Choosing ISMS Software: Requirements Catalog & Checklist
Choosing ISMS software: requirements catalog with about 30 criteria, must-have vs nice-to-have, and a free checklist download.


You want to start choosing ISMS software, but you're staring at twenty vendors with near-identical feature lists? That's exactly where the problem starts: without a structured requirements catalog, you end up comparing marketing copy instead of real criteria, and the most convincing sales rep often wins instead of the best-fitting tool.
Choosing ISMS software is not a gut-feeling project. It's a structured procurement decision, just like any other software investment. This guide shows you how to build your own requirements list, which criteria actually matter across the key evaluation areas, and how to separate must-haves from nice-to-haves. Further down in this article, you can download the full requirements catalog as a checklist and use it directly in your own selection process.
How to approach the selection process
Before you book the first demo, an hour of prep work pays off. Three steps turn a vague search into a solid selection process:
- Define scope: which standards and frameworks does the software need to cover today, and which will follow soon? A company that only needs ISO 27001 has different requirements than one that also has to track TISAX and NIS2 at the same time.
- Collect requirements: gather every criterion that matters to your team, your IT department and your leadership. The requirements catalog below gives you a solid starting point you can adapt to your situation.
- Prioritize: not every criterion carries the same weight. A simple three-tier split works well:
- Must-have: without this requirement, a vendor is out, no matter how strong the rest of the offering is. Example: no EU hosting for a company under strict data protection rules.
- Should-have: important for the decision, but can be worked around or compensated with reasonable effort, for instance through a manual interim step.
- Nice-to-have: pleasant, but not decisive. Can tip the scale between two otherwise equal vendors.
This structure helps you avoid the most common trap in software selection: a shiny extra feature distracting from a missing core requirement.
Checklist · 34 items
ISMS Software Requirements Checklist
What to look for when choosing
About 30 criteria for a structured ISMS software evaluation, from framework coverage and security to integrations and core ISMS features.
Check standards and framework coverage
The first thing to look at is content coverage. Check whether the software already ships with preloaded catalogs for ISO 27001, BSI IT-Grundschutz, NIS2 and TISAX, or whether you have to build them yourself. Also check whether you can add your own or additional catalogs if a new standard becomes relevant that the vendor doesn't (yet) support.
Two more points are easy to overlook: can another management system, such as quality management under ISO 9001, be integrated into the same structure instead of running as a second silo? And does the software include its own data protection module, for example for a processing register, or do you need a separate tool for that?
Evaluate users, roles and access
Once several people work in the software, the permission model decides how practical it really is. Check whether there are differentiated roles, such as admin, auditor and employee, each with matching permissions, instead of an all-or-nothing access model.
Also look at integration with your existing identity systems: SSO and Active Directory integration should be possible, ideally without extra cost, since some vendors bill it as an expensive enterprise add-on. Multi-factor authentication should be enforceable company-wide, not just an optional per-user toggle. And if your team works internationally or with partners: multi-language support, at least German and English, is no longer a nice-to-have in many cases, it's a requirement.
Check the vendor's own security and privacy
Extra diligence pays off here, because you're entrusting the vendor with sensitive information security data. Check whether the vendor itself holds an ISO 27001 certificate or a BSI C5 attestation. Both are solid evidence that the vendor actually lives the standards it sells you.
Other criteria: confirmed GDPR compliance including a data processing agreement, end-to-end encryption for data both at rest and in transit, and EU or German hosting. If the software offers AI-powered features, ask explicitly whether your data is used to train the underlying models. A reputable vendor rules that out contractually.
Check interfaces and integrations
ISMS software rarely stands alone. Check whether data can be imported and exported in structured formats like Excel, CSV or XML, for example to bring over existing risk lists or asset inventories. An open API matters if you want to connect the software to a SIEM, a ticketing system, or other business applications. And check the interface to your asset inventory or HR system: maintaining the same data twice costs more time in the long run than the integration ever would.
Plan for scalability, operations and exit
What fits today may not fit in two years. Check functional, organizational and regulatory scalability: does the software grow with additional locations, more users and new regulatory requirements, or does it hit limits quickly?
Operational criteria belong on the list too: high availability, a documented backup and recovery process, and a complete audit trail that makes changes traceable. And one point that's easy to forget during selection and painful later: the exit terms. Can you fully export your data in a usable format when the contract ends, or do you end up stuck in vendor lock-in?
Core ISMS features in detail
Beyond the framework conditions, what the software actually delivers matters just as much. Key core features include:
- A Statement of Applicability that can be generated directly from the stored controls and requirements, instead of being maintained separately.
- Document control with review dates, approval workflows and versioning for policies.
