Manage your ISMS
with full sovereignty
ISO 27001 & NIS2 · Zero installation · 100% open source · Works offline
SaaS solutions expose your sensitive data
Risk registers, business continuity plans, critical asset mappings... Do these strategic documents really belong on external servers?
Data out of control
With SaaS, your risk registers and continuity plans transit through third-party servers. For a DPO or CISO, this is a permanent GDPR vulnerability.
Unavailable during crisis
Cyberattack, network outage, major incident? Your SaaS solution becomes inaccessible, depriving your crisis team of continuity plans at the worst moment.
Heavy infrastructure
Docker, PostgreSQL, DevOps team... Small municipalities don't have these resources. Total cost of ownership explodes before you even start.
Cyber Assistant: sovereignty by design
A tool designed for all security managers, suited to public administrations and businesses alike. No data ever transits through external servers. Privacy by Design.
Zero cloud, zero compromise
- Complete sovereignty: your data stays in your browser or on your internal server — never elsewhere
- Crisis-resilient: works offline, even when internet is down or your network is compromised
- Zero installation: open the HTML file in your browser, that's it. No Docker, no database
- Collaborative mode available: a simple web server is all you need for team collaboration on your own infrastructure
Master your risks with full autonomy
An ISO 27005-aligned risk analysis module, pragmatic and guided. From assessment to PDF report, in just a few clicks.
Perform a risk analysis in a few pragmatic steps
An 8-step wizard guides you through: CIA classification, continuity (RTO/RPO), data protection, security controls, risk scenarios, and automatic recommendations.
- 8 guided steps, from CIA classification to final report
- 24 control questions covering 6 operational domains
- ISO 27005-aligned — without the methodological overhead
Manage your risk analyses
10 built-in scenarios or the threats of 6 embedded frameworks (NIST SP 800-30, OWASP Top 10:2025, STRIDE, MITRE ATT&CK, OWASP LLM and API), with suggested ratings you always review. Probability × severity matrix, customizable thresholds, and 35 recommendation rules.
- 6 threat frameworks on top of the 10 built-in scenarios: NIST, OWASP, STRIDE, MITRE ATT&CK...
- 5×5 probability × severity matrix with 5 risk levels
- Automatic recommendations and treatment strategy per risk
Produce your risk analysis reports
Generate a complete PDF report ready for the board or auditor: executive summary, domain radar chart, threat/scenario register, method and framework traced (frozen version), priority recommendations.
- Multi-page PDF report with professional cover page
- Domain radar chart and traffic light global assessment
- Ready for the board, audit, or NIS2 reporting
Methodology, standards, frameworks and features: how it all fits together
- Analyse des risques — wizard 8 étapes
- Matrice d'impacts — 3 grilles
- Déclaration d'applicabilité (SoA) — 93 contrôles
- Actifs essentiels & parties prenantes
- Contrôles ISO 27002 — 93 mesures
- Menaces (traitement ISO 27005)
- Socle de sécurité NIS2
- Dashboard — Score SMSI consolidé
- Contrôles NIS2 CyFun — 218 exigences
- Mesures ReCyF — 152 mesures
- Audits · KPI · Revues de direction
- Plan d'actions — 6 types de lien
- Non-conformités (détection → clôture)
- Budget cybersécurité
Three guarantees for your peace of mind
Designed to meet the requirements of DPOs, CISOs and compliance officers in the public sector and critical infrastructure.
Data sovereignty
Without an external backend, it is technically impossible for your data to leave your perimeter without your knowledge. Privacy by Design for uncompromising GDPR compliance.
Operational resilience
Cyberattack, network outage, crisis situation? Cyber Assistant remains accessible. Your continuity plans available even in "scorched earth" mode. Essential for emergency services.
Zero infrastructure debt
No Docker, no PostgreSQL, no DevOps team. Open an HTML file, that's it. The lowest total cost of ownership on the market, even for a 500-inhabitant municipality.
Visualize cross-coverage of your frameworks
The bidirectional mapping system visualizes overlaps between ISO 27002, CyFun 2025/NIS2, DORA and PCI DSS. Immediately identify covered areas and gaps.
Map your coverage at a glance
The interactive heatmap shows correspondence levels between frameworks. Three relationship types (equivalent, covers, related) enable fine-grained cross-coverage analysis.
- Bidirectional mapping with 3 relationship types
- Real-time coverage statistics
- Filtering by relationship type and text search
Explore each relationship control by control
The list view lets you explore each cross-framework relationship in detail, with relationship type, coverage percentage and explanatory notes.
- 132 pre-configured relationships between ISO 27002 and CyFun 2025
- Coverage percentage per relationship
