ISMS Software · OSCAL-native · EU hosting

ISMS software for ISO 27001, NIS2 and TISAX in one platform.

Preloaded catalogs, cross-framework mapping, audit workflow and an OSCAL-native core. From 599 EUR/month for unlimited frameworks instead of expensive consulting stacks.

kopexa.com / dashboard
Live
Frameworks active

7

ISO 27001, NIS2, TISAX, DORA, GDPR ...

Controls compliant

847 / 912

92.9% · +14 in the last 7 days

Risk score

A-

3 open High, 8 Medium

Audit trail · Live

  • [2026-05-11 12:42] A.8.5 (MFA) — evidence uploaded by maria@
  • [2026-05-11 12:38] Risk R-014 mitigation status → ACCEPTED
  • [2026-05-11 12:31] NIS2 Art. 21 mapping → 12 controls covered

Three things that define ISMS software today

What Kopexa builds differently.

Preloaded

93 Annex A controls out of the box

ISO 27001:2022, BSI Grundschutz++, NIS2 practices and VDA ISA 6.0 are already there when you log in. Including categories, maturity levels and automatic mappings.

Cross-framework

One measure satisfies multiple standards

You document MFA once. Kopexa works out that this covers ISO A.8.5, NIS2 Art. 21(2)(j), TISAX 4.x and DORA Art. 9 all at the same time.

OSCAL-native

Compliance as code, not as PDF

Catalogs in OSCAL JSON instead of 200-page Word documents. BSI Grundschutz++ migration in days instead of months, plus clean audits without copy-paste errors.

Comparison

What do you really get for your compliance budget?

Four categories, four realities. A factual comparison based on publicly communicated tier characteristics, without vendor names.

CriterionExcel / WordUS GRC SaaSDACH GRC SaaSKopexa Prorecommended
Transparent pricing on the website
0 €
on request
from 599 €
Frameworks in the standard tierall (manual)12-3unlimited
OSCAL-nativeBSI Grundschutz++ migration without PDF reverse engineering
Cross-framework mapping
addon
EU hosting by defaultself-hosted
Paris
BYOK / on-premise available
On-premise
Open-source compliance standardKSPEC: compliance checks publicly auditable
Tamper-proof audit trail

Values refer to typical characteristics of each tool category, as of May 2026. Individual vendors may differ.

Workflow

Five steps. One system. End to end.

From the first asset to the approved audit. Every step lands in the same audit trail.

01

Asset inventory

Connectors to AWS, Azure, M365, GitHub, HR. Auto-discovery classifies assets by protection needs.

02

Assess risks

Risk matrix with a threat library. Risk owners assigned, treatment documented.

03

Apply controls

Preloaded catalogs for ISO 27001, NIS2, TISAX, BSI Grundschutz++. Cross-mapping calculates automatically.

04

Collect evidence

Evidence from tickets, logs, screenshots, policies. Linked to controls, tamper-proof.

05

Deliver the audit

Read-only audit access or a signed PDF package. Surveillance audits in days instead of weeks.

Framework universe

Ten frameworks. One license. Zero surcharges.

The Pro plan covers everything. No lock-in to a single standard, no add-on for the next regulation.

Incl. Pro

ISO 27001

93 Annex A controls

Incl. Pro

NIS2

Art. 21 + § 30 BSIG

Incl. Pro

TISAX 6.0

VDA ISA chapters 1-9

Incl. Pro

DORA

Art. 5-30 ICT risk

Incl. Pro

GDPR

Art. 5-99 + BDSG

Incl. Pro

BSI Grundschutz++

OSCAL profile 2026

Incl. Pro

ISO 9001

QMS Annex SL

Incl. Pro

SOC 2

Trust Services Criteria

Incl. Pro

VdS 10000

Cyber for SMEs

Incl. Pro

ISO 27701

Privacy extension

Pricing

Transparent. One Pro plan, all frameworks.

No hidden per-framework surcharges. No "demo required to see pricing" hurdle.

Pro plan

Pro

For mid-market and SaaS teams that need a full ISMS without re-licensing for every framework.

0EUR / month
  • Unlimited frameworks plus OSCAL
  • Up to 25 users
  • SSO and SAML 2.0 (Entra ID, Google, Okta, ...)
  • Asset & vendor management
  • Cross-framework mapping
  • Audit trail & read-only auditor access
  • Priority support
Start a 14-day trial
Enterprise

Enterprise

For corporations, regulated industries and multi-entity setups. Self-hosting, a custom SLA and multi-entity included.

custom
  • Everything in Pro
  • On-premise / self-hosting + BYOK
  • Dedicated success manager
  • Custom SLA + DPA
  • Multi-entity consolidation
  • Custom audit onboarding
Request a demo

Lite plan from 249 EUR/month for single-framework teams. See all plans in the pricing comparison.

FAQ

Answers for your procurement checklist

What data protection, IT and compliance leads most often clarify before selecting an ISMS platform.