
ISMS Software Requirements Checklist
What to look for when choosing
- 8
- Sections
- 34
- Checkpoints
- A4 · Print
Checklist · 34 items
Get the checklist as PDF
Enter your email and we send you the full checklist as a printable PDF right away.
What's inside
- All 8 clauses of the standard covered, from scope to certificate
- 34 concrete checkpoints to tick off, each with a short explanation
- Stage 1 and Stage 2 audit clearly separated so nothing surfaces at the auditor
- A PDF to print, share with your team and check off
About 30 criteria for a structured ISMS software evaluation, from framework coverage and security to integrations and core ISMS features.
Standards & Framework Coverage
4 Checkpoints
Check preloaded catalogs
Are ISO 27001, BSI IT-Grundschutz, NIS2 and TISAX already available, or do you have to add controls manually?
Custom catalogs can be added
Can you add your own or additional catalogs and rulesets when a new standard becomes relevant?
Integrated management system
Can the software integrate other management systems, such as quality management, into the same structure instead of staying siloed?
Data protection module available
Does the software include its own data protection module, such as a processing register and DPIA, or do you need a separate tool for that?
Users, Roles & Access
4 Checkpoints
Role and permission concept
Are there differentiated roles such as admin, auditor and employee with matching permissions?
SSO and Active Directory integration
Can the software connect to your existing SSO or Active Directory setup, ideally without extra cost?
Enforceable MFA
Can multi-factor authentication be made mandatory for all users?
Multi-language support
Does the software support at least German and English for content and interface?
Vendor Security & Privacy
5 Checkpoints
Vendor's own certification
Does the vendor hold its own ISO 27001 certificate or a BSI C5 attestation?
GDPR compliance and DPA
Does the vendor confirm GDPR compliance and provide a data processing agreement?
End-to-end encryption
Is data encrypted both at rest and in transit?
EU or German hosting
Is your data verifiably hosted in the EU or in Germany?
Restrictions on AI training with customer data
If the software offers AI features: is your data explicitly excluded from model training?
Interfaces & Integrations
3 Checkpoints
Import and export
Can data be imported and exported in structured formats like Excel, CSV or XML?
API for external systems
Is there an API to connect the software to a SIEM, ticketing system or other business applications?
Interface to asset inventory and HR
Can the software pull data from your asset inventory or HR system instead of maintaining it twice?
Scalability, Operations & Exit
5 Checkpoints
Functional, organizational and regulatory scalability
Does the software grow with additional features, more locations and new regulatory requirements?
High availability
What availability does the vendor guarantee, and how is it monitored?
Backup and recovery
Are there regular backups and a documented recovery process for emergencies?
Audit trail and change history
Are all changes logged and traceable after the fact?
Data portability and exit terms
Can you fully export your data in a usable format when the contract ends?
Core ISMS Features
6 Checkpoints
Statement of Applicability from content
Can the SoA be generated directly from the stored controls and requirements instead of being maintained separately?
Document control
Does the software support review dates, approval workflows and versioning for policies and documents?
Task and deadline management
Is there task and deadline management with automatic reminders for responsible owners?
Asset management with protection needs assessment
Can assets be assessed for protection needs, and does that assessment inherit sensibly to linked assets?
Pragmatic risk management
Is the risk management module both standards-compliant and practical, including risk acceptance?
Incident documentation
Can security incidents be recorded, assessed and tracked in a structured way?
Audits & Vendors
3 Checkpoints
Audit plan and audit program
Does the software support planning internal and external audits over a defined period?
Findings flow into task management
Do audit findings automatically become tasks with owners and deadlines?
Vendor self-assessments
Can self-assessments be sent to vendors and automatically re-scheduled when due?
BCM, Reporting & Dashboards
4 Checkpoints
BIA based on business processes
Can a business impact analysis be run directly against your actual business processes?
Visualization of RPO, RTO and MTPD
Are recovery objectives like RPO, RTO and MTPD visualized in an understandable way?
KPIs and status dashboards
Are there dashboards that summarize status, risks and measures at a glance?
Automated reports
Can reports and reference documents be generated automatically instead of manually?
Get the complete checklist as a PDF
All 34 checkpoints on A4 to print and check off. Free, all you need is your email address.