- Export mappings for your audits
Everything you need to manage your ISMS
A complete suite of tools designed for operational efficiency, executive reporting and audit compliance.
ISMS Dashboard
Clickable KPIs, ISO 27002 and NIS2 maturity radars, impact × probability risk matrix, evolution charts.
ISO 27001/27002 Controls
Integrated library of 93 Annex A 2022 controls. Status, CMM maturity, filters by domain and operational capabilities.
Complete NIS2 Program
NIS2 controls, 2027/2028 radar, phased action plans, budget management by action and domain, color-coded milestones.
Action Plans & Risks
Actions linked to controls, risks, audits, non-conformities and threats. Impact × probability score, treatment strategy, board date.
Exports & Reports
Global PDF report, Excel export per module, standalone NIS2 HTML export, local snapshots with one-click restore.
Search & Quality
Global search across all objects. Quality tools: duplicate detection, invalid links, controls without subcategory.
Cross-framework mapping
Visualize correspondences between ISO 27002, CyFun 2025, DORA and PCI DSS with heatmap and detailed list view.
Impact matrices
Assess impacts using NIST SP 800-30, PESTEL/5M or EBIOS RM with customizable multi-dimensional matrices.
A complete NIS2 program: CyFun (CCB) label and ReCyF (ANSSI) framework
Drive your NIS2 compliance end-to-end: budget program, controls with CMM maturity, 5-pillar security baseline, and national framework tracking — Belgium's CyFun (CCB) label and France's ReCyF (ANSSI) framework.
NIS2 budget management and CyFun CCB milestones
Configure your budget blocks, track compliance KPIs, visualize maturity on radar chart and drive regulatory milestones toward the CyFun label from Belgium's CCB.
- Configurable budget blocks (OPEX, CAPEX, infra, ISS)
- NIS2 maturity radar with 2027/2028 targets
- 10+ strategic domains with actions and owners
- PDF, HTML and Excel export of the complete program
23 NIS2 controls with integrated CMM maturity
Manage your NIS2 controls by function (Identify, Protect, Detect, Respond, Recover), assess CMM maturity for each and document your justifications.
- Complete NIS2 library (ID, PR, DE, RS, RC)
- 5-level CMM maturity per control
- Filters by function, category, status and level
A security baseline structured on NIST CSF 2.0
The security baseline is built on the NIST Cybersecurity Framework 2.0 with 6 structural functions: Govern, Identify, Protect, Detect, Respond and Recover.
- 6 NIST CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, Recover
- Aligned with NIS2 and CyFun 2025 CCB requirements
- Supply chain, Identities & IAM, Risk management
Choose your NIS2 assurance level
The CyFun 2025 framework from Belgium's Centre for Cybersecurity (CCB) defines 3 assurance levels aligned with the NIS2 directive. Configure your target level directly in the setup wizard.
- 3 levels: Basic, Important, Essential
- 218 CyFun 2025 requirements based on NIST CSF 2.0
- 6 functions: Govern, Identify, Protect, Detect, Respond, Recover
- Maturity thresholds adapted to each level
France's path to NIS2 with the ANSSI's ReCyF framework
For French entities, Cyber Assistant natively integrates the ANSSI's ReCyF framework. Unlike CyFun's maturity model, ReCyF follows a conformity logic: for each of the 152 measures, you declare your status and justify it. The objective scope adapts automatically to your tier (Important or Essential Entity).
- 20 security objectives and 152 measures (ANSSI acceptable means)
- Two tiers: Important Entity (objectives 1 to 15) and Essential Entity (objectives 1 to 20)
- Conformity-based assessment: compliant, partial, non-compliant, alternative measure, not applicable — with justification
- Conformity radar per objective and overall % score, separate from the CyFun engine
Assess your impacts with precision
Two pre-configured matrices (PESTEL/5M and NIST SP 800-30) assess impacts across 6 to 10 dimensions with 5 severity levels. Create your own custom matrices.
NIST SP 800-30, PESTEL and EBIOS RM in one tool
Three pre-configured matrices cover the main impact assessment methodologies. Customize dimensions, levels and calculation rules to fit your context.
- NIST SP 800-30: 6 dimensions (Mission, Data, Physical Security, Relationships, Finance, Planning)
- PESTEL: 10 dimensions with Confidentiality/Integrity/Availability impacts
- Compatible with EBIOS RM, ISO 27005 and NIST
- Customizable matrices: levels, dimensions, calculation rules
A platform open to sector-specific regulations
Cyber Assistant's modular architecture enables integration of new regulatory frameworks. The bidirectional mapping system automatically connects new frameworks to existing controls.
DORA
Digital Operational Resilience Act. European regulation for digital resilience in the financial sector. Available on request with ISO 27002 mapping.
PCI DSS
Payment Card Industry Data Security Standard. Security standard for payment card data. Available on request with complete mapping.
