Controls
Every security measure, its owner and its status in one place
Controls are what you do about your risks. Add them from the ready-made library or one by one, link them to NIS2 and ISO 27001 codes, and follow each one until it is implemented. Your readiness score and the Frameworks page are worked out from them.

How it works
Add controls
Start with the ten NIS2 Article 21(2) measures in one click, add more from the library, or write your own.
Link them
Name the framework codes, choose the risks each control treats and attach evidence that shows it works.
Follow the status
Move each control from not started to in progress and implemented. Reviews return in Tasks with a reminder.
What changes for you
Readiness you can explain
The share of implemented controls is your readiness, per area and per framework.
Proof next to the measure
Evidence and automatic check results show on the control itself, where an auditor looks.
One control, several frameworks
A control that names NIS2, ISO 27001 and DORA codes counts for each of them.
What it covers
- NIS2 21(2)(a)-(j)
- ISO 27001 Annex A
- ISO 27001 6.1.3
Works together with
Questions
Do I have to write every control myself?
No. The library holds ready-made controls with their codes, and the ten NIS2 measures can be added in one click.
Which codes can a control name?
NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A, and codes of DORA, the CRA, ISO 22301, TISAX, SOC 2, ENS and BSI IT-Grundschutz. Only codes are stored, never copyrighted texts.
Build your control register
Start from the library and see your readiness grow with every control you implement.
