Audit & Compliance

Always audit-ready instead of last-minute sprints

Frameworks for ISO 27001, NIS2 and DORA are included. You continuously assess where you stand and see at a glance where evidence is missing.

Ready to use with pre-loaded frameworks

Compliance foundation

Frameworks, controls and completeness in one place

Docusnap provides an information security management system that starts with ready-made frameworks for ISO 27001, NIS2 and DORA. Controls can be assessed, interlinked and connected with measures, documents and assets. A completeness overview shows at any time which evidence is in place and where gaps remain.

Pre-loaded frameworks

ISO 27001, NIS2 and DORA come as pre-loaded frameworks. You start by assessing where you stand instead of building a catalogue from scratch.

Assess and link controls

Each control is assessed individually. Links between controls make visible which measure contributes to ISO 27001 and NIS2 at the same time.

Completeness at a glance

The completeness overview continuously shows where evidence exists and where gaps remain. No scrambling before the audit date.

Frameworks are in place, controls are ready for your assessment.

Try Now

AI support

Ask instead of reading reports

AI-powered analysis supports you in assessing controls and analysing your ISMS status. Ask questions about your documented controls and evidence instead of working through reports.

Which controls haven't been assessed yet?

14 of 93 controls are still unassessed, 9 of them in access control. Five already have a linked document in place.

Where is evidence missing for NIS 2?

Seven controls in the NIS 2 framework have no document linked. Three of them also contribute to ISO 27001.

What's the implementation status for ISO 27001?

82 of 93 controls are assessed, 6 of them documented as not applicable. Four reviews fall due next quarter.

Which systems have had no update for 30 days?

96 clients and five servers have had no update for more than 30 days.

Where is SQL Server 2016 still running?

Four instances on three servers, two of them holding ERP databases.

Learn more about AI support in Docusnap

Daily operations

From setup to day-to-day

An ISMS does not run on the initial assessment alone. What matters in practice is whether reviews recur reliably, exceptions are properly documented and changes remain traceable.

Applicability and exceptions

Non-applicable controls are documented with a stated reason, not silently skipped. That is the first question in any audit.

Recurring measures

Annual reviews and periodic evidence requirements appear automatically as tasks. They do not need to be remembered.

Reviews with deadlines and owners

Every control has a review date and an assigned person. No shared responsibility, no forgotten deadlines.

Relationships and change history

Controls, measures, documents and assets are interlinked. Every change is recorded in the journal. In an audit, the path matters as much as the current state.

Platform

Compliance on real systems

The ISMS module runs on the same platform as the CMDB, permission analysis and controlled Smartdocs. Controls are attached to real assets, not to a separate description of the target state.

CMDB

Controls and measures are linked to real IT systems documented in the CMDB. Compliance evidence is based on the actual state of the infrastructure.

Controlled Smartdocs

Policies and procedures are maintained as controlled documents, versioned and approved. For every document, it is traceable who changed it and when.

Permission analysis

Permission analysis shows who can access which systems and data. For access management controls under ISO 27001, a reliable basis instead of manual surveys.

Frequently asked questions about the ISMS module in Docusnap

Which frameworks are included in Docusnap?

ISO 27001, NIS-2 and DORA come as complete, pre-loaded frameworks. The included objectives and controls can be assessed and interlinked directly, without having to build a catalogue first.

How does Docusnap show where evidence is missing?

The completeness overview shows the status of all controls and evidence. You can see which controls have been assessed, where documents are missing and which reviews are due.

How does the link between controls and assets work?

Controls are linked to measures, documents and assets from the CMDB. This makes visible which IT systems are affected by a control and whether the associated evidence is in place.

What happens when a control is not applicable?

Non-applicable controls are documented as an exception with a stated reason. These exceptions are part of the ISMS evidence and appear in audits as a deliberate decision, not as a gap.

How does AI support ISMS work?

AI-powered analysis helps with assessing controls and analysing the ISMS status. You ask questions about your documented controls and evidence and receive answers based on your actual data.

How are recurring reviews managed?

Measures can be set up as recurring. Annual reviews or periodic evidence requirements appear automatically as tasks with a deadline and an assigned person.

Start ISMS

Start with the ISMS that already knows your IT landscape

Frameworks are in place. The connection to your CMDB is ready. Now add your assessment.