Your framework
Custom integration of sector-specific or internal frameworks. Contact us to evaluate the integration of your specific regulatory framework.
Go collaborative on your infrastructure
Upload the files to any simple web server (Apache, Nginx, or any PHP hosting) and Cyber Assistant becomes a multi-user collaborative platform. No database, no complex setup — your data stays on your own infrastructure.
Real-time co-editing
Tab-level locking system with heartbeat. Automatic conflict detection. Multiple users work simultaneously on different modules.
Multi-account & Roles
JWT authentication with strong passwords. Session management and automatic action attribution in the audit log.
Contractual guarantees
Deployment on your infrastructure (Express.js or PHP). SLA, support and maintenance according to your requirements. Data never externalized.
Continuous updates
New features, frameworks and fixes deployed regularly. Backward compatibility guaranteed with your existing data.
A partitioned ISMS per site or entity
Manage several entities — subsidiaries, sites, business units — in a single installation. Data partitioned per sub-entity, a consolidated view for the parent company, per-section rights.
Each entity its own space, management its overview
Each sub-entity keeps its own risks, actions, controls and audits. The parent company consolidates in one click and enforces a common frame (framework, scoring scales).
- Strict data isolation per partition, enforced server-side
- Per-section rights (none / read / write) via reusable profiles
- Consolidated group view, with the source entity on every row
- Per-entity SSO default and backup of all partitions
Your ISMS, queryable by your AI
Open read-only access to your governance data for an AI assistant, through MCP — the interoperability standard for assistants. Ideally an AI hosted on your own infrastructure, or sovereign.
Ask the question, the AI reads your real data
“Which critical risks have no action plan?”, “Where does my NIS2 maturity stand, function by function?” — no more copy-paste or manual exports: your assistant works on up-to-date data, within its scope.
- Structurally read-only: no assistant can modify your data
- Personal, expirable and revocable tokens — the account's entity scope is enforced
- Access log; activation and tokens recorded in the security audit trail
- Shared responsibility: we secure application access, you control network exposure
Track your remediation actions end-to-end
A complete action plan to drive compliance. Each action is linked to the controls, risks, audits or non-conformities that generated it.
Manage each action from creation to closure
From opening to closure, each action is tracked with its status, priority, owner and deadline. Dashboard KPIs reflect progress in real time.
- Statuses: Open, In Progress, Completed, Postponed, Rejected
- Priorities, owners, deadlines and progress rates
- Direct link to ISO 27002, NIS2 controls and risks
- Dashboard KPI: percentage of completed actions
Cyber Assistant vs CISO Assistant
Two different approaches. CISO Assistant requires server infrastructure and DevOps skills. Cyber Assistant works directly in your browser, without any dependencies.
CISO Assistant is an excellent tool for organizations with IT teams. Cyber Assistant is for structures that prioritize data sovereignty and operational simplicity.
Drive your compliance over time
From NIS2 to ISO 27001, Cyber Assistant covers key frameworks and structures roles for effective governance.
NIS2 Roadmap
Gap analysis & initial action plan
Implementation of priority controls
Full compliance & audit
Ready-to-use frameworks
Everything below ships in the current version — nothing is «coming soon». Native frameworks are built into the tool; cross-mappings are generated by the mapping engine.
Complete management system with document review
93 Annex A controls with CMM assessment
Dedicated program with phases, budget and radar
Belgian framework (CCB) natively integrated
French framework (ANSSI) natively integrated
Digital resilience for the financial sector
Payment card data security
A tool for every role
Strategic ISMS management, board reporting, risk analysis
GDPR compliance, data protection, processing register
Executive dashboard, KPIs, NIS2 budget tracking
Operational actions, control tracking, documentation
An application for all security managers
Clean design, intuitive navigation, clear information. Everything is made to save time.
Every action is automatically tracked
A comprehensive audit log records every creation, modification and deletion across all application modules. Total transparency for your internal audits and regulatory compliance.
18 traceability categories covering all modules
From ISO controls to NIS2 actions, every operation is timestamped and automatically attributed. Filter by action type, search by element, and export the complete history.
