All compliance modules in one clearly arranged tool. Developed specifically for organisations in the Netherlands.
One platform for your management system, with its own specific modules alongside the general modules below.
For ISO 27001, NEN 7510 (the Dutch healthcare information security standard) and the Dutch Cybersecurity Act (the Dutch implementation of NIS2).
ComplianceGuard translates the Dutch and European obligations into concrete controls, tasks and records: you demonstrate that you comply.
The successor to the Dutch Network and Information Systems Security Act (Wbni) affects thousands of organisations in essential and important sectors. ComplianceGuard helps you with the duty of care and the notification duty.
Get your processing of personal data in order and keep it demonstrable. From the record to the data breach notification: everything in one place.
These modules work for all your standards at the same time: one way of working, whether you run ISO 27001, NEN 7510 or the Dutch Cybersecurity Act.
See at a glance where you stand with your compliance. Real-time insight into your current risk profile, open tasks and audit findings. Clear progress and action points.
Identify and manage risks with a simple wizard. Your current risk level is calculated continuously on the basis of operational tasks, audit findings and registered incidents and data breaches. Parameters are fully adjustable.
Full support for ISO 27001, NEN 7510 and the Dutch Cybersecurity Act. Predefined controls, tasks and templates for each standard, plus your own standards.
Register and classify your assets: data, applications, hardware and contracts. With ownership, data classification and links to risks and controls, in line with ISO 27001 (A.8).
Keep track of all compliance tasks. Automatic reminders and clear deadlines for your team.
Register and handle security incidents in line with Dutch legislation. GDPR notifications made easy.
Plan and carry out audits with a complete system for findings, follow-up and reporting. From planning to final report.
Central document management with version control, templates and collaboration. You can also link documents held elsewhere, such as SharePoint or Google Drive: external references run fully within the status and review workflow.
Generate the management review almost automatically, filled with current data from across your management system in line with chapter 9.3. Management assesses, decides and signs off, including action points with an owner and a deadline and export to Word.
Manage and assess suppliers on compliance. Risk profiles, assessments and tracking in line with ISO 27001, NEN 7510 and NIS2.
Extensive reports and dashboards for management. Export to CSV, Excel and PDF for the board and auditors.
An impression of the dashboard, risk management and the business impact analysis. Clearly arranged, in the same way of working for all your standards.
Real-time insight into risks, tasks and the progress for each standard.
| Process | RTO | Criticality |
|---|---|---|
| Order processing | 4 hours | High |
| Invoicing | 24 hours | Medium |
| Customer portal | 8 hours | High |
| Reporting | 72 hours | Low |
| Payroll processing | 48 hours | Medium |
Determine the recovery time objective (RTO) and the criticality for each process.
Risks in a 5×5 matrix. The level is recalculated continuously.
Alongside the classic risk overview, the dynamic dashboard continuously recalculates your baseline risks into a current picture based on incidents, tasks and audit findings.
Totals, status distribution and the risk matrix in a single overview.
| Threat | Current | Status |
|---|---|---|
| Ransomware infections | 15 | In progress |
| Inadequate backup procedures | 12 | Open |
| Disruptions caused by IT | 12 | Open |
| Phishing or social engineering | 9 | Resolved |
Baseline risks are adjusted automatically into a current picture.
Based on reports linked to the threat within 90 days. Raises the risk by 10 to 30%.
Based on overdue operational tasks from linked controls. Raises the risk by 15 to 30%.
Based on open audit findings within 365 days. Observations +10%, non-conformities +40%.
Illustrative examples. How things appear in your own environment depends on your standards and settings.
Keep track of which security controls you have put in place and their status.
Central management of all your policy documents with version control.
Automatic backup of all your compliance data and documents.