Cover of the ISMS Software Requirements Checklist
Free checklist

ISMS Software Requirements Checklist

What to look for when choosing

8
Sections
34
Checkpoints
PDF
A4 · Print

Checklist · 34 items

Get the checklist as PDF

Enter your email and we send you the full checklist as a printable PDF right away.

8 categories34 checkpointsPDF · A4

What's inside

  • All 8 clauses of the standard covered, from scope to certificate
  • 34 concrete checkpoints to tick off, each with a short explanation
  • Stage 1 and Stage 2 audit clearly separated so nothing surfaces at the auditor
  • A PDF to print, share with your team and check off

About 30 criteria for a structured ISMS software evaluation, from framework coverage and security to integrations and core ISMS features.

01

Standards & Framework Coverage

4 Checkpoints

  • Check preloaded catalogs

    Are ISO 27001, BSI IT-Grundschutz, NIS2 and TISAX already available, or do you have to add controls manually?

  • Custom catalogs can be added

    Can you add your own or additional catalogs and rulesets when a new standard becomes relevant?

  • Integrated management system

    Can the software integrate other management systems, such as quality management, into the same structure instead of staying siloed?

  • Data protection module available

    Does the software include its own data protection module, such as a processing register and DPIA, or do you need a separate tool for that?

02

Users, Roles & Access

4 Checkpoints

  • Role and permission concept

    Are there differentiated roles such as admin, auditor and employee with matching permissions?

  • SSO and Active Directory integration

    Can the software connect to your existing SSO or Active Directory setup, ideally without extra cost?

  • Enforceable MFA

    Can multi-factor authentication be made mandatory for all users?

  • Multi-language support

    Does the software support at least German and English for content and interface?

03

Vendor Security & Privacy

5 Checkpoints

  • Vendor's own certification

    Does the vendor hold its own ISO 27001 certificate or a BSI C5 attestation?

  • GDPR compliance and DPA

    Does the vendor confirm GDPR compliance and provide a data processing agreement?

  • End-to-end encryption

    Is data encrypted both at rest and in transit?

  • EU or German hosting

    Is your data verifiably hosted in the EU or in Germany?

  • Restrictions on AI training with customer data

    If the software offers AI features: is your data explicitly excluded from model training?

04

Interfaces & Integrations

3 Checkpoints

  • Import and export

    Can data be imported and exported in structured formats like Excel, CSV or XML?

  • API for external systems

    Is there an API to connect the software to a SIEM, ticketing system or other business applications?

  • Interface to asset inventory and HR

    Can the software pull data from your asset inventory or HR system instead of maintaining it twice?

05

Scalability, Operations & Exit

5 Checkpoints

  • Functional, organizational and regulatory scalability

    Does the software grow with additional features, more locations and new regulatory requirements?

  • High availability

    What availability does the vendor guarantee, and how is it monitored?

  • Backup and recovery

    Are there regular backups and a documented recovery process for emergencies?

  • Audit trail and change history

    Are all changes logged and traceable after the fact?

  • Data portability and exit terms

    Can you fully export your data in a usable format when the contract ends?

06

Core ISMS Features

6 Checkpoints

  • Statement of Applicability from content

    Can the SoA be generated directly from the stored controls and requirements instead of being maintained separately?

  • Document control

    Does the software support review dates, approval workflows and versioning for policies and documents?

  • Task and deadline management

    Is there task and deadline management with automatic reminders for responsible owners?

  • Asset management with protection needs assessment

    Can assets be assessed for protection needs, and does that assessment inherit sensibly to linked assets?

  • Pragmatic risk management

    Is the risk management module both standards-compliant and practical, including risk acceptance?

  • Incident documentation

    Can security incidents be recorded, assessed and tracked in a structured way?

07

Audits & Vendors

3 Checkpoints

  • Audit plan and audit program

    Does the software support planning internal and external audits over a defined period?

  • Findings flow into task management

    Do audit findings automatically become tasks with owners and deadlines?

  • Vendor self-assessments

    Can self-assessments be sent to vendors and automatically re-scheduled when due?

08

BCM, Reporting & Dashboards

4 Checkpoints

  • BIA based on business processes

    Can a business impact analysis be run directly against your actual business processes?

  • Visualization of RPO, RTO and MTPD

    Are recovery objectives like RPO, RTO and MTPD visualized in an understandable way?

  • KPIs and status dashboards

    Are there dashboards that summarize status, risks and measures at a glance?

  • Automated reports

    Can reports and reference documents be generated automatically instead of manually?

Get the complete checklist as a PDF

All 34 checkpoints on A4 to print and check off. Free, all you need is your email address.

Get the download