One ISMS for ISO 27001 and NIS2 — audit-ready from day one

Run your whole Information Security Management System inside Odoo: dual-framework control library, Statement of Applicability, SHA-256 evidence integrity, risk, incidents, suppliers, audits, CAPA, documentation and a readiness dashboard — one product instead of spreadsheets and a patchwork of disconnected apps.

The problem

Proving ISO 27001 and NIS2 compliance to an auditor means maintaining a Statement of Applicability across dozens of controls, versioning evidence, running a risk register, scheduling audits, logging incidents and tracking supplier risk — today scattered across spreadsheets, shared folders and ticketing tools that never talk to each other, or an enterprise GRC suite that costs $10k–$100k a year.

The solution

A single Odoo app that unifies the full ISMS lifecycle: a pre-seeded ISO 27001:2022 and NIS2 control library, per-entity applicability profiles, tamper-evident evidence, risk-to-control mapping, incident and supplier tracking, internal audits, CAPA, versioned documentation and a readiness dashboard — guided by an onboarding wizard so a non-specialist can start producing valid documentation on day one.

Capabilities

Everything an ISMS needs, in one app

Every capability below is implemented in the module.

01

Dual-framework control library

ISO 27001:2022 Annex A and NIS2 Article 21(2) controls pre-seeded into one unified library, grouped by theme and category, so dual-scope organizations stop maintaining two disconnected tools.

02

Statement of Applicability

Record an applicability decision and justification for every control and generate an auditor-ready SoA report grouped by theme, owner and evidence count — the first document any auditor asks for.

03

Evidence integrity & locking

Every evidence file is fingerprinted with SHA-256 on confirmation, checked for Changed / Intact / No Snapshot state, and locked with a required reason for unlock — a defensible chain of custody, explained in plain language.

04

Risk register linked to controls

Maintain a risk register with inherent and residual scoring where every risk maps to the controls that treat it, closing the loop between risk and mitigation instead of tracking them separately.

05

Incident management with NIS2 flags

Register security incidents with a full timeline and remediation tracking, flagged for NIS2 reporting obligations, satisfying both regulatory reporting and ISO 27001 event handling.

06

Supplier & third-party risk

Track supplier and third-party risk assessments in one place, covering the supply-chain security requirement that NIS2 makes explicit and most competitors leave out entirely.

07

Internal audits & CAPA

Plan and schedule internal audits with control review intervals, and track corrective and preventive actions arising from audits, incidents and findings through to closure.

08

Documentation with versioning

Author policies and procedures with full version history, approval workflow and rollback, organised by category, so documents evolve on the record instead of in an email thread.

09

Readiness dashboard & onboarding

A first-run wizard sets up your applicability profile and starting SoA, then a compliance-scoring dashboard shows exactly which controls still lack evidence — no blank page, no guesswork.

Workflow

How it works

1

Run the onboarding wizard

Declare your sector, size and essential/important designation; the wizard scopes your applicable controls and generates a starting SoA.

2

Assign owners & attach evidence

Assign an accountable owner to each control, attach evidence, and let SHA-256 fingerprinting and locking protect it once confirmed.

3

Run the ISMS lifecycle

Track risk, incidents, supplier assessments, internal audits, CAPA and training completion as they happen — all mapped back to controls.

4

Prove readiness

Watch the dashboard score readiness per control and entity, then export the SoA and management report as PDFs for your auditor.

Questions

Frequently asked

No sales fog. If your question isn't here, email us and we'll answer it the same way.

One app, both frameworks. The control library pre-seeds ISO 27001:2022 Annex A and NIS2 Article 21(2) controls together, so organizations subject to either or both regimes work from a single unified set instead of maintaining duplicate data in two tools.

Get the app

Buy it on the Odoo App Store

Purchase, download and install directly from the official Odoo Apps Store — you'll always get the latest supported build.

Information Security Management (ISMS)

A dual ISO 27001 and NIS2 control library, Statement of Applicability, locked evidence, risk register, incidents, supplier risk, internal audits and CAPA — with a readiness dashboard.

Buy on Odoo App Store