- Task and deadline management with automatic reminders, so nothing gets lost in the team.
- Asset management with a protection needs assessment, where the protection level inherits sensibly to linked assets instead of requiring a separate assessment for every single one.
- A pragmatic, standards-compliant risk management module including risk acceptance, one that stays usable in daily work instead of only working on paper.
- Structured incident documentation for security incidents.
Don't forget audits, vendors, BCM and reporting
Four more areas often decide how useful the software is in daily operations. Check whether an audit plan or audit program can be mapped over a defined period, and whether findings from audits automatically flow into task management instead of gathering dust in a separate log.
If you work with vendors whose security posture matters to your ISMS: look for vendor self-assessments that can be sent out and automatically re-scheduled when due. For business continuity, check whether a business impact analysis can be run directly against your actual business processes, and whether metrics like RPO, RTO and MTPD are visualized in an understandable way. And for ongoing steering: KPIs, status dashboards for risks and measures, and automated reports save you a lot of manual work every quarter.
Should the vendor itself be certified?
This question comes up in almost every selection process, and the answer is a clear yes, with some nuance. An ISO 27001 certificate or a BSI C5 attestation from the vendor shows they've had their own processes independently audited, which is an important trust signal for software that processes your information security data.
Just as important are the fundamentals that aren't optional: confirmed GDPR compliance with a data processing agreement, EU or German hosting, and a clear, written statement about how your data is handled, especially where AI features are involved. When in doubt, actively ask for the audit report or certificate instead of relying on a logo on the website. A vendor that's transparent about this evidence usually has nothing to hide.
Conclusion: choosing ISMS software with structure
A structured requirements list turns a confusing vendor landscape into a solid decision. Define your scope first, gather criteria across all relevant areas, and consistently separate must-have, should-have and nice-to-have before you book the first demo.
So you don't start from scratch, you can download the full requirements catalog with about 30 criteria as a checklist and use it directly for your own evaluation. To see how selection plays out in practice across multiple frameworks like ISO 27001, TISAX and NIS2 at once, read the guide ISMS Software: What Helps with ISO 27001, TISAX and NIS2?. And if you want to start even further back with what an ISMS actually is, check out the guide ISMS Explained Simply.
Kopexa's ISMS software covers the criteria described here, from preloaded catalogs and cross-framework mapping to EU hosting and transparent pricing. To see how ISMS and compliance software costs break down overall, read What Does Compliance Software Cost for SMEs?, and the audit cost calculator gives you a first estimate for an ISO 27001 or TISAX certification audit.
Frequently Asked Questions
- What should I look for when choosing ISMS software?
- Start by defining scope, meaning which standards like ISO 27001, TISAX or NIS2 need to be covered. Then check criteria across framework coverage, user roles and access, vendor security, integrations, scalability, core ISMS features, and audits and reporting. A structured requirements list helps you compare vendors objectively instead of relying on gut feeling.
- What criteria belong in an ISMS software requirements catalog?
- A complete catalog covers at least eight areas, standards and framework coverage, users and access rights, vendor security and privacy, interfaces and integrations, scalability and exit terms, core ISMS features like the SoA and risk management, audit and vendor management, and BCM, reporting and dashboards. About 30 individual criteria map onto these areas.
- What is a must-have versus a nice-to-have criterion?
- A must-have is a disqualifying criterion. If a vendor doesn't meet it, they're out, no matter how strong the rest of the offering is. A nice-to-have is pleasant but not decisive. In between sit should-have criteria, which matter but can be compensated with reasonable effort. This three-tier split prevents a shiny extra feature from covering up a missing core requirement.
- How do I build a requirements list for ISMS tools?
- Start with scope, the standards and frameworks that are relevant now and in the near future. Then gather requirements from your team, your IT department and your leadership, structured around the key evaluation areas. Prioritize each criterion as must-have, should-have or nice-to-have. A ready-made template with about 30 criteria is available as a checklist you can adapt directly.
- Should the ISMS software vendor itself be ISO 27001 certified?
- Yes, that's an important trust signal, though not the only one. An ISO 27001 certificate or a BSI C5 attestation shows the vendor has had its own processes independently audited. Just as important are confirmed GDPR compliance with a data processing agreement, EU or German hosting, and a clear statement on how your data is handled, especially where AI features are involved.
- Do I need external consulting for the selection process?
- That depends on your internal resources and experience with software procurement. With a structured requirements catalog, you can run the selection process well as a self-service effort. For more complex requirements, multiple frameworks at once, or limited experience on the team, a partner or consultant can provide valuable support. Both are valid paths, and they're not mutually exclusive.