implement ISMS management software?
1. Designate the right person or team, with time, budget and knowledge to run the ISMS. 2. Choose suitable software that gives a clear view of your compliance processes. 3. Document your compliance scope, requirements and activities in the compliance software. 4. Keep it up to date. Complaica is built to make steps 3 and 4 as quick and easy as possible.
What are the advantages of ISMS software over Excel?
Excel is a capable tool, but an ISMS needs automation, collaboration, access control and data validation that a spreadsheet does not provide. With Complaica you get a 360-degree view of your ISMS across compliance projects and assets, with integrated standards, best practices and recommendations, which makes complying with several information security standards at once practical.
Can external documents and files be uploaded to your compliance system?
Yes. Complaica is a flexible software for ISMS that accepts external documents and files, and external users can be invited by link to collaborate on documents safely.
What information security standards does Complaica support?
Complaica supports most norms organizations need, among them NIS2, TISAX, B3S KRITIS, ISO 22301, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27019, BSI IT-Grundschutz, Grundschutz++ and DORA.
Does your ISMS tool support BSI IT-Grundschutz?
Yes. Complaica implements BSI standards 200-1, 200-2, 200-3 and 200-4. The Complaica BSI IT-Grundschutz kit is a quickstart with the structure, tools, documentation and guidelines needed to build the ISMS yourself and meet IT-Grundschutz compliance.
Does your ISMS tool support BSI IT-Grundschutz++?
Yes. Complaica is one of the first tools supporting BSI IT-Grundschutz++.
Does your ISMS tool support OSCAL catalogs?
Yes. Complaica is one of the first fully functional ISMS tools supporting import and export of NIST OSCAL catalog formats.
Do you provide consulting services?
Yes. Our compliance experts support every stage of implementing the tool and building ISMS processes. Book a free demo and our specialists will answer your questions and walk you through the ISMS tool.
Who is responsible for ISMS implementation?
Implementation requires a person with the necessary knowledge and competence. If your organization has no such specialist, our team of experts supports every stage of ISMS system software implementation.
Working with us is easy and pleasant!
Ask us – we answer quickly.
Thank you.
We will get back to you within one business day.
Not sent.
That did not work. Please check the fields or email us directly.