
GRC Requirements Catalogue
More than 110 requirements in 15 areas, collected from tenders and customer projects. An Excel template for aligning your team, free of charge.
- 15
- Areas
- 112
- Requirements
- Excel
- Ready to fill in
Template · 112 requirements
Request the catalogue for free
Would you rather not align the requirements on your own?
We offer a facilitated requirements analysis with your stakeholders, run by one of our consulting partners. Online in four hours for EUR 2,500 net, or as a full day on site for EUR 4,500 net including travel expenses within Germany. Write to us at hello@kopexa.com.
What's inside
- 15 areas from frameworks and risk management to BCM, suppliers, hosting and support
- 112 requirements from real tenders and customer projects
- Set priorities (must, should, could) and owners directly in the template
- Excel file with scope sheet, ready to share with your team
What the catalogue is for
Anyone looking for a tool for ISMS, risk management or BCM usually starts with a blank spreadsheet and collects requirements from memory. What gets missed are the points that hurt later in daily operation: multiple legal entities, interfaces to the asset inventory, evidence from the vendor.
The catalogue does this groundwork for you. You rate each requirement as must, should or could and end up with a basis you can put in front of any vendor, including us.
Who it is for
For information security, IT management, data protection and executive management in organisations that are selecting a GRC tool or replacing an existing one.
Standards & frameworks
14 Requirements
ISO 27001 fully covered
ISO 22301 (BCM) covered
NIS2 / BSIG covered
BSI IT-Grundschutz / BSI standards 200-x
TISAX covered
DORA covered (gap analysis)
AI Act covered
GDPR / data protection module
ISO 27031 covered
Create your own catalogues and requirements
Mapping between frameworks (integrated management system)
Support when standards change
Statement of Applicability (SoA) generated from the content
Register of requirements and legal obligations
Governance & organisation
9 Requirements
Role and permission model
Permissions at group and department level
Multi-tenancy for several legal entities
Standard ISMS as a master template for entities
Approval workflows for management and owners
Configurable workflows
Annual planner and cycle planning (ISMS/BCMS)
Scales to the required volume
Scales with the organisation
Assets & protection needs
6 Requirements
Asset inventory with categories and structure
Protection requirement assessment
Inheritance of protection requirements
Assisted protection requirement analysis with suggestions
Connection to CMDB and asset systems
Processes and process map
Risk management
10 Requirements
Risk analysis and assessment
Assets and protection requirements carried into the risk
Pre-assessed risks / risk catalogue
Threat catalogues (for example BSI elementary threats)
AI-assisted suggestions for risks and measures
Documented risk acceptance
Transfer into measures and tasks
Visualisation (heat map, risk matrix)
Risk appetite and criticality flags
Integrated ISMS and BCMS risk analysis
Controls & tasks
8 Requirements
Implementation status of controls and measures
Effectiveness and maturity with evidence
Tasks with recurring reminders
Deadline monitoring and notifications
Escalation when a deadline is missed
Evidence repository
Automated technical checks
Vulnerability management
Document control
7 Requirements
Versioning, review and approval
Reminders for review dates
Automatic list of controlled documents
Acknowledgement by employees
Automated documents and reports from the data
Template library
DMS integration (for example SharePoint)
Audits & findings
3 Requirements
Audit plan and audit programme
Audit per control (checklists)
Findings turned into tasks
Suppliers & third parties
8 Requirements
Supplier register with criticality
Self-assessment sent to suppliers
Recurring assessment based on criticality
Third-country transfer and processing agreement per supplier
Concentration risk, sub-outsourcing, exit strategies
DORA register of information
Review of contract clauses (for example DORA Art. 30)
Cyber risk check for holdings and small units
Incidents & reporting
4 Requirements
Incident recording and classification
Reporting deadlines for NIS2, DORA and GDPR with reminders
Reporting form for employees
Connection to ticket and incident systems
Business continuity (BCM)
7 Requirements
Business impact analysis
Graphical view of RTO, RPO and MTPD
Damage scenarios and continuity strategies
Continuity plans and emergency manual
Emergency teams and roles
Exercises and recovery tests
Alerting, mobile crisis app, offline use
Reporting & dashboards
7 Requirements
Real-time dashboards
KPIs with measurements and charts
Your own dashboards
Management and CISO dashboard
Export to PDF and Excel
Connection to BI tools (Power BI, Qlik)
Global search across all records
People & awareness
3 Requirements
Training records
User synchronisation from Microsoft 365
Onboarding status per employee
Integration & technology
11 Requirements
REST API
Single sign-on with Entra ID / AD
Enforced multi-factor authentication
Import from Excel, CSV and XML
Webhooks and event triggers
Integration with process and EAM tools
Multilingual (at least German and English)
Audit trail and change history
No AI training on customer data
On-premise operation or export
Data portability and exit
Hosting, security & vendor
10 Requirements
Hosting in Germany or the EU
No third-country transfers
Development and support in Germany or the EU
Vendor holds an ISO 27001 certificate
BSI C5 attestation / SOC 2
Evidence of the vendor's IT operations and continuity management
Encryption, patches, backups
Customer-managed keys (BYOK)
High availability
Data processing agreement under GDPR
Support & onboarding
5 Requirements
Technical support in the required languages
Training for administrators and users
Documentation and online help
Support during rollout
Scalable licence model
Download the full catalogue as an Excel file
All 112 requirements with priorities and owners, ready to fill in. Free, after a short sign-up.