- Controls, risks, actions, documents, KPIs, audits, NIS2…
- Filter by action type and search by target
- Automatic user attribution (local or authenticated)
- Dashboard integration with the 10 latest entries
Pourquoi ils choisissent Cyber Assistant
Accessible, souverain, abordable : ce que retiennent les RSSI, DPO et CISO qui l'ont comparé aux outils GRC classiques.
« Plus accessible que Monarc. »
« Correspond bien mieux à nos besoins que CISO Assistant. »
« La souveraineté des données était non négociable : ici, tout reste chez nous. »
« Zéro installation, on a démarré en quelques minutes. »
Keep control of your sensitive data
Your risk registers and continuity plans deserve a solution that respects their confidentiality. Cyber Assistant runs entirely locally — no data ever leaves your organization.
Buy it once. It stays yours.
A purchase that's easy to defend before an executive committee: you pay once, the license is perpetual — no subscription, no imposed recurring cost.
Community Local
Individual use — Offline local mode
- 100% offline in your browser
- Open NIS2 frameworks: CyFun (BE) & ReCyF (FR)
- Zero install — just open the HTML file
- Risk analysis, action plans, audits, KPIs
- ISO 27001 & 27002 standards not included
- No collaborative mode
Start right now, locally — then move up to Corporate Locale or Server anytime; your data follows you, no starting from scratch.
Download for free Installation guideCorporate Locale ISO
Individual use — Official ISO standards
Everything in Community, plus:
- Official ISO 27001 & 27002 standards included *
- Valid and compliant ISO license *
- Advanced trilingual interface — FR / EN / NL
- NIS2 frameworks: CyFun (BE) & ReCyF (FR)
- All Community features included
Corporate Server ISO
Multi-user collaborative
Everything in Corporate Local, plus:
- Real-time co-editing with tab locking
- Up to 100 collaborators co-editing — roles & audit trail
- Multi-entity included — up to 50 sub-entities from one instance
- 1st year of support & updates included
- Deployed on your infrastructure — your data stays with you
- All Corporate Local features included
- Enterprise SSO (OIDC) — Azure AD, Google Workspace, Okta, Keycloak
- Read-only AI access (MCP) — off by default, opened by the administrator
* ISO 27001 and ISO 27002 standards are copyrighted documents. Their integration in Corporate versions requires the user to provide proof of a valid purchase license from ISO or a national standards body.
Need support? Training, deployment assistance and customizations available on request.
Already on Corporate Local? Upgrading to the Server edition is possible — your existing data is carried over. Write to us for the details.
Three editions. And one setup that looks like you.
Cyber Assistant ships in three editions — free local, local ISO, collaborative server. Then it is tuned to your organisation: your sections, your needs, your colours, your methodology. No two organisations run their ISMS the same way.
Community Local
One file, your browser, and you are running. No cloud, no install, no account to create. Ideal to get started and prove the value internally.
Corporate Locale ISO
The same tool, extended with the official ISO 27001 and 27002 standards and the trilingual interface. Still offline, still on your own machine.
Corporate Server ISO
The whole team on a single shared base: co-editing, roles, audit log, SSO, multi-entity. Deployed on your infrastructure, not ours.
No cloud does not mean no server. No data ever leaves for a third-party host — that is what "no cloud" means. The Server edition does exist — but it runs on your server, behind your firewall, under your administration.
And then we fit it to your context
An ISMS cannot simply be dropped onto an organisation: it has to adopt its vocabulary, its priorities and its established practices. That is where the tailoring work begins.
Your sections
Rename, reorder, hide: the tool speaks your organisation's vocabulary. A section can be renamed, moved up the menu, or removed entirely if it serves no purpose for you.
Your needs
Public administration, private company, multi-site group: everyone has different priorities. If NIS2 matters more than ISO in your organisation, the tool is reorganised accordingly — fields, statuses, indicators and exports follow your processes, not generic ones.
Your colours
Logo, palette, themes: the interface carries your visual identity. Reports and exports come out in your own colours, ready to present to the board.
Your methodology
Your rating scale, your risk matrix, your analysis method, your own take on the ISMS. If you already have an in-house method that works, the tool bends to it — your teams do not have to relearn their own.
Every deployment starts with a scoping session: we look at how you actually work, then we adjust. Tell us what, in your organisation, fits no standard box.
See the 3 editions in detail Discuss your context
Manage controls, risks and actions from a unified interface.

