30 standards and regulations in one platform.
For a company that wants to take ISO 27001 all the way to the certificate.
Each additional company you manage: 99 € net per month.
For a company running several standards at once and answering customer security questions.
For organisations that need their own terms and support during the audit.
Do you serve several clients or group companies? We add each additional company to your account after a short call: arrange a call.
Prices on this page are in euro and we charge in euro. Prices exclude tax, invoice issued once settled. Self-service plans are for organisations of up to 250 employees; for larger ones we prepare an individual offer.
Guardiso holds an ISO/IEC 27001 certificate and runs its entire information security management system on the same platform you get.
| Module | Starter | Professional | Enterprise |
|---|---|---|---|
| Foundation: policies, risks, controls, evidence and assetsPolicies, risks, controls, evidence and assets, the foundation everything else stands on. | ✓ | ✓ | ✓ |
| Personal data protection (GDPR)Processing register, impact assessments, data subject requests and breach notifications. | ✓ | ✓ | ✓ |
| Trust portal for customersA public trust page for customers asking about your security. | — | ✓ | ✓ |
| Statement of Applicability, readiness and standards mappingStatement of Applicability for ISO 27001, an audit readiness assessment with a gap list, the legal requirements register and mapping of controls between the standards your company has switched on. | ✓ | ✓ | ✓ |
| Shared controls, compliance tests and the document repositoryShared controls view, compliance tests, data lifecycle, information classification and the document repository. Together with the full standards catalogue in this plan, mapping covers every standard against every other, not only the three standards in Starter. | — | ✓ | ✓ |
| Operational workOperational work | — | ✓ | ✓ |
| Security Readiness QuestionnaireA large security self-assessment where questions covered by a certificate you hold are credited automatically, with a readiness score and a grade. | — | — | ✓ |
| Auditor access and evidence packRead-only access for your external auditor and an audit evidence pack with a readiness score. | ✓ | ✓ | ✓ |
| Internal Audit (ISO 27001 clause 9.2)Internal Audit (ISO 27001 clause 9.2) | ✓ | ✓ | ✓ |
| Audit programme and questionnairesAnnual audit programme, internal audits, certificates register and client audit questionnaires. | — | ✓ | ✓ |
| Vendors and third-party risk assessmentVendor register, third-party risk assessment, data processing agreements and electronic signatures. | — | ✓ | ✓ |
| Incidents and nonconformitiesIncident reporting, notification deadlines and case records. | ✓ | ✓ | ✓ |
| Business continuity and resilienceBusiness continuity plan, impact analysis and failure scenarios. | ✓ | ✓ | ✓ |
| Domain Security AssessmentScanning of your own domains and subdomains with a score and a list of recommendations. | ✓ | ✓ | ✓ |
| Security operationsThreat information, review of third-party security test reports, patch management, monitoring and a baseline configuration register. | — | ✓ | ✓ |
| Training and employee lifecycleSecurity training for employees with a record of who completed it, employee lifecycle and access reviews. | — | — | ✓ |
| Information security system setup (ISO 27001)Scope, organisational context, objectives and interested parties, all required by ISO 27001. | ✓ | ✓ | ✓ |
| Compliance wizard and document analysisA compliance wizard that prepares implementation documentation, analysis of documents you paste in and the Guardiso Assistant. | ✓ | ✓ | ✓ |
| Advisor and register of artificial intelligence systemsAn artificial intelligence advisor and a register of artificial intelligence systems with impact assessments. | — | — | ✓ |
| Integrations with your company tools and the programming interfaceConnections to the tools your company already uses, plus public programming interface documentation. | — | ✓ | ✓ |
| Board panel and reportsCompliance status for the board on one screen, with trend, management review and a downloadable report. | — | ✓ | ✓ |
| Your own company standards and full data exportYour own company standards with custom controls, automated asset discovery and a full export of organisation data. | — | — | ✓ |
| Client companies (consultant)Client companies (consultant) | — | — | ✓ |
| Company login and accounts provisioned from the corporate directoryLogin with company identity plus provisioning and deprovisioning of accounts from the corporate directory. | — | — | ✓ |
| Group structure: parent company and subsidiariesParent company, subsidiaries and a consolidated compliance view of the whole group under one account. | — | — | ✓ |
Cancel any time.
Still comparing? Check your organisation in a free self-assessment, no account needed.