Optional web hosting to collaborate with stakeholders.

Complete ISO pyramid with links to evidence and deliverables.

An 8-step wizard guides you through: CIA classification, continuity (RTO/RPO), data protection, security controls, risk scenarios, and automatic recommendations.

10 built-in scenarios or the threats of 6 embedded frameworks (NIST SP 800-30, OWASP Top 10:2025, STRIDE, MITRE ATT&CK, OWASP LLM and API), with suggested ratings you always review. Probability × severity matrix, customizable thresholds, and 35 recommendation rules.

Generate a complete PDF report ready for the board or auditor: executive summary, domain radar chart, threat/scenario register, method and framework traced (frozen version), priority recommendations.

From ISO controls to NIS2 actions, every operation is timestamped and automatically attributed. Filter by action type, search by element, and export the complete history.

Configure your budget blocks, track compliance KPIs, visualize maturity on radar chart and drive regulatory milestones toward the CyFun label from Belgium's CCB.

Manage your NIS2 controls by function (Identify, Protect, Detect, Respond, Recover), assess CMM maturity for each and document your justifications.

The security baseline is built on the NIST Cybersecurity Framework 2.0 with 6 structural functions: Govern, Identify, Protect, Detect, Respond and Recover.

The CyFun 2025 framework from Belgium's Centre for Cybersecurity (CCB) defines 3 assurance levels aligned with the NIS2 directive. Configure your target level directly in the setup wizard.

The interactive heatmap shows correspondence levels between frameworks. Three relationship types (equivalent, covers, related) enable fine-grained cross-coverage analysis.

The list view lets you explore each cross-framework relationship in detail, with relationship type, coverage percentage and explanatory notes.

Three pre-configured matrices cover the main impact assessment methodologies. Customize dimensions, levels and calculation rules to fit your context.

From opening to closure, each action is tracked with its status, priority, owner and deadline. Dashboard KPIs reflect progress in real time.